Critical Authentication Bypass in nginx-ui Allows Full Server Takeover
ID: 2f34b345-ce95-585c-9767-97f497307d90
STIX ID: report--2f34b345-ce95-585c-9767-97f497307d90
Feed Name: ThreatCluster
Threat Score
A critical NGINX UI vulnerability (CVE-2026-33032) enables unauthenticated attackers to bypass authentication on the /mcp_message endpoint and gain full control of NGINX servers; the flaw has a CVSS of 9.8, has been actively exploited since March 2026, affects over 2,600 publicly exposed instances, and a patch (nginx-ui 2.3.4) was released on March 15, 2026 — organizations should update or restrict access to the management interface immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
