Fetching from the wire…
Security2026-07-28 · source-backed
CVE-2026-33032 (CVSS 9.8) in nginx-ui left the MCP message endpoint entirely unauthenticated. CVE-2026-40576 is a path traversal in excel-mcp-server through 0.1.7 letting unauthenticated attackers read, write and overwrite arbitrary files. A scan of 10,000+ real-world servers found credentials, API keys and PII leaking above 10%. Missing auth and path traversal, over and over. The spec layer is improving today; the community long tail isn't. (Adversa AI)
Each link below shares sources, entities, or timing with this story.
Adversa AI criticizes Anthropic / Shared entities / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (Adversa AI criticizes Anthropic); both cover CVE, CVEs, CVSS, MCP; overlapping topics (auth, cves, server).
Adversa AI criticizes Anthropic / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (Adversa AI criticizes Anthropic); both cover CVEs, CVSS, MCP; reported by the same outlet (adversa.ai).
Adversa AI criticizes MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Adversa AI criticizes MCP); both cover CVE, CVEs, CVSS, MCP; overlapping topics (cves, cvss, over).
Linked by a graph relationship (Adversa AI criticizes MCP); both cover CVE, CVEs, CVSS, MCP; overlapping topics (auth, server).
Linked by a graph relationship (Adversa AI criticizes MCP); both cover CVE, CVEs, CVSS, MCP; overlapping topics (credential, server).
Linked by a graph relationship (Adversa AI criticizes MCP); both cover CVEs, CVSS, MCP; overlapping topics (auth, cves, cvss, server, unauthenticated).
Linked by a graph relationship (Adversa AI criticizes MCP); both cover CVE, CVEs, MCP; overlapping topics (arbitrary, cves, server).
Adversa AI criticizes Anthropic / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Adversa AI criticizes Anthropic); both cover CVE, CVEs, MCP; overlapping topics (arbitrary, cves, server).