Critical Nginx UI flaw CVE-2026-27944 exposes server backups
2026-03-08T20:51:51Z•895f62ff3ff815607fc89115865dddbc404aeb14ae86a8da641ca493f914adb8
BoryptGrabCVE-2026-20122CVE-2026-20128CVE-2026-27944Catalyst SD-WANCiscoClickFixDindoorFBI-investigationGitHubIP-camerasIran-linkedLumma StealerMuddyWaterNginxactive-exploitationcyber-espionagedata-exposuremalwarestealerunauthenticated-downloadvulnerability
What happened
Multiple high-impact incidents: a critical unauthenticated Nginx UI vulnerability (CVE-2026-27944, CVSS 9.8) allows attackers to download and decrypt full server backups; Cisco warns of active exploitation of two recently patched Catalyst SD‑WAN flaws (CVE-2026-20128, CVE-2026-20122). Trend Micro reported a large GitHub-based distribution of the BoryptGrab stealer, Microsoft disclosed a ClickFix campaign abusing Windows Terminal to deliver Lumma Stealer, and Iran-linked actors (including MuddyWater) have targeted IP cameras and deployed the Dindoor backdoor against U.S. organizations. The FBI,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 895f62ff3ff815607fc89115865dddbc404aeb14ae86a8da641ca493f914adb8
- Enrichment time
- 2026-03-08T20:51:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.