Fetching from the wire…
Security2026-06-12 · source-backed
Disclosed June 11, this flaw lets any client circumvent intended restrictions on Kubernetes operations, which makes environment-variable-based access controls cosmetic. Adversa AI has the details. If you're running this MCP server to give agents cluster access, upgrade to 3.6.0 now and stop treating env-var gating as authorization. This is the second time this year I've seen "we gated it with an env var" turn out to mean "we didn't gate it." Env vars are configuration, not a security boundary. Agents reaching production infrastructure need real RBAC behind them.
Each link below shares sources, entities, or timing with this story.
CVE-2026-90474, published September 12 at CVSS 7.6, is an authentication bypass in MCPHub's embedded OAuth 2.0 authorization server: client authentication is off by default and PKCE enforcement is optional (NVD). Two days after the Langflow and ContextForge cluster, the same s...
Full 10.0. Network vector, low complexity, no authentication, no user interaction, high impact on confidentiality, integrity and availability. CVE-2026-79696, published September 9, is a code injection flaw in adk web affecting Google's Agent Development Kit for Python 2.0.0 t...
Adversa AI's roundup shows Golf Scanner (20 checks across 7 IDEs), Astrix MCP Secret Wrapper (runtime vault integration), and mcp-sec-audit all shipped in April. PipeLab's "State of MCP Security 2026" is the first incident-by-incident mapping against the OWASP MCP Top 10. The...
Ten days from spec to shipped client. That's fast even for this ecosystem. The MCP 2026-07-28 revision replaced the bidirectional stateful protocol with request/response. Every request now independently carries protocol version, client identity and capabilities. Cloudflare's t...
Adversa AI's March 2026 roundup documented 8 confirmed security incidents across OpenClaw and ServiceNow deployments, with aggregate scanning finding 43% of MCP servers vulnerable to command execution. A new vulnerability class is emerging around persistent memory and SOUL.md...
The most important security research this week. Check Point demonstrated three attack vectors in Claude Code exploiting project configuration files in untrusted repositories: (1) Hooks RCE (CVE-2025-59536, CVSS 8.7) — malicious hooks in .claude/settings.json execute shell comm...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.