CRITICAL: Unauthenticated nginx-ui Flaw Gives Attackers Complete Control of Your Web Server
CVE-2026-33032 is a critical vulnerability in nginx-ui that allows unauthenticated attackers to take complete control of nginx services. The flaw exists because one MCP endpoint forgot to check authentication while another requires it. CISA has added it to the KEV catalog.