CVE-2026-27944Disclosure(nginxui / nginx_ui)

CRITICALCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 19 mentions and remains active

Immediate actions

  • Patch nginxui nginx_ui systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security response header. This allows an unauthenticated attacker to download a full system backup containing sensitive data (user credentials, session tokens, SSL private keys, Nginx configurations) and decrypt it immediately. This issue has been patched in version 2.3.3.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306CWE-311

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nginx_ui

Threat summary

  • Active exploitation appears in 8 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 88 mentions across 26 observed days

What's happening

  • Active exploitation reported across 8 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 19 signals
  • Patch or workaround mentioned in 22 signals
  • Technical details provided in 69 signals
  • Disclosure: 46 classified signals
  • General: 13 classified signals
  • Peaked 22d ago at 19 mentions (2026-03-08); latest day: 1
  • 88 total mentions across 26 days

Affected systems

Vendors
Products
nginx_ui

Deep dive

Activity timeline88 mentions / 26d
05101419Mentions · 2026-03-05: 2Mentions · 2026-03-06: 3Mentions · 2026-03-07: 1Mentions · 2026-03-08: 19Mentions · 2026-03-09: 19Mentions · 2026-03-10: 11Mentions · 2026-03-11: 5Mentions · 2026-03-12: 1Mentions · 2026-03-13: 2Mentions · 2026-03-15: 1Mentions · 2026-03-16: 1Mentions · 2026-03-17: 1Mentions · 2026-03-23: 3Mentions · 2026-03-24: 1Mentions · 2026-03-25: 1Mentions · 2026-03-26: 1Mentions · 2026-04-01: 2Mentions · 2026-04-11: 2Mentions · 2026-05-01: 1Mentions · 2026-05-11: 1Mentions · 2026-05-12: 3Mentions · 2026-05-13: 3Mentions · 2026-06-30: 1Mentions · 2026-07-12: 1Mentions · 2026-07-16: 1Mentions · 2026-07-22: 1PoC Mentioned / Linked · 2026-03-08: 3PoC Mentioned / Linked · 2026-03-09: 1PoC Mentioned / Linked · 2026-03-10: 3PoC Mentioned / Linked · 2026-03-11: 3PoC Mentioned / Linked · 2026-03-23: 1PoC Mentioned / Linked · 2026-04-01: 2PoC Mentioned / Linked · 2026-05-11: 1PoC Mentioned / Linked · 2026-05-12: 2PoC Mentioned / Linked · 2026-05-13: 1PoC Mentioned / Linked · 2026-07-12: 1PoC Mentioned / Linked · 2026-07-16: 1Exploit Tool / Code · 2026-03-10: 1Exploit Tool / Code · 2026-03-11: 1Active Exploitation · 2026-03-10: 1Active Exploitation · 2026-03-11: 1Active Exploitation · 2026-03-25: 1Active Exploitation · 2026-03-26: 1Active Exploitation · 2026-04-11: 1Active Exploitation · 2026-05-01: 1Active Exploitation · 2026-06-30: 1Active Exploitation · 2026-07-22: 1Patch / Workaround · 2026-03-05: 1Patch / Workaround · 2026-03-06: 1Patch / Workaround · 2026-03-07: 1Patch / Workaround · 2026-03-08: 5Patch / Workaround · 2026-03-09: 2Patch / Workaround · 2026-03-10: 5Patch / Workaround · 2026-03-11: 3Patch / Workaround · 2026-03-24: 1Patch / Workaround · 2026-03-26: 1Patch / Workaround · 2026-05-01: 1Patch / Workaround · 2026-07-16: 1Technical Details · 2026-03-05: 2Technical Details · 2026-03-06: 3Technical Details · 2026-03-07: 1Technical Details · 2026-03-08: 18Technical Details · 2026-03-09: 14Technical Details · 2026-03-10: 11Technical Details · 2026-03-11: 4Technical Details · 2026-03-13: 1Technical Details · 2026-03-15: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-23: 2Technical Details · 2026-03-24: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-26: 1Technical Details · 2026-04-01: 2Technical Details · 2026-05-01: 1Technical Details · 2026-05-11: 1Technical Details · 2026-05-13: 1Technical Details · 2026-07-12: 1Technical Details · 2026-07-16: 1Technical Details · 2026-07-22: 103-0503-0703-0903-1103-1303-1603-2303-2504-0105-0105-1206-3007-1607-22
Signal classification6 categories
Disclosure
4652.3%
General
1314.8%
PoC
1112.5%
Patch
1011.4%
Active Exploitation
78.0%
Exploit
11.1%
Referenced assets62 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-052
Disclosure1Patch1
2026-03-063
Disclosure2Patch1
2026-03-071
Patch1
2026-03-0819
Disclosure13General2Patch1PoC3
2026-03-0919
Disclosure17General2
2026-03-1011
Disclosure7Patch4
2026-03-115
Active Exploitation1Patch2PoC2
2026-03-121
General1
2026-03-132
Disclosure1General1
2026-03-151
Disclosure1
2026-03-161
Disclosure1
2026-03-171
General1
2026-03-233
Disclosure1General2
2026-03-241
Disclosure1
2026-03-251
Active Exploitation1
2026-03-261
Active Exploitation1
2026-04-012
Exploit1PoC1
2026-04-112
Active Exploitation1General1
2026-05-011
Active Exploitation1
2026-05-111
PoC1
2026-05-123
General1PoC2
2026-05-133
General2PoC1
2026-06-301
Active Exploitation1
2026-07-121
PoC1
2026-07-161
Disclosure1
2026-07-221
Active Exploitation1
Full discourse20 posts
  • Gray Hats@the_yellow_fall
    PoC

