CVE-2026-33032: Nginx UI Missing MCP Authentication
2026-04-17T19:23:46Z•a2a715d112e651ca6f5a38987a78d86595594d36e6e89885711d6e47ac4344b9
CVE-2026-20127CVE-2026-33032Cisco Catalyst SD-WANClaude impersonationClickFixMCPMicrosoft vulnerabilitiesNginx UIPatch Tuesday April 2026Pluto SecuritySOCauthentication-bypasscloud-detectionexposure-managementlog-analysismetasploitmissing-authenticationphishingremediation
What happened
This Rapid7 collection highlights multiple security topics from April 2026. Primary item: CVE-2026-33032 — a critical (CVSS 9.8) missing authentication vulnerability in Nginx UI (Model Context Protocol endpoint) disclosed by Pluto Security and patched March 15, 2026, allowing unauthenticated full-impact access. Other posts cover a ClickFix phishing campaign impersonating a Claude installer observed in EU/US, Microsoft’s April 2026 Patch Tuesday (167 vulnerabilities, with at least one actively exploited), product/operational guidance on prioritizing remediation and cloud detection strategy, SOC
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- a2a715d112e651ca6f5a38987a78d86595594d36e6e89885711d6e47ac4344b9
- Enrichment time
- 2026-04-17T19:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.