Organizations/security vendor

Recorded Future

1 records1 attackWebsite
Apr 15, 2026
MCPwn: unauthenticated MCP endpoint in nginx-ui exploited in the wild (CVE-2026-33032)
AttackVulnerability disclosurePluto Security, Recorded Future, nginx-ui project

Pluto Security found that nginx-ui's MCP integration left a message endpoint effectively unauthenticated under default settings, letting anyone reach its administrative MCP tools and take over the web server. The flaw (CVSS 9.8) was fixed in version 2.3.4 on 2026-03-15, and Recorded Future listed it among actively exploited vulnerabilities in March 2026.