Critical Nginx UI auth bypass flaw now actively exploited in the wild
2026-04-16T07:23:29Z•91c517237ebe6d70dea5be721cd3c1f7aa4b0674ac790e9543d6e9e19fe13de9
adwareagingflyantivirus-disableauth-bypassbitlockerchrome-web-storechromium-browserscredential-theftdata-breacheducationexploitationextortiongovernmenthealthcaremalicious-extensionsmicrosoft-patchesnginxprivilege-escalationsalesforce-misconfigurationsigned-binariessupply-chainwhatsappwindows-task-hostwordpress-compromisezero-day
What happened
This collection highlights multiple high-impact security incidents and active exploits: a critical unauthenticated Nginx UI (MCP) auth-bypass is being actively exploited for full server takeover; CISA flagged a Windows Task Host privilege-escalation vulnerability under active abuse; and Microsoft pushed emergency/extended updates (including fixes for two zero-days) while some updates caused BitLocker recovery prompts. Threat activity includes the new AgingFly credential‑stealing malware targeting Chromium browsers and WhatsApp in attacks against Ukrainian government and hospitals, a large Word
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 91c517237ebe6d70dea5be721cd3c1f7aa4b0674ac790e9543d6e9e19fe13de9
- Enrichment time
- 2026-04-16T07:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.