Critical Nginx UI Vulnerability Exposes Server Backups and Sensitive Data
ID: 38934e55-431f-5a91-ae8f-b840e77f9e6a
STIX ID: report--38934e55-431f-5a91-ae8f-b840e77f9e6a
Feed Name: The Cyber Express
**Executive Summary:** CVE-2026-27944 is a critical (CVSS 9.8) unauthenticated vulnerability in the Nginx UI /api/backup endpoint that returns encrypted server backups together with the AES key and IV in the X-Backup-Security response header, enabling attackers to download and instantly decrypt archives containing credentials, configuration, and private SSL keys; versions prior to 2.3.2 are affected and 2.3.3 contains a patch, and a public proof-of-concept demonstrates exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
