logo

Critical NGINX UI Vulnerability CVE-2026-33032 Under Active Exploitation

ID: 13d70352-32e1-536d-a910-e07b6e3ea913

STIX ID: report--13d70352-32e1-536d-a910-e07b6e3ea913

Feed Name: ThreatCluster

Threat Score
88/100

Date Published: 2026-04-15

Date Updated: 2026-04-16

...
...

A critical unauthenticated security flaw (CVE-2026-33032, CVSS 9.8) in the nginx-ui management interface has been actively exploited since March 2026, enabling attackers to bypass authentication via the /mcp_message endpoint and take full control of NGINX servers (modify configs, reload services, intercept traffic). Over 2,600 publicly accessible nginx-ui instances were identified as vulnerable; a patch (v2.3.4) was published on March 15, 2026 but many systems remain unpatched, and organizations are urged to update immediately or restrict access to the management interface.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.