    A critical 9.8 CVSS flaw (CVE-2026-27944) in Nginx UI lets hackers download and decrypt full system backups via an open API. A proof-of-concept exploit for this flaw is available. Update and rotate secrets! https://securityonline.info/unauthenticated-nginx-ui-flaw-leaks-decryption-keys-and-server-secrets/ https://t.co/6HTqzw7Ll6

    Post summary

    A critical CVE-2026-27944 flaw in Nginx UI permits downloading and decrypting system backups; a proof‑of‑concept exploit is publicly available, and users are urged to update systems and rotate secrets.

    44101337610.1K
    10.6K followersView on X
  • NullSecurityX@NullSecurityX
    PoC

    NEW Videoo: CVE-2026-3888: Nginx-UI Backup Leak to Root Shell + CVE-2026-27944 Snap Copy-Fail Root New video covering a full Linux exploitation chain: Unauth API → Backup leak → Credential cracking → SSH → Snapd TOCTOU privesc → Root shell https://youtu.be/ViyT7bu-ZxE

    Post summary

    The post highlights a video that demonstrates a full exploitation chain for CVE-2026-3888 and CVE-2026-27944, offering technical details but no actual exploit code or active usage reports.

    011050226.7K
    12.3K followersView on X
  • Hack The Box@hackthebox_eu
    General

    New threats alert 🚨  Our latest Machine just dropped on HTB Labs and the Enterprise Platform, challenging you to chain two critical, newly disclosed vulnerabilities. You will first exploit CVE-2026-27944 to gain a foothold via an authentication bypass in Nginx UI, before leveraging a timing-based logic flaw in Ubuntu’s snapd (CVE-2026-3888) to escalate your privileges to root. Sharpen your skills on the new Machine here: https://okt.to/zUtK7u #HackTheBox #Cybersecurity #Nginx #Ubuntu #CVEs #Pentesting #LPE

    Post summary

    A new HTB Labs Enterprise Platform machine challenges users to exploit two newly disclosed CVEs—an authentication bypass in Nginx UI (CVE‑2026‑27944) followed by a timing-based logic flaw in Ubuntu snapd (CVE‑2026‑3888)—to achieve root privileges.

