All verified exploits

CVE-2026-33032 Unauthenticated MCP Endpoint Enables Nginx Service Takeover

Deterministic critical Nginx UI Added cve-verified-cve-2026-33032

Detects Nginx UI instances where the /mcp_message endpoint is accessible without authentication. The MCP integration only applies IP whitelisting (empty by default = allow all) but no auth middleware on the message endpoint. An attacker can invoke MCP tools to restart nginx, create or modify config files, and reload the service — achieving complete control over the web server routing and traffic.

Is your app exploitable through CVE-2026-33032?

Scan your domain free