All verified exploits

CVE-2026-27944 Unauthenticated Backup Download

Deterministic critical Nginx UI Added cve-verified-cve-2026-27944

Downloads the full system backup including SSL keys and credentials without authentication. The AES encryption key is exposed in the response header.

Is your app exploitable through CVE-2026-27944?

Scan your domain free