A critical authentication-bypass flaw (CVE-2026-33032, CVSS 9.8) in nginx-ui’s Model Context Protocol integration let unauthenticated attackers invoke privileged MCP tools and fully take over managed Nginx servers. The vulnerable “/mcp_message” endpoint enforced IP whitelisting but no authentication, and its whitelist was empty by default, so any network attacker could reach it with just two HTTP requests to modify configurations, restart services, or intercept traffic. The maintainers patched the flaw on March 15, 2026, but Recorded Future reported active in-the-wild exploitation soon after, with roughly 2,689 vulnerable instances found publicly exposed on the internet.