Critical Nginx-ui MCP Flaw Actively Exploited in the Wild
ID: c49dd60c-1db1-57bf-8313-97e518428f53
STIX ID: report--c49dd60c-1db1-57bf-8313-97e518428f53
Feed Name: Infosecurity Magazine (News)
Threat Score
**Critical authentication bypass (CVE-2026-33032) in nginx-ui actively exploited** — a missing authentication check on the /mcp_message MCP endpoint allows a single unauthenticated API request to achieve full control of nginx servers; Pluto Security identified over 2,600 publicly reachable instances, the maintainers released patch 2.3.4, and organizations are advised to update, disable MCP if unpatchable, restrict access, and review logs and configs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
