logo

Nginx UI Alert: Public PoC Exploit and Full Details Disclosed for Critical 9.8 CVSS Flaw with No Patch Available

ID: 54a73e15-0419-5b27-a483-4b87189f3b4d

STIX ID: report--54a73e15-0419-5b27-a483-4b87189f3b4d

Feed Name: securityonline.info

Threat Score
95/100

Date Published: 2026-03-31

Date Updated: 2026-04-23

Author: Ddos

...
...

Nginx UI contains a critical unauthenticated remote vulnerability (CVE-2026-33032, CVSS 9.8) where the /mcp_message endpoint relies on an IP whitelist that defaults to “allow all,” enabling attackers to invoke MCP tools and potentially take over Nginx services; a public PoC exists and no official patch is available, so administrators should restrict network access or apply AuthRequired() and change the whitelist default to deny-all.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.