    07064114.0K
    242.0K followersView on X
  • Lupovis@LupovisDefence
    Active Exploitation

    We’re seeing CVE-2026-27944 hit our telemetry. Currently without a KEV inclusion. Unauthenticated access to /api/backup in Nginx UI versions lets an attacker download a full system bkp, and the response discloses the material needed to decrypt it via X-Backup-Security. Patch now https://t.co/jhdfx6R0IV

    Post summary

    The post reports active exploitation of CVE‑2026‑27944 via unauthenticated /api/backup access in Nginx UI and announces a vendor patch is available.

    112140276.9K
    552 followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    Critical Nginx UI flaw CVE-2026-27944 exposes server backups https://securityaffairs.com/189123/security/critical-nginx-ui-flaw-cve-2026-27944-exposes-server-backups.html

    Post summary

    The article announces a critical Nginx UI flaw (CVE-2026-27944) that exposes server backups, but provides no PoC, exploit details, or patch information.

    214143194.8K
    152.5K followersView on X
  • NullSecurityX@NullSecurityX
    General

    🚨 CVE-2026-3888: Nginx-UI Backup Leak to Root Shell + CVE-2026-27944 Snap Copy-Fail Root We’re going to have a lot of fun with this one 😈 Wait for tomorrow… Don’t forget to follow our YouTube channel: https://www.youtube.com/@NullSecurityX https://t.co/uwGx5EK8ws

    Post summary

    The tweet merely announces the existence of CVE-2026-3888 and CVE-2026-27944 and hints at upcoming content via a YouTube channel, providing no technical or exploit details.

    19041132.4K
    12.3K followersView on X
  • 0xdf@0xdf_
    PoC

    Snapped from @hackthebox_eu features CVE-2026-27944 to download and decrypt Nginx UI backups without auth, bcrypt cracking for a shell, and CVE-2026-3888 to exploit a snapd race condition for root. https://0xdf.gitlab.io/2026/04/01/htb-snapped.html

    Post summary

    The tweet highlights two newly disclosed CVEs—CVE‑2026‑27944 and CVE‑2026‑3888—providing a concise technical overview of how to exploit them (downloading and decrypting Nginx backups, bcrypt cracking, and a snapd race condition for root) and linking to a detailed PoC article.

    0401982.1K
    26.5K followersView on X
  • GreyNoise@GreyNoiseIO
    Active Exploitation

    This week in GreyNoise data, rented crawlers probed for credentials and configuration secrets across widely deployed web software. A matched pair of crawlers sharing one client fingerprint probed NGINX UI (CVE-2026-27944) and LiteSpeed Cache (CVE-2024-44000), two CVSS 9.8 flaws that leak credentials, private keys, or session material, from two different hosting providers. Alongside them, an RDP brute force cohort spread across three networks under one transport fingerprint. WordPress core SQL injection CVE-2026-60137 also entered the CISA KEV catalog this week. The rented hosts rotate; the fingerprints persist. Customers get the full weekly brief. Our public At The Edge Clear one-pager 👉https://www.greynoise.io/resources/at-the-edge-clear-072026

    Post summary

    GreyNoise reports active probing and exploitation of CVE-2026-27944, CVE-2024-44000, and CVE-2026-60137, with evidence of real‑world attacks and inclusion in the CISA KEV catalog.

    020641.7K
    29.4K followersView on X
  • blueblue@piedpiper1616
    Disclosure

    Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure · CVE-2026-27944 · GitHub Advisory Database · GitHub - https://github.com/advisories/GHSA-g9w5-qffc-6762

    Post summary

    The advisory announces CVE-2026-27944, highlighting an unauthenticated backup download vulnerability in Nginx-UI that exposes the encryption key.

