logo

Critical Nginx-ui MCP Flaw Actively Exploited in the Wild

ID: c49dd60c-1db1-57bf-8313-97e518428f53

STIX ID: report--c49dd60c-1db1-57bf-8313-97e518428f53

Feed Name: Infosecurity Magazine (News)

Threat Score
95/100

Date Published: 2026-04-15

Date Updated: 2026-04-22

...
...

**Critical authentication bypass (CVE-2026-33032) in nginx-ui actively exploited** — a missing authentication check on the /mcp_message MCP endpoint allows a single unauthenticated API request to achieve full control of nginx servers; Pluto Security identified over 2,600 publicly reachable instances, the maintainers released patch 2.3.4, and organizations are advised to update, disable MCP if unpatchable, restrict access, and review logs and configs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.