nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover (CVE-2026-33032) | HOL Guard CVE