Critical Nginx UI auth bypass flaw now actively exploited in the wildPosted by PrivacyWireA critical vulnerability in Nginx UI with Model Context Protocol (MCP) support is now being exploited in the wild for full server takeover without authentication. [...]1 repliestomspark wrote:Nginx UI is niche enough that most people won't be hit, but if you're self-hosting anything critical on it, patch immediately. The MCP integration thing is a wild attack surface to introduce.