SecurityWeek: Top 25 MCP Vulnerabilities — Exec/Shell Injection Dominates at 43% of Q1 2026 CVEs
SecurityWeek·high signal
SecurityWeek published an empirical breakdown of the 25 most critical MCP vulnerability patterns across the 30+ CVEs filed in Q1 2026. Exec/shell injection — MCP servers passing user input to shell commands without sanitization — represents 43% of vulnerabilities and is the modal failure pattern. Tool poisoning and prompt injection are secondary classes. This is the first aggregated attack-path taxonomy covering the full MCP CVE corpus.