CVE-2026-33032: Nginx UI Auth Bypass Under Active Exploitation for Full Server Takeover
A critical unauthenticated vulnerability in Nginx UI's Model Context Protocol endpoint is being actively exploited in the wild, enabling attackers to fully take over web servers without credentials. Over 2,600 publicly exposed instances remain potentially vulnerable.