logo

Nginx-ui Vulnerability Actively Exploited in Attack – Enables Full Server Takeover

ID: 0d38e320-163f-5ed4-a7ff-915bd17df526

STIX ID: report--0d38e320-163f-5ed4-a7ff-915bd17df526

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-04-16

Date Updated: 2026-04-21

Author: Abinaya

...
...

**Critical authentication bypass in Nginx UI (CVE-2026-33032) — actively exploited:** The Nginx UI MCP integration omits authentication on the /mcp_message endpoint and uses a permissive default IP whitelist, exposing ~2,600+ instances and allowing unauthenticated attackers to run administrative MCP tools (config changes, traffic proxying, credential capture, config exfiltration, and service disruption); public PoC and confirmed exploitation make immediate patching (Nginx UI 2.3.4+), disabling MCP, or restricting admin IPs urgent.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.