NewsCVE-2026-26118: Azure MCP Server SSRF — First Cloud MCP VulnerabilityTheHackerWire·high signalXBlueskyLinkedInCopy linkSSRF in Azure MCP Server Tools (CVSS 8.8) lets attackers steal managed identity tokens. First CVE targeting cloud-hosted MCP infrastructure.SourceSource pageTheHackerWire↳ Follow the threadPolicy dependency / Stack layer'Do this as quickly as possible' repeatedly got a Claude session flagged by a corporate security directorr/ClaudeAIPolicy dependency / Stack layerrmcp replays your X-API-Key to whatever a cross-origin 307 points atNVDStack layer / Threat patternTwo high-severity CVEs land in rmcp, the official Rust MCP SDK: OAuth token theft and a permanent session-table leakGitHub Advisory DatabasePolicy dependency / Stack layerCodex makes Code Mode wrappers transparent to Guardian policy and adds read-only policy to MCP tool requestsGitHubStack layer / Threat patternTypeSafe AI ships Jev, a model that returns typed probabilistic values instead of text, at $0.042 per million input tokens and free outputTypeSafe AIStack layer / Threat patternMCP Rust SDK 3.4.0 splits ServerInfo/ClientInfo into config types and tightens three HTTP transport edge casesGitHubStack layer / Threat patternThree new advisories land on the most-used community GitLab MCP server, including a five-way bypass of its read-only mode and project allow-listGitHub Advisory DatabaseStack layer / Threat patternClaude Code makes the v2 MCP client and 2026-07-28 negotiation the default on Bedrock, Vertex and FoundryGitHub