{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/findings/exposed-mcp-endpoints-exploited/",
 "asOf": "2026-09-26",
 "id": "exposed-mcp-endpoints-exploited",
 "claim": "An MCP endpoint exposed without authentication has been reported as exploited in the wild.",
 "evidenceKind": "reported",
 "scope": "One case, from secondary sources; exploitation rests on a threat-intelligence listing with no public detail of the activity.",
 "topics": [
  "tool-and-mcp-security"
 ],
 "atlas": [
  "tools",
  "access-gate"
 ],
 "evidence": [
  {
   "event": "nginx-ui-mcpwn-cve-2026-33032-2026"
  }
 ],
 "relations": [],
 "statusHistory": [
  {
   "status": "reported",
   "on": "2026-04-15",
   "why": "MCPwn in nginx-ui reported as exploited.",
   "event": "nginx-ui-mcpwn-cve-2026-33032-2026",
   "kind": "evidence"
  }
 ],
 "halfLifeDays": 365,
 "wouldChange": "Scanning data on how many MCP endpoints are exposed and attacked.",
 "fideQuestions": [],
 "methods": [
  "tool-poisoning"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}