MCPwn (CVE-2026-33032): First Confirmed In-the-Wild MCP Exploit Hits nginx-ui

incident response free stock image for MCPwatch editorial use

What Happened In March 2026, security researcher Yotam Perkal at Pluto Security discovered a critical authentication bypass in nginx-ui, the popular open-source web management interface for Nginx servers (11,000+ GitHub stars, 430,000+ Docker pulls). The vulnerability was assigned CVE-2026-33032 with a CVSS 9.8 severity score, and it was quickly dubbed MCPwn. The root cause is … Read more