    04050713
    5.5K followersView on X
  • kokumօtօ@__kokumoto
    PoC

    Nginx UIにサーババックアップ露出の重大(Critical)な脆弱性。CVE-2026-27944はCVSSスコア9.8で、/api/backupがバックアップ復号用の暗号鍵を無認証でお漏らしするもの。PoC(攻撃の概念実証コード)公開済み。管理画面を公開する奴が悪い。バージョン2.3.3で修正。 https://securityaffairs.com/189123/security/critical-nginx-ui-flaw-cve-2026-27944-exposes-server-backups.html

    Post summary

    The post confirms a PoC was published for CVE-2026-27944, details the vulnerability with a high CVSS score, and notes a patch in version 2.3.3, but provides no evidence of active exploitation or a specific exploit tool.

    020251.3K
    7.3K followersView on X
  • ET Labs@ET_Labs
    General

    35 new OPEN, 66 new PRO (35 + 31) ACR Stealer, Katana Botnet, Lumma Stealer, NetSupport RAT, TA4903, TA569, XWorm, FreePBX (CVE-2026-28287), Linksys (CVE-2025-34037), Microsoft Exchange (CVE-2021-28480, CVE-2021-28481), Nginx-ui (CVE-2026-27944) and more. https://community.emergingthreats.net/t/ruleset-update-summary-2026-03-17-v11150/3235 https://t.co/SNltFetetX

    Post summary

    The post lists several newly identified vulnerabilities in the emerging threats ruleset, referencing CVE identifiers with no further technical details or exploitation information.

    03050465
    5.7K followersView on X
  • Mr. OS@ksg93rd
    Disclosure

    #exploit #reversing 1⃣ Getting a Shell on the Tapo C260 Camera (CVE-2026-0651, CVE-2026-0652, CVE-2026-0653) https://spaceraccoon.dev/getting-shell-tapo-c260-webcam // Reverse-engineered Tapo C260 firmware reveals vulnerabilities enabling local file disclosure and full RCE through path traversal and configuration manipulation 2⃣ nginx UI Vulnerability https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-g9w5-qffc-6762 // CVE-2026-27944 (9.8/10) 3⃣ Patch diff to SYSTEM https://www.elastic.co/security-labs/patch-diff-to-system // Researchers utilized LLMs and patch diffing to develop a reliable privilege escalation exploit for Windows DWM via a UAF, demonstrating AI's growing role in vulnerability discovery and exploitation 4⃣ Reverse engineering Claude's CVE-2026-2796 exploit https://red.anthropic.com/2026/exploit ]-> Claude Code skill to support Android app's reverse engineering https://github.com/SimoneAvogadro/android-reverse-engineering-skill

    Post summary

    The text announces several new CVEs, providing PoC links, technical details of the vulnerabilities, and evidence of exploitation tools, but it contains no evidence of active exploitation or patches.

    10024544
    3.2K followersView on X
  • connect24h@connect24h
    Disclosure

    2026年3月の脆弱性何で、みんな、対処済みだよな? これは洒落にならない。Nginx UIのバックアップ一式が認証なしで抜ける(CVE-2026-27944、CVSS 9.8)。 2.3.3未満では /api/backup に認証がなく、復号用のAES-256 keyとIVまで X-Backup-Security headerで返す。database、session token、ユーザー認証情報、Nginx設定、SSL private keyが即座に復号可能。2026年3月からPoCも公開済みだ。 現場で怖いのは「updateしたから終了」にすること。まずversionとInternet exposureを棚卸しし、reverse proxy/WAF logの GET /api/backup を遡る。痕跡があればsession無効化、credentialとSSL keyのrotationまで実施してほしい。2.3.3以上への更新と外部公開制限は最優先。CSIRT初動checklistとして保存推奨。 #セキュリティ

    Post summary

    The post announces CVE‑2026‑27944, shares technical details, notes that a PoC has been released, and urges users to update to v2.3.3+ and harden exposure.

    100411.2K
    6.8K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-27944 - critical 🚨 Nginx UI < 2.3.3 - Information Disclosure > Nginx UI < 2.3.3 contains an information disclosure vulnerability caused by unauthent... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-27944 @pdnuclei #NucleiTemplates #cve

    Post summary

    ProjectDiscovery discloses a critical information‑disclosure vulnerability in Nginx UI <2.3.3 and provides a link that likely hosts a PoC, but no active exploitation, patch, or debunking is mentioned.

