Fetching from the wire…
Security2026-09-22 · source-backed
The NVD MCP keyword window for September 21 alone returned seven CVEs, and five of them are failures to apply an existing check on a second code path. MaxKB's dispatch path skips the per-tool grant its tool routes enforce (CVE-2026-77516), its detail route skips the check its list route applies (77518), its MCP auth path skips key expiry (77519). CKAN MCP Server's validateServerUrl guard has now been bypassed three separate times because it string-matches a hostname and never resolves DNS, and the third bypass reaches [redacted] (CVE-2026-61612, fixed in 0.4.108). The audit question this week is whether every entry point runs the check, not whether the check exists. (NVD)
Each link below shares sources, entities, or timing with this story.
Your read-only flag is a claim, not a guarantee. Two independent Postgres MCP servers proved it on September 4. Postgres MCP Pro got CVE-2026-85620 at CVSS 9.2. The bug is one line of reasoning in safe_sql.py: the validator checks function names on FuncCall AST nodes. A functi...
CVE-2026-90474, published September 12 at CVSS 7.6, is an authentication bypass in MCPHub's embedded OAuth 2.0 authorization server: client authentication is off by default and PKCE enforcement is optional (NVD). Two days after the Langflow and ContextForge cluster, the same s...
Between September 14 and September 15, NVD published seven entries hitting MCP infrastructure. I read all of them expecting to find something clever. There's nothing clever in any of them. CVE-2026-57124, 9.8, published September 14. PraisonAI's default UI exposes POST /api/mc...
The trick is one line in a file you never read. Manifold Security published eight findings across seven coding agents (Claude Code, Codex, Cursor, Grok Build, Qwen Code, goose, Hermes Agent) that all reduce to the same mechanism. A repository's own .git/config sets core.fsmoni...
NVD's September 16-18 window added CVE-2026-54618 (Obsidian Web MCP before 0.2.0 issues an OAuth authorization code with no login or consent check, then exchanges it for the static VAULT_MCP_TOKEN), CVE-2026-54504 (MCP Documentation Server 1.13.0 calls app.listen(3080) with no...
The agent skills supply chain is under coordinated attack. Snyk's ToxicSkills audit found 36% of ClawHub's 3,984 skills contain prompt injection payloads, 13.4% have critical malware, and submission rates exploded 10x to 500+/day. This week alone: CVE-2026-2256 (CVSS 9.1) is a...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.