Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover
ID: 36d8d587-b038-5d12-8258-6ef35c856571
STIX ID: report--36d8d587-b038-5d12-8258-6ef35c856571
Feed Name: The Hacker News
A critical authentication-bypass vulnerability in nginx-ui (CVE-2026-33032, CVSS 9.8), dubbed MCPwn, allows unauthenticated attackers to invoke management tools via the /mcp_message endpoint and achieve full Nginx service takeover (modify configs, reload, intercept traffic). The flaw was patched in nginx-ui 2.3.4 (released 2026-03-15); mitigations include adding authentication middleware to /mcp_message or changing default IP allowlisting to deny-all. The report cites active exploitation, inclusion on Recorded Future’s list of actively exploited vulnerabilities, and Shodan data showing ~2,689 exposed instances, and also references two related Atlassian MCP flaws (CVE-2026-27825 and CVE-2026-27826) that can be chained for unauthenticated RCE.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
