Fetching from the wire…
Security2026-09-16 · source-backed
A keyword query for September 14 through 16 returns 34, six at 9.8 or higher. Sort by cause and you get three buckets: bind to 0.0.0.0 with no auth (MySQL MCP Server, @zereight/mcp-gitlab, Bifrost, PraisonAI), validate a hostname then resolve it again at connect time with no IP pinning (mcp-searxng, FrontMCP, ToolHive, ContextForge, MCP Atlassian), and pass a caller-controlled path or command straight through (MCP Memory Keeper, MCPVault, Flowise, Meta Ads MCP). No novel technique anywhere in the set. Every one is a boundary somebody didn't draw.
Each link below shares sources, entities, or timing with this story.
Between September 14 and September 15, NVD published seven entries hitting MCP infrastructure. I read all of them expecting to find something clever. There's nothing clever in any of them. CVE-2026-57124, 9.8, published September 14. PraisonAI's default UI exposes POST /api/mc...
CVE-2026-90474, published September 12 at CVSS 7.6, is an authentication bypass in MCPHub's embedded OAuth 2.0 authorization server: client authentication is off by default and PKCE enforcement is optional (NVD). Two days after the Langflow and ContextForge cluster, the same s...
CVE-2026-90898, published today, covers Maxim's Bifrost LLM gateway. A stdio MCP client is a command plus args, and Bifrost launches that program the moment the client is registered, before any handshake. governance.auth_config.is_enabled defaults to false, so a single unauthe...
IBM's bulletin lists CVE-2026-85025, rated CVSS 9.8, which allows unauthenticated code execution through publicly shared MCP project endpoints in Langflow 1.0.0 through 1.11.5. CVE-2026-78575 and CVE-2026-81941 let authenticated users run OS commands through the MCP stdio serv...
The trick is one line in a file you never read. Manifold Security published eight findings across seven coding agents (Claude Code, Codex, Cursor, Grok Build, Qwen Code, goose, Hermes Agent) that all reduce to the same mechanism. A repository's own .git/config sets core.fsmoni...
Your read-only flag is a claim, not a guarantee. Two independent Postgres MCP servers proved it on September 4. Postgres MCP Pro got CVE-2026-85620 at CVSS 9.2. The bug is one line of reasoning in safe_sql.py: the validator checks function names on FuncCall AST nodes. A functi...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.