Skip to content

CVE-2026-27944

CVE

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
March 5, 2026
Last Seen
April 16, 2026
API
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A critical vulnerability in the nginx-ui web server management tool, tracked as CVE-2026-33032, has been actively exploited since March 2026. This flaw allows attackers to bypass authentication on the /mcp_message endpoint, enabling full control over NGINX servers through a single unauthenticated AP...

CVE-2026-27944 was published on March 5, 2026, revealing that the /api/backup endpoint is accessible without authentication, allowing unauthenticated attackers to download sensitive system backups. These backups can contain user credentials, session tokens, SSL private keys, and Nginx configurations...

Public Exploits

Checking GitHub for proof-of-concept code…