NewsCVE-2026-26118: Azure MCP Server SSRF — First Cloud MCP VulnerabilityTheHackerWire·high signalXBlueskyLinkedInCopy linkSSRF in Azure MCP Server Tools (CVSS 8.8) lets attackers steal managed identity tokens. First CVE targeting cloud-hosted MCP infrastructure.SourceSource pageTheHackerWire↳ Follow the threadPolicy dependency / Stack layerMCP ext-apps migrated to SDK v2 across 125 files to cut a server-to-client dependency edgeGitHubStack layer / Threat patternchrome-devtools-mcp 1.9.0 publishes itself as an Agent Plugins 1.0 package installable across five agent clientsGitHubPolicy dependency / Stack layerHierarchical Ransomware Agents Escalate to Dynamic and Memory Analysis Only on Specialist DisagreementarXiv 2609.04820Stack layer / Threat patternn8n 2.39.0 stops advertising instance MCP OAuth discovery when MCP access is disabledGitHubStack layer / Threat pattern16% of 3,171 public agent-harness setups carry a confirmed security defect, and 3.8% ship a skill that pre-approves your shellarXivStack layer / Threat patternLangChain's deepagents-talon adds channel-scoped MCP server authorization and OAuth device auth for Slack and GitHubGitHub ReleasesPolicy dependency / Stack layerAgents hit 80% F1 deciding whether a dependency CVE is exploitable, but fall below 70% explaining whyarXiv 2609.08040Policy dependency / Stack layerKeyclasp Puts Agent Credentials in a Local AES-256-GCM Vault and Kills the Process if a Secret Appears in Outputkeyclasp on GitHub, via Hacker News Show HN (single source)