CVE-2026-33032Active Exploitation(nginxui / nginx_ui)

CRITICALCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 57 mentions and remains active

Immediate actions

  • Patch nginxui nginx_ui systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message. While /mcp requires both IP whitelisting and authentication (AuthRequired() middleware), the /mcp_message endpoint only applies IP whitelisting - and the default IP whitelist is empty, which the middleware treats as "allow all". This means any network attacker can invoke all MCP tools without authentication, including restarting nginx, creating/modifying/deleting nginx configuration files, and triggering automatic config reloads - achieving complete nginx service takeover. At time of publication, there are no publicly available patches.

9.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nginx_ui

Threat summary

  • Active exploitation appears in 118 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 204 mentions across 32 observed days

What's happening

  • Active exploitation reported across 118 signals
  • Exploit tool or code specified in 6 signals
  • PoC mentioned or linked in 27 signals
  • Patch or workaround mentioned in 66 signals
  • Technical details provided in 170 signals
  • Disclosure: 47 classified signals
  • General: 20 classified signals
  • Peaked 23d ago at 57 mentions (2026-04-16); latest day: 1
  • 204 total mentions across 32 days

Affected systems

Vendors
Products
nginx_ui

Deep dive

Activity timeline204 mentions / 32d
014294357Mentions · 2026-03-30: 4Mentions · 2026-03-31: 4Mentions · 2026-04-01: 4Mentions · 2026-04-02: 1Mentions · 2026-04-03: 2Mentions · 2026-04-04: 1Mentions · 2026-04-08: 1Mentions · 2026-04-15: 54Mentions · 2026-04-16: 57Mentions · 2026-04-17: 19Mentions · 2026-04-18: 6Mentions · 2026-04-19: 4Mentions · 2026-04-20: 10Mentions · 2026-04-21: 1Mentions · 2026-04-22: 4Mentions · 2026-04-23: 3Mentions · 2026-04-24: 2Mentions · 2026-04-25: 1Mentions · 2026-04-27: 6Mentions · 2026-04-28: 1Mentions · 2026-05-01: 2Mentions · 2026-05-06: 2Mentions · 2026-05-11: 3Mentions · 2026-05-12: 2Mentions · 2026-05-15: 1Mentions · 2026-05-16: 1Mentions · 2026-05-18: 2Mentions · 2026-05-19: 1Mentions · 2026-05-25: 1Mentions · 2026-06-19: 2Mentions · 2026-06-25: 1Mentions · 2026-09-17: 1PoC Mentioned / Linked · 2026-03-31: 2PoC Mentioned / Linked · 2026-04-01: 2PoC Mentioned / Linked · 2026-04-15: 6PoC Mentioned / Linked · 2026-04-16: 10PoC Mentioned / Linked · 2026-04-17: 2PoC Mentioned / Linked · 2026-04-19: 1PoC Mentioned / Linked · 2026-04-27: 1PoC Mentioned / Linked · 2026-05-12: 1PoC Mentioned / Linked · 2026-05-16: 1PoC Mentioned / Linked · 2026-05-18: 1Exploit Tool / Code · 2026-03-31: 1Exploit Tool / Code · 2026-04-15: 2Exploit Tool / Code · 2026-04-16: 1Exploit Tool / Code · 2026-04-23: 1Exploit Tool / Code · 2026-05-16: 1Active Exploitation · 2026-04-15: 44Active Exploitation · 2026-04-16: 38Active Exploitation · 2026-04-17: 10Active Exploitation · 2026-04-18: 5Active Exploitation · 2026-04-19: 1Active Exploitation · 2026-04-20: 6Active Exploitation · 2026-04-21: 1Active Exploitation · 2026-04-22: 3Active Exploitation · 2026-04-23: 3Active Exploitation · 2026-04-24: 1Active Exploitation · 2026-04-27: 3Active Exploitation · 2026-05-01: 1Active Exploitation · 2026-05-15: 1Active Exploitation · 2026-05-16: 1Patch / Workaround · 2026-03-30: 1Patch / Workaround · 2026-03-31: 3Patch / Workaround · 2026-04-01: 3Patch / Workaround · 2026-04-03: 1Patch / Workaround · 2026-04-04: 1Patch / Workaround · 2026-04-08: 1Patch / Workaround · 2026-04-15: 14Patch / Workaround · 2026-04-16: 22Patch / Workaround · 2026-04-17: 6Patch / Workaround · 2026-04-18: 3Patch / Workaround · 2026-04-20: 4Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-04-22: 2Patch / Workaround · 2026-04-23: 1Patch / Workaround · 2026-04-28: 1Patch / Workaround · 2026-05-01: 1Patch / Workaround · 2026-05-16: 1Technical Details · 2026-03-30: 3Technical Details · 2026-03-31: 4Technical Details · 2026-04-01: 4Technical Details · 2026-04-02: 1Technical Details · 2026-04-03: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-15: 47Technical Details · 2026-04-16: 48Technical Details · 2026-04-17: 17Technical Details · 2026-04-18: 3Technical Details · 2026-04-19: 4Technical Details · 2026-04-20: 10Technical Details · 2026-04-21: 1Technical Details · 2026-04-22: 3Technical Details · 2026-04-23: 3Technical Details · 2026-04-24: 2Technical Details · 2026-04-25: 1Technical Details · 2026-04-27: 4Technical Details · 2026-04-28: 1Technical Details · 2026-05-01: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-11: 2Technical Details · 2026-05-12: 1Technical Details · 2026-05-15: 1Technical Details · 2026-05-16: 1Technical Details · 2026-05-18: 2Technical Details · 2026-05-25: 1Technical Details · 2026-06-19: 1Technical Details · 2026-06-25: 103-3004-0204-0804-1704-2004-2304-2705-0605-1505-1906-2509-17
Signal classification5 categories
Active Exploitation
11556.4%
Disclosure
4723.0%
General
209.8%
Patch
157.4%
PoC
73.4%
Referenced assets103 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-304
Disclosure3General1
2026-03-314
Disclosure1Patch1PoC2
2026-04-014
Disclosure3PoC1
2026-04-021
Disclosure1
2026-04-032
General1Patch1
2026-04-041
Patch1
2026-04-081
Disclosure1
2026-04-1554
Active Exploitation44Disclosure8Patch2
2026-04-1657
Active Exploitation36Disclosure9General4Patch7PoC1
2026-04-1719
Active Exploitation10Disclosure5General2Patch1PoC1
2026-04-186
Active Exploitation5Patch1
2026-04-194
Active Exploitation1Disclosure2PoC1
2026-04-2010
Active Exploitation6Disclosure3Patch1
2026-04-211
Active Exploitation1
2026-04-224
Active Exploitation2Disclosure2
2026-04-233
Active Exploitation3
2026-04-242
Active Exploitation1General1
2026-04-251
Disclosure1
2026-04-276
Active Exploitation3Disclosure3
2026-04-281
Disclosure1
2026-05-012
Active Exploitation1General1
2026-05-062
General2
2026-05-113
General3
2026-05-122
General1PoC1
2026-05-151
Active Exploitation1
2026-05-161
Active Exploitation1
2026-05-182
Disclosure2
2026-05-191
General1
2026-05-251
General1
2026-06-192
Disclosure1General1
2026-06-251
Disclosure1
2026-09-171
General1
Full discourse20 posts
  • Anis Haboubi |₿|@HaboubiAnis
    Disclosure

    Cyberpandémie : Prise de contrôle totale de Nginx sans login ! CVE-2026-33032 L’endpoint MCP /mcp_message est ouvert à Internet (IP whitelist vide par défaut). Un attaquant peut réécrire n’importe quelle config Nginx et reloader → contrôle complet. https://t.co/fIqOpAS0ZQ

    Post summary

    The post announces CVE-2026-33032, stating that the MCP /mcp_message endpoint is publicly exposed with no IP whitelist, allowing an attacker to reconfigure Nginx and achieve full control, but no PoC, exploit, or patch information is included.

