Pluto Security found that nginx-ui's MCP integration left a message endpoint effectively unauthenticated under default settings, letting anyone reach its administrative MCP tools and take over the web server. The flaw (CVSS 9.8) was fixed in version 2.3.4 on 2026-03-15, and Recorded Future listed it among actively exploited vulnerabilities in March 2026.
Why it matters
It is an early case of an MCP interface itself being exploited in the wild as a server-takeover path.
Key facts
As stated in the sources, with where to find them.
- Shodan data cited identified about 2,689 exposed instances.Article body
- Fixed in nginx-ui 2.3.4, released 2026-03-15.Article body
Findings that cite this record
Sources
Related records
May 20, 2026
Feb 17, 2026
Sep 11, 2026
Sep 30, 2025
Aug 6, 2025
Jul 8, 2025