Critical NGINX UI Vulnerability CVE-2026-33032 Under Active Exploitation
ID: 13d70352-32e1-536d-a910-e07b6e3ea913
STIX ID: report--13d70352-32e1-536d-a910-e07b6e3ea913
Feed Name: ThreatCluster
A critical unauthenticated security flaw (CVE-2026-33032, CVSS 9.8) in the nginx-ui management interface has been actively exploited since March 2026, enabling attackers to bypass authentication via the /mcp_message endpoint and take full control of NGINX servers (modify configs, reload services, intercept traffic). Over 2,600 publicly accessible nginx-ui instances were identified as vulnerable; a patch (v2.3.4) was published on March 15, 2026 but many systems remain unpatched, and organizations are urged to update immediately or restrict access to the management interface.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
