Infosecurity-Magazine Critical NGINX UI Vulnerability CVE-2026-33032 Under Active Exploitation
Article Content
- •CVE-2026-33032 allows unauthenticated access to critical NGINX management functions.
- •Over 2,600 nginx-ui instances are publicly exposed and vulnerable to exploitation.
- •A patch was released on March 15, 2026, but many systems remain unpatched.
A critical vulnerability in the nginx-ui web server management tool, tracked as CVE-2026-33032, has been actively exploited since March 2026. This flaw allows attackers to bypass authentication on the /mcp_message endpoint, enabling full control over NGINX servers through a single unauthenticated API request. Discovered by Pluto Security, the vulnerability has a CVSS score of 9.8 and affects numerous installations, with over 2,600 instances identified as publicly accessible. The nginx-ui maintainers released a patch (version 2.3.4) on March 15, 2026, but many systems remain unpatched. Attackers can leverage this vulnerability to modify server configurations, reload services, and intercept traffic. Organizations using nginx-ui are urged to update immediately or restrict access to the management interface. The vulnerability highlights risks associated with the integration of AI management protocols in web applications.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (26)
Following this threat?
Track Pluto Security and CVE-2025-55182 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Langflow AI Platform Targeted by RCE Exploitation In September 2026, the Langflow AI application-building platform faced significant exploitation attempts targeting CVE-2026-0768, an unauthenticated remote code execution vulnerability. F5 Labs reported 405 requests from 55 distinct source IPs, indicating a coordinated effort to exploit this flaw. The vulnerability…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…