CVE-2026-33032: Nginx UI Missing MCP Authentication

2026-04-17T19:23:46Za2a715d112e651ca6f5a38987a78d86595594d36e6e89885711d6e47ac4344b9
CVE-2026-20127CVE-2026-33032Cisco Catalyst SD-WANClaude impersonationClickFixMCPMicrosoft vulnerabilitiesNginx UIPatch Tuesday April 2026Pluto SecuritySOCauthentication-bypasscloud-detectionexposure-managementlog-analysismetasploitmissing-authenticationphishingremediation

What happened

This Rapid7 collection highlights multiple security topics from April 2026. Primary item: CVE-2026-33032 — a critical (CVSS 9.8) missing authentication vulnerability in Nginx UI (Model Context Protocol endpoint) disclosed by Pluto Security and patched March 15, 2026, allowing unauthenticated full-impact access. Other posts cover a ClickFix phishing campaign impersonating a Claude installer observed in EU/US, Microsoft’s April 2026 Patch Tuesday (167 vulnerabilities, with at least one actively exploited), product/operational guidance on prioritizing remediation and cloud detection strategy, SOC

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
a2a715d112e651ca6f5a38987a78d86595594d36e6e89885711d6e47ac4344b9
Enrichment time
2026-04-17T19:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.