Nginx-UI Flaw Actively Exploited to Enable Full Server Takeover
ID: 22b1e0b3-fd0b-55c6-82ec-c8033507ff37
STIX ID: report--22b1e0b3-fd0b-55c6-82ec-c8033507ff37
Feed Name: Cyber Press
Threat Score
**Executive summary:** A critical unauthenticated remote-control vulnerability in nginx-ui (CVE-2026-33032, CVSS 9.8) allows attackers to bypass authentication via an unprotected MCP endpoint and execute administrative commands, with researchers reporting active exploitation and roughly 2,600 publicly exposed instances; nginx-ui v2.3.4 contains the patch and administrators are urged to update, configure the IP whitelist, and audit logs immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
