CVE-2026-33032 is a vulnerability tracked across 1 threat cluster and 10 intelligence report mentions on ThreatCluster. First observed April 15, 2026; most recent activity April 16, 2026.
A critical vulnerability in the nginx-ui web server management tool, tracked as CVE-2026-33032, has been actively exploited since March 2026. This flaw allows attackers to bypass authentication on the /mcp_message…