CVE-2026-42238
Nginx UI can be hijacked to run any command on your server
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
An unauthenticated attacker can hijack Nginx UI during startup to run any command on your server, potentially gaining full control. This affects internet-facing management interfaces, so act fast.