    942420216333.2K
    5.0K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 A critical nginx-ui flaw is now exploited in the wild. CVE-2026-33032 (9.8) allows auth bypass via the /mcp_message endpoint, letting attackers take full control of Nginx with two HTTP requests due to an “allow-all” default. 🔗 Details here → https://thehackernews.com/2026/04/critical-nginx-ui-vulnerability-cve.html

    Post summary

    CVE-2026-33032 is an auth bypass in nginx-ui that allows full control via two HTTP requests; it is reportedly being exploited in the wild, yet no patch or PoC has been provided in the text.

    46521505121.0K
    1.7M followersView on X
  • yousukezan@yousukezan
    PoC

    Nginx UIに致命的な欠陥が見つかり、未認証でサーバーを完全制御される危険が浮上した。すでにPoCも公開されており、修正未提供のまま攻撃が現実化する可能性が高まっている。 CVE-2026-33032はCVSS 9.8の重大脆弱性で、MCP連携機能の設計不備に起因する。/mcp_messageエンドポイントがIPホワイトリストのみで保護されているが、初期設定が空の場合に「全許可」と解釈されるため、誰でもアクセス可能となる。この状態では攻撃者が認証なしで設定変更や内部操作を実行でき、通信の改ざんや資格情報の窃取、設定情報の取得、サービス停止などが可能となる。特に設定書き換えによるトラフィック乗っ取りは深刻で、管理者の認証情報も奪取され得る。全バージョンが影響を受け、現時点で修正は未提供。対策としては該当エンドポイントへの認証追加やアクセス制限の強化が推奨されている。早急な手動対処が不可欠な状況となっている。 https://securityonline.info/nginx-ui-poc-disclosed-critical-vulnerability-cve-2026-33032/

    Post summary

    Nginx UI CVE-2026-33032 is a critical vulnerability allowing unauthenticated attackers to modify configuration and hijack traffic via the /mcp_message endpoint; a PoC is already public, no patch exists yet, and immediate manual mitigation is recommended.

    050294349.1K
    14.3K followersView on X
  • Rapid7@rapid7
    Active Exploitation

    🚨 On 3/30/26, a security advisory was published for CVE-2026-33032 – a critical vulnerability affecting #NginxUI. This is a missing authentication bug with a CVSS score of 9.8, and exploitation in the wild has begun. More from Rapid7: https://r-7.co/4mzAr7G https://t.co/9ugkW7IF5P

    Post summary

    An advisory for CVE‑2026‑33032 highlights a critical missing‑authentication flaw in NginxUI with a CVSS of 9.8, noting that exploitation has begun in the wild, but provides neither a PoC nor any patch details.

    325069206.0K
    124.5K followersView on X
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-33032 (CVSS 9.8): Unauthenticated /mcp_message exposure may allow remote Nginx takeover. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJOZ2lueC1VSSI= 🎯14.3K+ Results are currently visible on https://en.fofa.info. FOFA Query: app="Nginx-UI" 🔖Refer: https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-h6c2-x2m2-mwhf #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The post announces CVE-2026-33032, detailing a remote takeover vulnerability in Nginx, with an FOFA search result count and a link to a GitHub advisory, but it provides no PoC, exploit code, or evidence of active exploitation.

