Nginx-ui Vulnerability Actively Exploited in Attack – Enables Full Server Takeover
ID: 0d38e320-163f-5ed4-a7ff-915bd17df526
STIX ID: report--0d38e320-163f-5ed4-a7ff-915bd17df526
Feed Name: cybersecurityNews.com
**Critical authentication bypass in Nginx UI (CVE-2026-33032) — actively exploited:** The Nginx UI MCP integration omits authentication on the /mcp_message endpoint and uses a permissive default IP whitelist, exposing ~2,600+ instances and allowing unauthenticated attackers to run administrative MCP tools (config changes, traffic proxying, credential capture, config exfiltration, and service disruption); public PoC and confirmed exploitation make immediate patching (Nginx UI 2.3.4+), disabling MCP, or restricting admin IPs urgent.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
