Critical Nginx UI auth bypass flaw now actively exploited in the wild
ID: 2e939fa2-8cb9-5141-bcc5-5ed52f320882
STIX ID: report--2e939fa2-8cb9-5141-bcc5-5ed52f320882
Feed Name: Bleeping Computer
Threat Score
A critical unauthenticated vulnerability in nginx-ui (CVE-2026-33032) allows remote attackers to use the exposed /mcp_message endpoint to invoke privileged MCP tools, modify nginx configuration, trigger reloads, and achieve complete nginx service takeover; the flaw is actively exploited in the wild with public PoCs and thousands of potentially exposed instances, and fixes have been released.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
