Frequency
4
occurrences
First Seen
March 5, 2026
Last Seen
April 16, 2026
Related Threat Clusters
-
Critical NGINX UI Vulnerability CVE-2026-33032 Under Active Exploitation
A critical vulnerability in the nginx-ui web server management tool, tracked as CVE-2026-33032, has been actively exploited since March 2026. This flaw allows attackers to bypass authentication on the /mcp_message…
22 articles · Updated April 15, 2026 -
Critical CVE-2026-27944 Exposes Sensitive Data via Unauthenticated API Access
CVE-2026-27944 was published on March 5, 2026, revealing that the /api/backup endpoint is accessible without authentication, allowing unauthenticated attackers to download sensitive system backups. These backups can…
11 articles · Updated March 5, 2026
Recent Intelligence Reports
- CVE-2026-27944 — nvd.nist.gov · April 16, 2026
- Critical MCP Integration Flaw Puts NGINX at Risk — Darkreading · April 15, 2026
- A critical 9.8 CVSS flaw (CVE-2026-27944) in Nginx UI lets hackers download and decrypt ... — X · March 8, 2026
- CVE-2026-27944 - Exploits & Severity — Feedly · March 5, 2026