CVE-2026-33032: severe nginx-ui bug grants unauthenticated server access
2026-04-15T20:51:50Z•135028ff29273bc5e89bc20de3e6679dd00bb6f15578e2b2f5bb1344ae9cb278
Android RATBasic-FitCISA-KEVCVE-2025-0520CVE-2026-32201CVE-2026-33032MiraxOperation AtlanticPHP ComposerRCERockstar GamesSOCKS5 proxySharePointShinyHuntersShowDoccrypto theftdata breachnginx-ui
What happened
Multiple high-risk incidents and disclosures: an actively exploited critical nginx-ui vulnerability (CVE-2026-33032, CVSS 9.8) allows unauthenticated takeover of Nginx servers due to improper protection of the /mcp_message endpoint. Microsoft Patch Tuesday fixed 165 flaws including an actively exploited SharePoint zero-day (CVE-2026-32201); CISA added multiple Microsoft, Adobe, Fortinet, Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities (KEV) catalog. Other urgent items include active exploitation of a critical ShowDoc RCE (CVE-2025-0520), two high-severity PHP
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 135028ff29273bc5e89bc20de3e6679dd00bb6f15578e2b2f5bb1344ae9cb278
- Enrichment time
- 2026-04-15T20:51:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.