CRITICALAi
Global

Critical Nginx UI auth bypass flaw now actively exploited in the wild

·Source: BleepingComputer

Updated:

Executive Summary

A critical vulnerability in Nginx UI with Model Context Protocol (MCP) support is now being exploited in the wild for full server takeover without authentication. [...]

Analysis

A critical vulnerability in Nginx UI with Model Context Protocol (MCP) support is now being exploited in the wild for full server takeover without authentication. [...]
Source Attribution

Originally published by BleepingComputer on Apr 15, 2026.

Related Threats