INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Critical Nginx UI MCP Flaw Exploited in the Wild

| 2026-04-15 13:00 CRITICAL MEDIUM EXPLOITED VULNERABILITY ATTACK ON AI SYSTEMS
Executive Summary
AI-generated
The critical Nginx-ui MCP flaw has been actively exploited in the wild, allowing any network-adjacent attacker to take full control of an nginx server through a single unauthenticated API request. This vulnerability, tracked as CVE-2026-33032 with a CVSS score of 9.8, was discovered by Pluto Security and poses significant risks to organizations relying on nginx servers for their infrastructure. The flaw has been independently flagged by Recorded Future's Insikt Group in a recent report as one of the top 31 high-impact vulnerabilities exploited during March 2026, with a risk score of 94 out of 100.
Technical Mitigations AI-generated
• Update to version 2.3.4 or later • Disable MCP functionality entirely • Restrict network access to the management interface
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

mi•••••.authrequired
ap•••••.ini
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-27826CVE-2026-27826 CVE-2026-27825CVE-2026-27825 CVE-2026-27944CVE-2026-27944 CVE-2026-33032CVE-2026-33032
Target & Sectors
NORTH_AMERICA NORTH_AMERICA DACH DACH technologytechnology
Incident Timeline
‎March 15, 2026
Threat actors exploited the Critical Nginx UI auth bypass flaw in version 2.3.4 by using it to target an unknown entity on March 15, 2026.
infrastructure 2.3.4
‎March 15, a day
Researchers at Pluto Security AI reported a critical Nginx UI auth bypass flaw in version 2.3.4 on March 15.
infrastructure 2.3.4
organisation NGNIX
organisation Pluto Security AI
‎2026/03/16
Threat actors exploited a critical Nginx UI auth bypass flaw in the wild by targeting and compromising an affected system using the /mcp and /mcp_message HTTP endpoints.
organisation MCP
‎March 2026
Threat actors have been actively exploiting a critical Nginx UI auth bypass flaw since March 2026.
organisation Recorded Future's Insikt Group
general_metric 31 impact vulnerabilities
vulnerability CVE-2026-33032
organisation Recorded Future
‎2026/04/08
The latest secure version of nginx-ui, 2.3.6, was released last week and is now actively exploited in the wild by threat actors who used it to target systems with a vulnerable UI auth configuration.
infrastructure 2.3.6
‎Apr 15, 2026
Threat actors have discovered and are actively exploiting a critical vulnerability in the Nginx web server's User Interface authentication system.
‎2026/04/15
Threat actors used a critical Nginx UI auth bypass flaw to exploit the SSE (Session Establishment) vulnerability in the wild.
organisation Pluto Security's
organisation SSE
‎2026/04/15
The threat actors exploited the critical Nginx UI auth bypass flaw in nginx-ui, an open-source web-based management interface for the Nginx web server.
organisation TLS
organisation CVE-2026-33032
organisation CVSS
organisation Pluto Security
organisation API
organisation Actively Exploited
organisation MCP
organisation nginx-ui's
organisation the Model Context Protocol
infrastructure 3.4
organisation v2.3.4
organisation AI-Led Remediation Crisis Prompts HackerOne
organisation Pause Bug Bounties
infrastructure 2.3.4
organisation Update
organisation MCPwnfluence
organisation Critical Nginx-ui
organisation MCP Flaw Actively Exploited
organisation VulnCheck
organisation Known Exploited
organisation KEV
organisation Missing Middleware
organisation Nginx UI
organisation Model Context Protocol
organisation IP
organisation AuthRequired
organisation Trigger
organisation Shodan
organisation GitHub
organisation Docker
organisation DevOps
organisation Nginx
organisation Pluto Security
organisation The Hacker News
organisation Based on Pluto Security's
organisation LAN
organisation Critical Nginx UI
organisation NIST
organisation the National Vulnerability Database
organisation NVD
organisation PoC
infrastructure 3.3
infrastructure 2.3.3
organisation Critical MCP Integration
organisation Adobe Patches Actively
organisation UUID
organisation RBAC
organisation Omdia
organisation SOC
Tactical Metrics
Metrics
infrastructure
‎2.3.4
Software Version
Metrics
infrastructure
‎2.3.6
Software Version
Metrics
infrastructure
‎3.4
Software Version
Metrics
infrastructure
‎2.3.3
Software Version
Metrics
infrastructure
‎3.3
Software Version
Intelligence Sources
Infosecurity-Magazine 2026-04-15
Dark Reading 2026-04-15
Infosecurity-Magazine 2026-04-15