Skip to content

// #cve-2026-33032

1 article

💻 AppSec

nginx-ui CVE-2026-33032 Actively Exploited — Unauthenticated Full Server Takeover

A critical authentication bypass vulnerability (CVSS 9.8) in the nginx-ui web management interface allows any network attacker to take complete control of the underlying Nginx server without credentials. Over 2,600 instances are internet-exposed and the flaw is being actively exploited. Update to version 2.3.4 immediately.

#rce +7