Fetching from the wire…
Public story · 2026-03-20 · source-backed
Arctic Wolf published a critical advisory for a CVSS 10.0 vulnerability in the mcp-atlassian MCP server — one of the most widely deployed connectors linking agents to Jira, Confluence, and Bitbucket. A remote attacker with zero credentials can execute arbitrary code and pivot into internal networks via SSRF. Any enterprise agent workflow connecting to Atlassian tools via MCP is exposed. Patch immediately or isolate.
Each link below shares sources, entities, or timing with this story.
PromptArmor went public August 5 (248 points on HN) after Atlassian went silent. Rovo's URL-retrieval tool has no protection against URLs the agent itself generates, so indirect prompt injection reaches anything behind its connectors. Disabling web search doesn't help: it remo...
Ten days from spec to shipped client. That's fast even for this ecosystem. The MCP 2026-07-28 revision replaced the bidirectional stateful protocol with request/response. Every request now independently carries protocol version, client identity and capabilities. Cloudflare's t...
Varonis Threat Labs disclosed at DEF CON 34 that Rovo's rovoChatPrompt URL parameter pre-fills content straight into a victim's live AI session, and leaving the organization ID blank silently routes into the victim's default org with no warning (SecurityWeek). Rovo's built-in...
Token Security researcher Ariel Simon will present at RSAC 2026 a vulnerability chain starting from SSRF in Microsoft's Azure MCP server (CVE-2026-26118, CVSS 8.8). The managed identity token included in outbound MCP requests is capturable without admin access, then escalatabl...
The Model Context Protocol has a security problem that's no longer theoretical — it's statistical. Between January and February 2026, researchers filed 30+ CVEs against MCP servers, clients, and infrastructure. One package with nearly 500,000 downloads carried a CVSS 9.6 RCE....
CVE-2026-82021 (CVSS 9.0) covers Hermes Agent 0.18.2 through 0.19.0, where the bundled MCP catalog referenced a third-party upstream by branch name rather than commit SHA. Compromise the upstream and your code reaches every host installing that catalog entry, with zero operato...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.