Critical Nginx UI auth bypass flaw now actively exploited in the wild

2026-04-16T07:23:29Z91c517237ebe6d70dea5be721cd3c1f7aa4b0674ac790e9543d6e9e19fe13de9
adwareagingflyantivirus-disableauth-bypassbitlockerchrome-web-storechromium-browserscredential-theftdata-breacheducationexploitationextortiongovernmenthealthcaremalicious-extensionsmicrosoft-patchesnginxprivilege-escalationsalesforce-misconfigurationsigned-binariessupply-chainwhatsappwindows-task-hostwordpress-compromisezero-day

What happened

This collection highlights multiple high-impact security incidents and active exploits: a critical unauthenticated Nginx UI (MCP) auth-bypass is being actively exploited for full server takeover; CISA flagged a Windows Task Host privilege-escalation vulnerability under active abuse; and Microsoft pushed emergency/extended updates (including fixes for two zero-days) while some updates caused BitLocker recovery prompts. Threat activity includes the new AgingFly credential‑stealing malware targeting Chromium browsers and WhatsApp in attacks against Ukrainian government and hospitals, a large Word

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
91c517237ebe6d70dea5be721cd3c1f7aa4b0674ac790e9543d6e9e19fe13de9
Enrichment time
2026-04-16T07:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Critical Nginx UI auth bypass flaw now actively exploited in the wild · Baitaphish