Skills
MCPwn CVE-2026-33032: First Major MCP Exploit in the Wild — Missing Auth Middleware in nginx-ui Enables Full Server Takeover in Two HTTP Requests
Pluto Security's CVE-2026-33032 (CVSS 9.8), codenamed MCPwn, became the first widely-exploited MCP vulnerability in the wild. The nginx-ui MCP integration exposed 12 MCP tools to any network attacker through a single missing middleware call on the /mcp_message endpoint — while /mcp enforced auth, /mcp_message only checked IP whitelisting. Added to VulnCheck KEV on April 13. Recorded Future ranked it 94/100 risk score and one of the 31 most-exploited CVEs of March 2026. The fix was 27 characters of code. 2,600+ instances were exposed.
↳ Follow the thread