Drooid Logo
Back to today’s briefing

Story perspectives

Critical Nginx Vulnerability Exposed — 2,689 Servers at Risk

4/17/2026

25 2 Full Breakdown

1 of 1

Story summary
  • A critical vulnerability in Nginx UI, CVE-2026-33032, is actively exploited to take full control of servers.
  • Pluto Security identified it as an authentication bypass with a CVSS score of 9.8.
  • The flaw can be exploited through two HTTP requests targeting data and configuration files.
  • Version 2.3.4, released March 15, 2026, patches the flaw.
  • About 2,689 instances are exposed online, mainly in China, the United States, and Germany.