CVE-2026-33032: severe nginx-ui bug grants unauthenticated server access

2026-04-15T20:51:50Z135028ff29273bc5e89bc20de3e6679dd00bb6f15578e2b2f5bb1344ae9cb278
Android RATBasic-FitCISA-KEVCVE-2025-0520CVE-2026-32201CVE-2026-33032MiraxOperation AtlanticPHP ComposerRCERockstar GamesSOCKS5 proxySharePointShinyHuntersShowDoccrypto theftdata breachnginx-ui

What happened

Multiple high-risk incidents and disclosures: an actively exploited critical nginx-ui vulnerability (CVE-2026-33032, CVSS 9.8) allows unauthenticated takeover of Nginx servers due to improper protection of the /mcp_message endpoint. Microsoft Patch Tuesday fixed 165 flaws including an actively exploited SharePoint zero-day (CVE-2026-32201); CISA added multiple Microsoft, Adobe, Fortinet, Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities (KEV) catalog. Other urgent items include active exploitation of a critical ShowDoc RCE (CVE-2025-0520), two high-severity PHP

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
135028ff29273bc5e89bc20de3e6679dd00bb6f15578e2b2f5bb1344ae9cb278
Enrichment time
2026-04-15T20:51:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.