logo

Critical MCP Integration Flaw Puts NGINX at Risk

ID: 16a38d92-1eeb-5ab7-b6a0-e684dbe1d61b

STIX ID: report--16a38d92-1eeb-5ab7-b6a0-e684dbe1d61b

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2026-04-15

Date Updated: 2026-04-22

Author: Jai Vijayan

...
...

Attackers are actively exploiting a critical CVE-2026-33032 flaw in the nginx-ui management interface (CVSS 9.8) that allows unauthenticated use of MCP endpoints to modify NGINX configurations, restart services, and fully take over proxied applications; a previous backup-exposure flaw (CVE-2026-27944) and a static node_secret make many deployments trivial to compromise, with researchers finding ~2,600 publicly exposed instances and the project releasing a fix in v2.3.4.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.