Critical Nginx UI Auth Bypass Flaw Under Active Exploitation
A critical authentication bypass vulnerability (CVE-2026-33032) in Nginx UI with Model Context Protocol (MCP) support is being actively exploited in the wild. This flaw allows attackers to take full control of Nginx servers, including the ability to restart, create, modify, and delete configurations. Security teams should prioritize patching affected systems to mitigate potential server takeovers and ensure robust access controls are in place.