Critical Nginx UI flaw CVE-2026-27944 exposes server backups
2026-03-09T02:51:48Z•6c4225ba071fffa980884d767eb79aa5fba89f91cc232cd3990bc023758e18d9
CVE-2026-20122CVE-2026-20128CVE-2026-27944active-exploitationbackup-exposureboryptgrabcatalyst-sd-wanclickfixdindoorfbi-investigationgithub-malwareinformation-stealerip-camera-targetinglumma-stealermuddywaternginxsteganographysupply-chain-npmunauthenticated-accesswindows-terminal
What happened
Multiple high-impact incidents reported: a critical unauthenticated Nginx UI flaw (CVE-2026-27944, CVSS 9.8) allows attackers to download and decrypt full server backups from public management interfaces; Trend Micro uncovered BoryptGrab stealer being distributed through 100+ GitHub repositories; Microsoft and others warned of active campaigns (ClickFix using Windows Terminal delivering Lumma Stealer); Cisco flagged active exploitation of two recently patched Catalyst SD-WAN flaws (CVE-2026-20128, CVE-2026-20122); Iran-linked MuddyWater is deploying the Dindoor backdoor against U.S. entities;,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 6c4225ba071fffa980884d767eb79aa5fba89f91cc232cd3990bc023758e18d9
- Enrichment time
- 2026-03-09T02:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.