Fetching from the wire…
Public story · 2026-03-12 · source-backed
Azure MCP Server SSRF (CVSS 8.8). A malicious URL instead of an Azure resource identifier leaks the managed identity token, granting access to any Azure resource the MCP Server can reach. MCP is transitioning from a protocol curiosity to a security perimeter. TheHackerWire
Each link below shares sources, entities, or timing with this story.
Microsoft released Azure / Shared entities / Shared topic / What happened next
Linked by a graph relationship (Microsoft released Azure); both cover Azure, CVE, CVSS, MCP; overlapping topics (access, azure, cve-2026-26118, server).
Microsoft released Azure / Shared entities / Shared topic / What happened next / Tension
Linked by a graph relationship (Microsoft released Azure); both cover Azure, CVE, CVSS, MCP; overlapping topics (azure, server).
Shared entities / Same source / Shared topic / What happened next
Both cover Azure, CVE, MCP, TheHackerWire; cite the same source (TheHackerWire); overlapping topics (azure, cve-2026-26118, identity, managed, server).
Microsoft released Azure / Shared entities / Same source domain / Shared topic / What happened next
Linked by a graph relationship (Microsoft released Azure); both cover CVE, CVSS, MCP; reported by the same outlet (thehackerwire.com).
MCP deprecates Sampling / Shared entities / Shared topic / What happened next
Linked by a graph relationship (MCP deprecates Sampling); both cover CVE, CVSS, MCP; overlapping topics (cvss, identity, server).
Claude Code uses MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Claude Code uses MCP); both cover CVE, CVSS, MCP; overlapping topics (cvss, server).
Microsoft released Azure / Shared entities / Shared topic / What happened next
Linked by a graph relationship (Microsoft released Azure); both cover Azure, CVE; overlapping topics (azure, cve-2026-26118, server).
Cloudflare supports MCP / Shared entities / What happened next
Linked by a graph relationship (Cloudflare supports MCP); both cover CVE, MCP, URL; picks up the CVE thread on 2026-07-15.