CVE-2026-33032: severe nginx-ui bug grants unauthenticated server access
2026-04-16T02:51:49Z•374728b5fb2f95c6b089fe7197f7ccb9b2444a90d4dc5eb3d625e702d417001e
Android RATBasic-FitCVE-2025-0520CVE-2026-32201CVE-2026-33032MiraxOperation AtlanticPHP ComposerPerforce VCSRCERockstar GamesSharePointShinyHunters UIShowDocactive exploitationcrypto theftdata breachdata leaklaw enforcement takedownmalwarenginxnginx-uiremote code executionsupply-chainzero-day
What happened
Multiple high-impact security incidents and actively exploited vulnerabilities reported: a critical nginx-ui authentication bypass (CVE-2026-33032, CVSS 9.8) is being exploited to gain full control of Nginx servers; Microsoft fixed an actively exploited SharePoint zero-day (CVE-2026-32201) in April Patch Tuesday; ShowDoc is under active exploitation via a critical RCE (CVE-2025-0520). Additional notable items include high-severity PHP Composer RCE risks via Perforce VCS configs, the Mirax Android RAT campaign (220k+ infections via Meta ads), a 1M-record Basic-Fit data breach, a $45M crypto-the
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 374728b5fb2f95c6b089fe7197f7ccb9b2444a90d4dc5eb3d625e702d417001e
- Enrichment time
- 2026-04-16T02:51:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.