MCPwned: RCE Vulnerability in Microsoft Azure MCP Server to Be Presented at RSAC 2026
GlobeNewswire·high signal
Token Security announced on March 17 that a researcher will present 'MCPwned' vulnerability research at RSAC 2026, demonstrating a remote code execution flaw in Microsoft's Azure Model Context Protocol server that enables attackers to compromise cloud environments. No CVE number published yet. This is distinct from the Go SDK routing bypass (CVE-2026-27896) disclosed last week — Azure MCP is a separate implementation. Full technical details expected at RSAC.