Story perspectives
Critical Nginx Vulnerability Exposed — 2,689 Servers at Risk
4/17/2026
1 of 1
Story summary
- A critical vulnerability in Nginx UI, CVE-2026-33032, is actively exploited to take full control of servers.
- Pluto Security identified it as an authentication bypass with a CVSS score of 9.8.
- The flaw can be exploited through two HTTP requests targeting data and configuration files.
- Version 2.3.4, released March 15, 2026, patches the flaw.
- About 2,689 instances are exposed online, mainly in China, the United States, and Germany.
