INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ATTENTION: This report is based on previous data. New intelligence sources have been linked and the Executive Summary and Mitigations need to be re-synthesized.

Critical Nginx UI auth bypass flaw now actively exploited in the wild

| 2026-04-15 13:00 CRITICAL MEDIUM
Executive Summary AI-generated
The critical Nginx UI auth bypass flaw has been actively exploited in the wild, allowing remote attackers to invoke privileged MCP actions without credentials. This vulnerability enables full server takeover without authentication, including restarting nginx, creating/modifying/deleting nginx configuration files, and triggering automatic config reloads - achieving complete nginx service takeover. The flaw is caused by nginx-ui leaving the '/mcp_message' endpoint unprotected, making it possible for attackers to invoke all MCP tools without authentication, including restarting nginx, creating/modifying/deleting nginx configuration files, and triggering automatic config reloads.
Technical Mitigations AI-generated
* Implement a secure authentication mechanism for all Nginx UI instances, including Model Context Protocol (MCP) support, to prevent unauthorized access and changes to server configurations. * Regularly update and patch the nginx-ui library to ensure that any known vulnerabilities or exploits are addressed before they can be used by attackers. * Use a web application firewall (WAF) or intrusion detection system (IDS) to monitor and block suspicious traffic patterns, reducing the risk of unauthorized access and attacks on Nginx UI instances. * Implement network segmentation and isolation techniques to limit the reach of potential attackers and prevent them from exploiting vulnerabilities in Nginx UI instances.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-27826CVE-2026-27826 CVE-2026-27825CVE-2026-27825 CVE-2026-27944CVE-2026-27944 CVE-2026-33032CVE-2026-33032
Target & Sectors
NORTH_AMERICA NORTH_AMERICA DACH DACH
Incident Timeline
‎March 15, 2026
Threat actors exploited the Critical Nginx UI auth bypass flaw in version 2.3.4 by using it to target an unknown entity on March 15, 2026.
infrastructure 2.3.4
‎March 15, a day
Researchers at Pluto Security AI reported a critical Nginx UI auth bypass flaw in version 2.3.4 on March 15.
infrastructure 2.3.4
organisation NGNIX
organisation Pluto Security AI
‎March 2026
Threat actors have been actively exploiting a critical Nginx UI auth bypass flaw since March 2026.
organisation Recorded Future's Insikt Group
general_metric 31 impact vulnerabilities
vulnerability CVE-2026-33032
organisation Recorded Future
‎2026/03/16
Threat actors exploited the Critical Nginx UI auth bypass flaw by using the /mcp and /mcp_message HTTP endpoints.
organisation MCP
‎2026/04/08
The latest secure version of nginx-ui, 2.3.6, was released last week and is now actively exploited in the wild by threat actors targeting systems with this vulnerable software.
infrastructure 2.3.6
‎Apr 15, 2026
Threat actors have discovered and are actively exploiting a critical vulnerability in the Nginx web server's User Interface authentication module.
‎2026/04/15
Threat actors used a critical Nginx UI auth bypass flaw to exploit the SSE (Session Establishment) vulnerability in the wild.
organisation Pluto Security's
organisation SSE
‎2026/04/15
The Nginx UI interface for managing NGINX web servers has a critical flaw that allows attackers to bypass authentication and take control of the server without credentials.
organisation TLS
organisation CVE-2026-33032
organisation CVSS
organisation Pluto Security
organisation API
organisation Actively Exploited
organisation MCP
organisation nginx-ui's
organisation the Model Context Protocol
infrastructure 3.4
organisation v2.3.4
organisation AI-Led Remediation Crisis Prompts HackerOne
organisation Pause Bug Bounties
infrastructure 2.3.4
organisation Update
organisation MCPwnfluence
organisation Critical Nginx-ui
organisation MCP Flaw Actively Exploited
organisation VulnCheck
organisation Known Exploited
organisation KEV
organisation Missing Middleware
organisation Nginx UI
organisation Model Context Protocol
organisation IP
organisation AuthRequired
organisation Trigger
organisation Shodan
organisation GitHub
organisation Docker
organisation DevOps
organisation Nginx
organisation Pluto Security
organisation The Hacker News
organisation Based on Pluto Security's
organisation LAN
organisation Critical Nginx UI
organisation NIST
organisation the National Vulnerability Database
organisation NVD
organisation PoC
infrastructure 3.3
infrastructure 2.3.3
organisation Critical MCP Integration
organisation Adobe Patches Actively
organisation UUID
organisation RBAC
organisation Omdia
organisation SOC
Tactical Metrics
Metrics
infrastructure
‎2.3.4
Software Version
Metrics
infrastructure
‎2.3.6
Software Version
Metrics
infrastructure
‎3.4
Software Version
Metrics
infrastructure
‎2.3.3
Software Version
Metrics
infrastructure
‎3.3
Software Version
Intelligence Sources
Infosecurity-Magazine 2026-04-15
Dark Reading 2026-04-15
Infosecurity-Magazine 2026-04-15