Critical Nginx-ui MCP Flaw Actively Exploited in the Wild (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- CVE-2026-33032 with CVSS 9.8
- Authentication bypass in nginx-ui MCP
- Active exploitation confirmed
"A critical authentication bypass vulnerability (CVE-2026-33032, CVSS 9.8) in nginx-ui MCP is being actively exploited. Attackers can gain unauthorized access. Immediate patching is recommended."
no comments yet.