A critical authentication bypass in nginx-ui is being actively exploited right now, and more than 2,600 instances are sitting exposed on the internet.