    09032232.7K
    14.3K followersView on X
  • Sekurak@Sekurak
    Disclosure

    ❌ Badacze z Pluto Security odkryli krytyczną podatność (CVE-2026-33032) w Nginx UI. Endpoint /mcp_message nie miał pełnego uwierzytelniania, a whitelista IP była domyślnie pusta i dopuszczała wszystkie adresy. ❌ Atakujący mógł zmieniać konfigurację nginx, restartować usługę i odczytywać pliki konfiguracyjne. Problem naprawiono w wersji 2.3.4. Administratorzy powinni zaktualizować instancje i ograniczyć ich dostępność. ❌ Czytaj więcej: https://sekurak.pl/jak-mozna-bylo-zmieniac-konfiguracje-przez-endpoint-mcp-podatnosc-w-nginx-ui/

    Post summary

    The post reports a critical CVE‑2026‑33032 in Nginx UI that allowed unauthenticated configuration changes and reads, which has been corrected in v2.3.4; administrators are urged to patch and limit access.

    0503177.0K
    43.9K followersView on X
  • Yotam Perkal@pyotam2
    Active Exploitation

    CVE-2026-33032: unauthenticated RCE-like takeover path in nginx-ui via the exposed /mcp_message MCP endpoint - now actively exploited in the wild See writeup for additional details: https://pluto.security/blog/mcp-bug-nginx-security-vulnerability-cvss-9-8/ https://t.co/hpE7qXj9Wo

    Post summary

    CVE-2026-33032 is an unauthenticated RCE-like vulnerability in nginx‑ui that is reportedly being actively exploited in the wild, with additional technical details and PoC information available in a referenced blog post.

    18022121.6K
    619 followersView on X
  • Gray Hats@the_yellow_fall
    PoC

    Public PoC code and full details are out for a 9.8 CVSS flaw in Nginx UI (CVE-2026-33032). With no official patch, servers are at risk. Secure yours now! #NginxUI #CVE #PoC #CyberSecurity #ZeroDay #InfoSec #ServerSecurity #ExploitDisclosed https://securityonline.info/nginx-ui-poc-disclosed-critical-vulnerability-cve-2026-33032/ https://t.co/AaJStGbVsl

    Post summary

    Public proof‑of‑concept code for the CVE‑2026‑33032 critical vulnerability in Nginx UI has been released, with no patch available, leaving servers exposed.

    03019111.4K
    12.3K followersView on X
  • Pluto Security@pluto_security
    Active Exploitation

    Our research team disclosed CVE-2026-33032, a critical CVSS 9.8 vulnerability in nginx-ui that exposed over 500K users to full server takeover through a single unauthenticated request. No credentials. No exploit chain. Actively exploited in the wild. The root cause: MCP endpoints that inherit an application's full capabilities but skip its security controls entirely. The pattern is clear - and it's only getting more common as agentic workflows connect deeper into enterprise workspace infrastructure. Most security teams have no visibility into what MCP servers are running in their environment, no inventory of the endpoints they're exposing, and no way to enforce it. Full breakdown → https://lnkd.in/dmbkkQAp As covered by The Hacker News → https://lnkd.in/gWTZt4e4

    Post summary

    The disclosure announces a critical nginx‑ui vulnerability (CVE‑2026‑33032) that has been actively exploited in the wild, exposing over 500K users to full server takeover via unauthenticated requests.

    2302141.3K
    2.2K followersView on X
  • TangentCash ✨@tangentcash
    Active Exploitation

    🚨 JUST IN: "MCPwn" flaw (CVE-2026-33032) in nginx-ui is actively exploited. CVSS 9.8! Attackers bypass auth on /mcp_message to seize full Nginx control. 🤖 2,689 exposed instances identified globally. 🛑 Update to v2.3.4 IMMEDIATELY or disable MCP! Also: "MCPwnfluence" chaining RCE via Atlassian MCP. Details: https://thehackernews.com/2026/04/critical-nginx-ui-vulnerability-cve.html

    Post summary

    CVE-2026-33032 in nginx‑ui is being actively exploited with a high CVSS score; immediate patch to v2.3.4 or disabling of MCP is recommended.

    11201501.3K
    867 followersView on X
  • Nicolas Krassas@Dinosn
    Active Exploitation

    Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover https://thehackernews.com/2026/04/critical-nginx-ui-vulnerability-cve.html

    Post summary

    The headline reports that CVE‑2026‑33032 is being actively exploited to take over Nginx servers, but provides no proof‑of‑concept, patch information, or detailed technical description.

