Skip to content
The Nexus
SECURITYApr 15 · 12:56 UTCTHE HACKER NEWS[email protected] (The Hacker News)

Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover

A critical authentication bypass vulnerability (CVE-2026-33032) in nginx-ui, a web-based Nginx management tool, is being actively exploited to enable full server takeover. The flaw, named MCPwn by Pluto Security, carries a CVSS score of 9.8, indicating severe risk.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this