VDB

CVE-2026-33032

CVE-2026-33032 PUBLISHED CVSS 8.600000381469727 HIGH

On April 10, 2026, Nginx UI published a security advisory to address a critical vulnerability in the following product: Nginx UI – version v2.3.5 and prior Open-source reporting indicates that the CVE-2026-33032 vulnerability is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.

EPSS 15.42% · 94.8th percentile

Risk Scores

CVSS 4.0
8.600000381469727
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
15.42%
94.8th percentile

Affected Products

VendorProductVersions
NginxNginx UI – version v2.3.5 and prior

Timeline

  • CVE Published
  • Mar 28, 2026 PoC Published
  • Mar 30, 2026 PoC Published
  • Mar 30, 2026 Security Advisory
  • Apr 1, 2026 PoC Published
  • Apr 3, 2026 PoC Published
  • Apr 3, 2026 PoC Published
  • Apr 4, 2026 PoC Published
  • Apr 7, 2026 PoC Published
  • Apr 8, 2026 PoC Published
  • Apr 15, 2026 PoC Published
  • Apr 15, 2026 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›