Chronicle/Attacks & incidents

MCPwn: unauthenticated MCP endpoint in nginx-ui exploited in the wild (CVE-2026-33032)

AttackVulnerability disclosureSignificance assistant-drafted

Pluto Security found that nginx-ui's MCP integration left a message endpoint effectively unauthenticated under default settings, letting anyone reach its administrative MCP tools and take over the web server. The flaw (CVSS 9.8) was fixed in version 2.3.4 on 2026-03-15, and Recorded Future listed it among actively exploited vulnerabilities in March 2026.

Why it matters

It is an early case of an MCP interface itself being exploited in the wild as a server-takeover path.

Key facts

As stated in the sources, with where to find them.

  • Shodan data cited identified about 2,689 exposed instances.Article body
  • Fixed in nginx-ui 2.3.4, released 2026-03-15.Article body

Findings that cite this record

Sources

Related records