Nginx UI Alert: Public PoC Exploit and Full Details Disclosed for Critical 9.8 CVSS Flaw with No Patch Available
ID: 54a73e15-0419-5b27-a483-4b87189f3b4d
STIX ID: report--54a73e15-0419-5b27-a483-4b87189f3b4d
Feed Name: securityonline.info
Threat Score
Nginx UI contains a critical unauthenticated remote vulnerability (CVE-2026-33032, CVSS 9.8) where the /mcp_message endpoint relies on an IP whitelist that defaults to “allow all,” enabling attackers to invoke MCP tools and potentially take over Nginx services; a public PoC exists and no official patch is available, so administrators should restrict network access or apply AuthRequired() and change the whitelist default to deny-all.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
