CVE-2026-33032: severe nginx-ui bug grants unauthenticated server access

2026-04-16T02:51:49Z374728b5fb2f95c6b089fe7197f7ccb9b2444a90d4dc5eb3d625e702d417001e
Android RATBasic-FitCVE-2025-0520CVE-2026-32201CVE-2026-33032MiraxOperation AtlanticPHP ComposerPerforce VCSRCERockstar GamesSharePointShinyHunters UIShowDocactive exploitationcrypto theftdata breachdata leaklaw enforcement takedownmalwarenginxnginx-uiremote code executionsupply-chainzero-day

What happened

Multiple high-impact security incidents and actively exploited vulnerabilities reported: a critical nginx-ui authentication bypass (CVE-2026-33032, CVSS 9.8) is being exploited to gain full control of Nginx servers; Microsoft fixed an actively exploited SharePoint zero-day (CVE-2026-32201) in April Patch Tuesday; ShowDoc is under active exploitation via a critical RCE (CVE-2025-0520). Additional notable items include high-severity PHP Composer RCE risks via Perforce VCS configs, the Mirax Android RAT campaign (220k+ infections via Meta ads), a 1M-record Basic-Fit data breach, a $45M crypto-the

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
374728b5fb2f95c6b089fe7197f7ccb9b2444a90d4dc5eb3d625e702d417001e
Enrichment time
2026-04-16T02:51:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CVE-2026-33032: severe nginx-ui bug grants unauthenticated server access · Baitaphish