A critical authentication bypass in nginx-ui tracked as CVE-2026-33032 is being actively exploited to seize control of internet-exposed Nginx servers. The flaw affects nginx-ui deployments with MCP support enabled because the POST /mcp_message endpoint enforced only IP whitelisting, while the default empty whitelist behaved as allow-all, leaving the endpoint reachable without authentication. Researchers said attackers can exploit the bug in seconds with minimal HTTP requests, then invoke MCP management functions to modify or delete Nginx configuration files, reload or restart services, redirect or intercept traffic, disrupt applications, and steal administrator credentials and other secrets.
Pluto Security reported the issue in March, and multiple security outlets said threat actors began exploiting it in the wild after technical details emerged. The vulnerability carries a CVSS 9.8 rating and impacts nginx-ui 2.3.5 and earlier, with fixes released starting in version 2.3.4 and later secure releases also available. Public reporting estimated roughly 2,600 to 2,700 exposed nginx-ui instances online, and Recorded Future and VulnCheck both flagged the bug as under active exploitation. Administrators have been urged to upgrade immediately, disable or restrict MCP access if patching is delayed, populate the IP whitelist with trusted hosts, and review logs for suspicious configuration changes or unauthorized reload activity.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
The Hacker News says Recorded Future listed CVE-2026-33032 among 31 vulnerabilities actively exploited by threat actors in March 2026. This indicated the flaw had moved from disclosure to observed exploitation activity.
On April 15, 2026, multiple outlets reported that CVE-2026-33032 was being actively exploited in the wild, enabling full takeover of nginx servers through the exposed /mcp_message endpoint. Reports cited Pluto Security research and external threat intelligence, including Recorded Future and VulnCheck.
BleepingComputer reports that public technical details and proof-of-concept exploit code for CVE-2026-33032 appeared later in March 2026. This expanded public understanding of how the flaw could be exploited.
The Canadian Centre for Cyber Security says Nginx UI disclosed the critical vulnerability CVE-2026-33032 on April 10, 2026. The notice said the issue affected version 2.3.5 and earlier and referenced open-source reporting of active exploitation.
A CVE feed entry described CVE-2026-33032 as affecting nginx-ui 2.3.5 and earlier and enabling unauthenticated remote takeover through the /mcp_message endpoint. It stated that no public patch was available at the time of that publication.
A GitHub security advisory described the authentication bypass in nginx-ui's MCP integration, explaining that inconsistent protection between /mcp and /mcp_message could allow remote attackers to take over nginx management functions. The advisory also outlined remediation to require authentication and change whitelist behavior to deny by default.
nginx-ui released version 2.3.4 to fix the missing authentication check on /mcp_message and add a regression test. Sources explicitly date the fix release to March 15, 2026.
Multiple sources state that Pluto Security reported the nginx-ui authentication bypass vulnerability in March 2026, with one source specifically saying the report was made on March 14, 2026. The flaw involved the /mcp_message endpoint allowing unauthenticated access to MCP functionality.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
10 references tracked. Mallory keeps watching after this page renders.
infosecwriteups.com
Open sourcecyber.gc.ca
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcedarkreading.com
Open sourcebleepingcomputer.com
Open sourcecvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.