CVE-2026-33032
CVSS 9.8 CRITICAL: nginx UI is a web user interface for the Nginx web server. EPSS 36% (98th percentile).
Vulnerabilities · 151 days ago
The problem is not just a missing login check. nginx-ui’s MCP message endpoint was effectively open, so any network attacker could change Nginx behavior, reload configs, and take over the service through a management feature that was supposed to extend control, not remove it.
The flaw is CVE-2026-33032, a CVSS 9.8 authentication bypass in nginx-ui’s /mcp_message endpoint. Sources say version 2.3.4 fixes it, and exploitation is already in the wild. Pluto Security reported more than 2,600 internet-exposed instances, and the tool has seen more than 430,000 Docker pulls.
The risk is broader than one server restart. Once an attacker can write configs, they can intercept traffic, harvest admin credentials, and keep control through the management plane even if the original access path is closed.
CVSS 9.8 CRITICAL: nginx UI is a web user interface for the Nginx web server. EPSS 36% (98th percentile).
7 sources covering this story
CVE-2026-33032: Nginx UI Missing MCP Authentication
CVE-2026-33032 is a missing authentication bug with a CVSS score of 9.8, and exploitation in the wild has begun.
Critical MCP Integration Flaw Puts NGINX at Risk
Attackers can abuse the near-maximum severity flaw in nginx-ui to restart, create, modify, and delete NGINX configuration files.
Critical Nginx UI auth bypass flaw now actively exploited in the wild
A critical vulnerability in Nginx UI with Model Context Protocol (MCP) support is now being exploited in the wild for full server takeover without authentication.
Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover
CVE-2026-33032 exposes nginx-ui to unauthenticated takeover via MCP endpoint, impacting 2,600+ instances with active exploitation.
Critical nginx UI tool vulnerability opens web servers to full compromise
The MCP endpoint authentication weakness has been under active exploitation since March.
Exploited Vulnerability Exposes Nginx Servers to Hacking
Hackers are exploiting CVE-2026-33032, a critical remote takeover vulnerability in the Nginx UI management tool.
Critical Nginx-ui MCP Flaw Actively Exploited in the Wild
Critical nginx-ui MCP authentication bypass CVE-2026-33032 actively exploited with CVSS 9.8
Part of the PlainSec briefing for 2026-05-02