CVE-2026-33026 – nginx-ui
“A critical flaw with proven exploit code puts web management interfaces one step away from full compromise.”
A security patch has been released for nginx-ui addressing CVE-2026-33026, a critical vulnerability affecting the web-based management interface. The CVSS score is 9.4, which is Critical severity. This level of risk indicates a high likelihood of full system compromise if exploited.
A public proof-of-concept is available, confirming that exploitation is feasible and lowering the barrier for attackers. This vulnerability could allow unauthorized access, manipulation of configurations, or complete takeover of systems managed through nginx-ui. The patch closes this high-risk exposure and is essential for securing administrative interfaces.