Fetching from the wire…
Public story · 2026-03-16 · source-backed
An authenticated attacker substitutes a malicious URL for any Azure resource identifier, causing the MCP server to attach its managed identity token to outbound requests. Effective lateral movement in any agentic Azure deployment. Patched March 10; audit for exposure before that date. TheHackerWire
Each link below shares sources, entities, or timing with this story.
Token Security researcher Ariel Simon will present at RSAC 2026 a vulnerability chain starting from SSRF in Microsoft's Azure MCP server (CVE-2026-26118, CVSS 8.8). The managed identity token included in outbound MCP requests is capturable without admin access, then escalatabl...
The Model Context Protocol has a security problem that's no longer theoretical — it's statistical. Between January and February 2026, researchers filed 30+ CVEs against MCP servers, clients, and infrastructure. One package with nearly 500,000 downloads carried a CVSS 9.6 RCE....
Azure MCP Server SSRF (CVSS 8.8). A malicious URL instead of an Azure resource identifier leaks the managed identity token, granting access to any Azure resource the MCP Server can reach. MCP is transitioning from a protocol curiosity to a security perimeter. TheHackerWire
BlueRock scanned over 7,000 MCP servers against 22-plus security rules. 36.7% carry potential server-side request forgery exposure from unrestricted outbound fetch, and 42% handle credentials insecurely. Their worked example is Microsoft's 85K-star Markitdown MCP server and it...
Five capabilities moved onto Foundry deployments hosted on Azure rather than only Hosted on Anthropic. The practical change is residency: a US Data Zone Standard deployment can now run a web-search-backed research agent and connect to internal MCP servers without prompts leavi...
Token Security researcher Ariel Simon will demo a full attack chain at RSAC 2026 — from an RCE flaw in Microsoft's Azure MCP server to credential harvesting and complete Azure tenant compromise. The research extends beyond the patched CVE-2026-26118 by demonstrating post-explo...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.