News

Critical Nginx UI flaw CVE-2026-27944 exposes server backups

  • Pierluigi Paganini--Securityaffairs.com
  • published date: 2026-03-08 19:10:38 UTC

Nginx UI flaw CVE-2026-27944 lets attackers download and decrypt server backups without authentication, exposing sensitive data on public management interfaces. A critical vulnerability in Nginx UI, tracked as CVE-2026-27944 (CVSS score of 9.8), allows attack…

Critical Nginx UI flaw CVE-2026-27944 exposes server backups A critical vulnerability in Nginx UI, tracked as CVE-2026-27944 (CVSS score of 9.8), allows attackers to download and decrypt full server… [+3007 chars]