Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Unauthenticated MCP endpoint in Nginx UI allows full nginx takeover (CVE-2026-33032)

Nginx UI versions 2.3.5 and prior expose an /mcp_message Model Context Protocol endpoint that is protected only by an IP whitelist which defaults to empty and is treated as allow-all, letting any network attacker invoke all MCP tools without authentication. This permits restarting nginx and creating, modifying or deleting nginx configuration files with automatic reloads, amounting to complete service takeover; no patch was available at publication.

Disclosed 30 March 2026 · Record updated 13 September 2026

Impact

Unauthenticated network attackers can invoke all MCP tools, restarting nginx and creating, modifying or deleting configuration files, achieving complete nginx service takeover. No public patch at time of publication.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-33032