Pattern: 34 MCP CVEs landed in NVD in 72 hours and three root causes explain almost all of them
A keywordSearch=MCP query for 2026-09-14 to 2026-09-16 returned 34 CVEs, six of them 9.8 or higher. Sorting them by root cause gives three buckets and almost nothing else: bind to 0.0.0.0 with no auth (MySQL MCP Server, @zereight/mcp-gitlab, Bifrost, PraisonAI), validate a hostname and then resolve it again at connect time with no IP pinning (mcp-searxng, FrontMCP, ToolHive, ContextForge, MCP Atlassian), and pass a caller-controlled path or command straight through (MCP Memory Keeper, MCPVault, Flowise, Meta Ads MCP). Every one is a missing boundary, not a novel technique. Kong Gateway Enterprise also drew CVE-2026-14916 (7.7, published 2026-09-16) for accepting a JWT whose signing algorithm does not match the verification key type in MCP OAuth2 and DataKit integrations.
Source
↳ Follow the thread