    050841.5K
    157.5K followersView on X
  • kking@_r00tuser
    Patch

    #CVE-2026-33032 https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-h6c2-x2m2-mwhf 这个漏洞根本没法利用,没有第一步/mcp获取sessionId(需要认证),/mcp_message 根本过不去,会报Missing sessionId。 我使用官方的docker镜像进行了测试,发现v2.3.3 及以上已经修复了/mcp_message认证的问题,v2.3.2还存在这个问题。有漏洞真实性审查吗? https://t.co/v6BI4jVpqo

    Post summary

    The user reports CVE‑2026‑33032 is not exploitable, confirms the patch in newer nginx‑ui versions, and links to the GitHub advisory.

    00072655
    772 followersView on X
  • Hunt.io@Huntio
    Active Exploitation

    ⚠️ Nginx UI flaw enables full takeover without auth https://www.bleepingcomputer.com/news/security/critical-nginx-ui-auth-bypass-flaw-now-actively-exploited-in-the-wild/ A critical nginx-ui vulnerability (CVE-2026-33032) is now being actively exploited. An exposed “/mcp_message” endpoint allows attackers to execute privileged actions without authentication: modifying configs, triggering reloads, and taking over servers with a single request. Public PoCs are available, and thousands of instances remain exposed. If you’re running nginx-ui, update immediately and restrict external access to reduce risk. #Nginx #CyberSecurity #Infosec #Appsec

    Post summary

    CVE‑2026‑33032, a critical nginx‑ui authentication bypass, is currently being exploited in the wild with publicly available PoCs, and administrators should immediately patch and restrict external access.

    01052846
    6.4K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-33032 - critical 🚨 Nginx UI - Broken Access Control > Network attackers can fully control nginx service, including config modification and ... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-33032 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE‑2026‑33032 as a critical Nginx UI broken access‑control flaw that allows attackers full service control; no PoC, exploit, patch, or active exploitation details are provided.

    01052313
    958 followersView on X
  • Threat Intelligence@threatintel
    General

    #ThreatProtection #CVE-2026-33032 - #Nginxui Nginx UI Auth Bypass #vulnerability, read more about Symantec's protection: https://www.broadcom.com/support/security-center/protection-bulletin/cve-2026-33032-nginxui-nginx-ui-auth-bypass-vulnerability

    Post summary

    The tweet links to a Symantec protection bulletin for CVE‑2026‑33032 but provides no additional technical, PoC, exploit, or patch details.

    020321.7K
    115.1K followersView on X
  • Sam Stepanyan@securestep9
    Active Exploitation

    #Nginx: A critical vulnerability CVE-2026-33032 in Nginx UI with Model Context Protocol (#MCP) support is now being exploited in the wild for full server takeover without authentication. 👇 https://www.bleepingcomputer.com/news/security/critical-nginx-ui-auth-bypass-flaw-now-actively-exploited-in-the-wild/

    Post summary

    CVE-2026-33032, an Nginx UI vulnerability, is actively exploited in the wild, enabling attackers to take over servers without authentication.

    20040323
    7.4K followersView on X
  • Modat@modat_magnify
    Disclosure

    CVE-2026-33032  ⚠️ Nginx UI – Unauthenticated Remote Takeover (CVSS 9.8)  A critical flaw in Nginx UI ≤2.3.5 allows unauthenticated attackers to access the /mcp_message endpoint due to missing authentication and a fail-open IP whitelist.  Attackers can execute MCP actions, modify configs, reload services, and fully take over the Nginx instance.  There is no publicly available patch yet. Restrict external access immediately.  Modat Magnify Query: 
web.title~"nginx ui"  The platform:  https://magnify.modat.io/  #threatintel #vulnerability #CVE202633032 #Nginx #RCE #infosec #AppSec #Critical #ModatMagnify

    Post summary

    The post discloses a critical Nginx UI vulnerability (CVSS 9.8) that allows unauthenticated remote takeover, notes that no patch is currently available, and advises immediate restriction of external access.

