{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/nginx-ui-mcpwn-cve-2026-33032-2026/",
 "asOf": "2026-09-26",
 "id": "nginx-ui-mcpwn-cve-2026-33032-2026",
 "date": "2026-04-15",
 "datePrecision": "day",
 "title": "MCPwn: unauthenticated MCP endpoint in nginx-ui exploited in the wild (CVE-2026-33032)",
 "lane": "attack",
 "kind": "vulnerability-disclosure",
 "summary": "Pluto Security found that nginx-ui's MCP integration left a message endpoint effectively unauthenticated under default settings, letting anyone reach its administrative MCP tools and take over the web server. The flaw (CVSS 9.8) was fixed in version 2.3.4 on 2026-03-15, and Recorded Future listed it among actively exploited vulnerabilities in March 2026.",
 "whyItMatters": "It is an early case of an MCP interface itself being exploited in the wild as a server-takeover path.",
 "actors": [
  "pluto-security",
  "recorded-future",
  "nginx-ui"
 ],
 "topics": [
  "tool-and-mcp-security"
 ],
 "atlas": [
  "tools",
  "credentials"
 ],
 "artifacts": [],
 "sources": [
  {
   "url": "https://pluto.security/blog/mcp-bug-nginx-security-vulnerability-cvss-9-8/",
   "publisher": "Pluto Security",
   "title": "MCP Bug in Nginx: Critical CVSS 9.8 Security Vulnerability",
   "date": "2026-04-15",
   "type": "primary",
   "accessed": "2026-09-26"
  },
  {
   "url": "https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-h6c2-x2m2-mwhf",
   "publisher": "nginx-ui (GitHub security advisory)",
   "title": "GHSA-h6c2-x2m2-mwhf (CVE-2026-33032)",
   "date": "2026-03-28",
   "type": "primary",
   "accessed": "2026-09-26"
  },
  {
   "url": "https://thehackernews.com/2026/04/critical-nginx-ui-vulnerability-cve.html",
   "publisher": "The Hacker News",
   "title": "Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover",
   "date": "2026-04-15",
   "type": "secondary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "Shodan data cited identified about 2,689 exposed instances.",
   "locator": "Article body"
  },
  {
   "fact": "Fixed in nginx-ui 2.3.4, released 2026-03-15.",
   "locator": "Article body"
  }
 ],
 "significance": 3,
 "fideQuestions": [],
 "methods": [],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}