logo

Critical Nginx UI auth bypass flaw now actively exploited in the wild

ID: 2e939fa2-8cb9-5141-bcc5-5ed52f320882

STIX ID: report--2e939fa2-8cb9-5141-bcc5-5ed52f320882

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2026-04-15

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A critical unauthenticated vulnerability in nginx-ui (CVE-2026-33032) allows remote attackers to use the exposed /mcp_message endpoint to invoke privileged MCP tools, modify nginx configuration, trigger reloads, and achieve complete nginx service takeover; the flaw is actively exploited in the wild with public PoCs and thousands of potentially exposed instances, and fixes have been released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.