    11030324
    903 followersView on X
  • maru@maru1151157
    Patch

    🚨 CVE-2026-27944 (CVSS: 9.8) ニックスUIのバージョン2.3.3以前では、/api/backupエンドポイントが未認証でアクセス可能で、X-Backup-Securityヘッダーに暗号化キーを暴露。攻撃者はバックアップをダウンロード・復号可能となり、センシティブなデータが漏洩する。2.3.3で修正。 https://maruomosquit.com/vulnerability/CVE-2026-27944/ #脆弱性 #セキュリティ

    Post summary

    CVE-2026-27944 exposes an un‑authenticated /api/backup endpoint that leaks an encryption key via the X-Backup-Security header, allowing attackers to download and decrypt backups, resulting in data compromise; the issue is fixed in version 2.3.3.

    10040305
    1.5K followersView on X
  • akvn@0xAkvn
    Patch

    There is a new vulnerability in Nginx UI that allows unauthenticated attackers to download a full system backup containing sensitive data and decrypt it immediately (CVE-2026-27944). Make sure to upgrade to the latest version if you are using it! https://t.co/8TAqXJhmMg

    Post summary

    The tweet announces CVE-2026-27944, which lets unauthenticated users download and decrypt a full system backup, and urges users to upgrade to the latest version to mitigate the risk.

    01030139
    367 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical missing authentication vulnerability in #Nginx UI. Attackers can download the system backup leading to sensitive information disclosure and full system compromise. CVE-2026-27944 CVSS:9.8. #Patch https://ccb.belgium.be/advisories/warning-critical-missing-authentication-vulnerability-nginx-ui-leads-full-system

    Post summary

    A critical missing authentication vulnerability (CVE‑2026‑27944, CVSS 9.8) in Nginx UI lets attackers download system backups, exposing sensitive data and enabling full system compromise; a patch is available via the provided advisory link.

    00112369
    7.2K followersView on X
  • VulnTracker@vuln_tracker
    PoC

    @the_yellow_fall This Nginx UI vulnerability (CVE-2026-27944) is scary! CVSS 9.8 + PoC available + system backup access = nightmare scenario. If you're running Nginx UI, this needs immediate attention. Thanks for the heads up with the visual proof! Track and monitor: https://vulntracker.io/cves/CVE-2026-27944

    Post summary

    A PoC for CVE-2026-27944 is available, indicating a severe vulnerability with high CVSS and backup access impact; no exploitation or patch information is disclosed.

    00040890
    394 followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Disclosure

    Nginx UI Vulnerabilities Let Attackers Download Full System Backups https://gbhackers.com/nginx-ui-vulnerabilities/ "Tracked as CVE-2026-27944, this vulnerability carries a maximum critical severity score of 9.8 out of 10."

    Post summary

    A new vulnerability, CVE‑2026‑27944, is disclosed with a high severity score of 9.8/10, yet no PoC, exploit details, or mitigation information is provided.

    10101306
    3.4K followersView on X
  • Directoratul Național de Securitate Cibernetică@DNSC_RO
    Disclosure

    🚨 ALERTĂ - Vulnerabilitate critică în Nginx UI ⚠️ CVE-2026-27944 este o vulnerabilitate critică de securitate, cu scor CVSS v3 de 9.8, care afectează aplicația Nginx UI, o interfață web folosită pentru administrarea serverelor Nginx. 👉 https://www.dnsc.ro/citeste/alerta-vulnerabilitate-critica-in-nginx-ui #DNSC #Alert https://t.co/zITmfNCAjb

    Post summary

    The tweet announces the discovery of CVE-2026-27944, a critical vulnerability (CVSS 9.8) affecting the Nginx UI web interface, without providing PoC, exploits, or mitigation details.

    02010164
    4.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnginxuinginx_ui---

Explore more