Critical Nginx UI auth bypass flaw now actively exploited in the wild
2026-04-16T01:23:30Z•9a7f3a499b6ba522876edb571ccdcca02599ecd451dd298d43a461f926732669
agingflyauth-bypassav-disablebitlockerchrome-extensionschromiumcisacode-signing-abusecredential-theftextortion-breachmalwaremicrosoftnginxoauth-token-theftpatchesplugin-compromiseprivilege-escalationrdpremote-executionserver-takeoversupply-chainwhatsappwindowswordpresszero-day
What happened
A collection of widespread security incidents and fixes: a critical Nginx UI authentication-bypass in MCP-enabled builds is being actively exploited for unauthenticated full server takeover; a new 'AgingFly' malware family is stealing credentials from Chromium-based browsers and WhatsApp in targeted attacks against Ukrainian government and healthcare organizations; more than 30 WordPress plugins in the EssentialPlugin suite were backdoored to push malware; a signed adware package has been abused to run SYSTEM‑level antivirus‑disabling scripts across thousands of endpoints; and CISA flagged an已
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 9a7f3a499b6ba522876edb571ccdcca02599ecd451dd298d43a461f926732669
- Enrichment time
- 2026-04-16T01:23:30Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.