    00033589
    407 followersView on X
  • LA₿ 312 | 🛡️InfoSec & Self-Custody 🔑@Lab312_
    Disclosure

    🔴 CVE-2026-33032 — CVSS 9.8 ⚠️ Avant de paniquer: ceci ne concerne PAS Nginx. Ça concerne Nginx UI — un projet tiers complètement différent. Nginx = le serveur web/reverse proxy que 80% du web utilise. Nginx UI = une interface web (optionnelle, tierce) pour gérer Nginx via le navigateur. La faille: → Nginx UI intègre un serveur MCP (Model Context Protocol) → Deux endpoints exposés : /mcp et /mcp_message → /mcp exige une auth ✅ → /mcp_message exige juste un filtrage IP… dont la whitelist est vide par défaut → Whitelist vide = tout le monde passe 💀 Impact: → Redémarrer Nginx à distance → Créer / modifier / supprimer les fichiers de config → Prise de contrôle totale du serveur web → Aucune authentification requise → Versions ≤ 2.3.5 — pas de patch dispo à ce jour Leçons: Une interface d'admin web, c'est une surface d'attaque. Toujours. "Whitelist vide = autoriser tout" est un design pattern catastrophique Deux endpoints du même service qui n'appliquent pas les mêmes règles de sécurité = incohérence fatale MCP est un protocole puissant, mais mal sécurisé, il donne les clés du serveur. Si vous administrez Nginx : → Vérifiez que vous n'avez PAS Nginx UI installé → Si oui, coupez-le ou restreignez l'accès réseau immédiatement → Surveillez le projet pour un patch La config Nginx par fichiers .conf en CLI reste la méthode la plus sûre. Les interfaces "faciles" rajoutent toujours de la surface d'attaque. #Cybersécurité #CVE #NginxUI #MCP #OpSec

    Post summary

    The post announces CVE‑2026‑33032, detailing a no‑auth remote‑control flaw in Nginx UI, and advises administrators to block or restrict access and monitor for a patch.

    01041411
    2.7K followersView on X
  • Elusive@ElusivePrivacy
    Active Exploitation

    CVE-2026-33032 — nginx-ui auth bypass. CVSS 9.8. Actively exploited. PoC public.The /mcp_message endpoint has zero authentication. Two HTTP requests. Full server takeover no credentials, no JWT, nothing.Attacker gains: nginx config rewrite, traffic interception, credential harvesting, SSL private key theft.2,689 instances exposed on Shodan right now.Patch: v2.3.4. If not immediate → add AuthRequired() to /mcp_message or flip IP allowlist to deny-all. Source: https://t.me/VulnerabilityNews/41950 @TheHackersNews / @pluto_security

    Post summary

    CVE-2026-33032 is a high‑severity (CVSS 9.8) authentication bypass in nginx‑ui that is actively exploited and has a publicly available PoC. A patch (v2.3.4) is available, and workarounds such as adding AuthRequired() to /mcp_message or configuring IP allowlists are recommended.

    12020229
    184 followersView on X
  • DFIR Radar@DFIR_Radar
    Patch

    CVE-2026-33032 (CVSS 9.8) in nginx-ui allows unauthenticated attackers to fully compromise nginx servers via missing auth on /mcp_message endpoint. Over 2,600 public instances identified. Update to v2.3.4 immediately or disable MCP functionality. #DFIR_Radar https://t.co/ZYeRNVNWnd

    Post summary

    The disclosure details a severe CVE-2026-33032 flaw in nginx-ui that permits unauthenticated takeover through an unauthenticated /mcp_message endpoint, and immediately recommends updating to v2.3.4 or disabling MCP functionality.

    11030296
    1.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnginxuinginx_ui---

Explore more