Dossier
nginx-ui
Coverage of nginx-ui in the Nexus archive.
- Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover
A critical authentication bypass vulnerability (CVE-2026-33032) in nginx-ui, a web-based Nginx management tool, is being actively exploited to enable full server takeover. The flaw, named MCPwn by Pluto Security, carries a CVSS score of 9.8, indicating severe risk.