Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A critical unauthenticated vulnerability in Nginx UI (versions 2.3.5 and prior) allows any network attacker to take full control of Nginx web server configurations without credentials. The flaw stems from a misconfigured Model Context Protocol endpoint that bypasses authentication entirely, enabling attackers to modify, delete, or reload web server configurations at will. CISA and VulnCheck have both confirmed active exploitation, and no patch is publicly available.

Author

Tech Jacks Solutions