Agents30 MCP CVEs total - MCP security crisis crystallizesWweb·medium signalXBlueskyLinkedInCopy link30 CVEs since late 2024 launch. Q1 2026 alone produced ~15. 36.7% SSRF rate, ~10% servers compromised. BlueRock Trust Registry scans 7100+ servers. Noma Security MCP guardrails launched. OAuth 2.1 spec criticized as mess for enterprise. Go SDK parsing bypass CVE-2026-27896.↳ Follow the threadShared entity / Stack layerClaude Code 2.1.269 Ships a Plugin Eval Runner and a Knob to Raise the Workflow Tool's Concurrent Agent Cap to 256Anthropic (claude-code CHANGELOG)Shared entity / Policy dependencyMicrosoft Agent Framework dotnet-1.21.0 lands four breaking changes at once, including limiting MCP skill archives to ZIPGitHubShared entity / Threat patternCROSS-CATEGORY: Five Launches in 48 Hours Shipped an MCP Server as the Product, Not a Web App With an APIProduct Hunt daily leaderboards for 2026-09-11 and 2026-09-12, plus the Hacker News Show HN feedShared entity / Stack layerpascalorg/editor is a 3D architectural CAD editor built for agents, with a local CLI and MCP toolsGitHub TrendingShared entity / Policy dependencyAnthropic adds an 'auto' permission policy that lets the server adjudicate every Managed Agents tool call, plus a terminal attach commandClaude Platform release notesShared entity / Stack layerArize Phoenix ships Claude Code, Codex and Cursor plugins plus an MCP skills root in two releases a day apartGitHubShared entity / Threat patternMCP's skills extension SEP-2640 is Accepted, and the conformance suite now grades clients by what they refuse to fetchGitHubShared entity / Stack layerTip: record MCP agent-mock answers into `mocks/.replay/` so eval runs in CI stop calling a modelClaude Code Docs