| 12 Sept 2026 | MCPHub OAuth 2.0 authentication bypass vulnerability | MCPHub | other | misconfiguration | | confirmed |
| 11 Sept 2026 | CVE-2026-59973: SSRF fix bypass in FrontMCP and mcp-from-openapi OpenAPI $ref handling | FrontMCP | other | supply chain | | confirmed |
| 11 Sept 2026 | Threat actors abused Anthropic's Claude to extract secrets from 1.8M Android apps | Anthropic | other | tool misuse | | confirmed |
| 11 Sept 2026 | MySQL MCP Server SSE transport allows unauthenticated SQL execution (CVE-2026-59971) | mysql-mcp-server | workflow | misconfiguration | | resolved |
| 11 Sept 2026 | Multiple vulnerabilities in IBM Langflow OSS 1.0.0-1.11.5 | IBM | workflow | excessive permissions | | reported |
| 10 Sept 2026 | Command injection in Tianxi AI Agent PC Application | Lenovo | other | tool misuse | | reported |
| 10 Sept 2026 | AWS Security Agent MCP Server S3 Bucket Ownership Verification Missing | AWS | other | misconfiguration | | confirmed |
| 10 Sept 2026 | n8n Multiple Vulnerabilities in Workflow Execution and Access Control | n8n | workflow | misconfiguration | | confirmed |
| 10 Sept 2026 | OmniRoute RCE via unauthenticated POST /api/acp/agents endpoint | OmniRoute | other | excessive permissions | | reported |
| 10 Sept 2026 | Path Injection in n8n Elasticsearch and ElasticSecurity Nodes | n8n | workflow | tool misuse | | resolved |
| 9 Sept 2026 | functype-mcp-server RCE via unsanitized pnpm install | functype-mcp-server | workflow | prompt injection | | confirmed |
| 9 Sept 2026 | Open WebUI vulnerabilities allow DoS and message tampering | Open WebUI | other | misconfiguration | | resolved |
| 8 Sept 2026 | Covert channel in ChatGPT's internal Artifactory enabled cross-account Gmail data theft | OpenAI | other | prompt injection | | resolved |
| 8 Sept 2026 | Command injection and credential exposure in GitHub Copilot and Visual Studio Code | Microsoft | coding | prompt injection | | confirmed |
| 8 Sept 2026 | Roo-Code auto-approve bypass vulnerabilities in shell command parsing | Roo-Code | coding | excessive permissions | | reported |
| 8 Sept 2026 | Okta Hyperdrive agent plugin authentication and logging vulnerabilities | Okta | other | misconfiguration | | reported |
| 8 Sept 2026 | ASUS Control Center Express Agent missing authentication vulnerability | ASUS | other | misconfiguration | | reported |
| 7 Sept 2026 | knowns path traversal vulnerabilities in MCP tool arguments | knowns-dev | coding | tool misuse | | reported |
| 7 Sept 2026 | Eclipse Ankaios wildcard authorization bypass in Control Interface | Eclipse Ankaios | other | misconfiguration | | reported |
| 5 Sept 2026 | AVideo API rate limit bypass via bot User-Agent header | AVideo | other | misconfiguration | | reported |
| 5 Sept 2026 | Rowboat fails to validate custom MCP server and webhook URLs | Rowboat Labs | workflow | misconfiguration | | reported |
| 4 Sept 2026 | AgentScope path traversal vulnerability in LocalWorkspace.add_skill | AgentScope | workflow | excessive permissions | | reported |
| 4 Sept 2026 | Aider arbitrary code execution via malicious .aider.conf.yml | aider-chat | coding | misconfiguration | | reported |
| 4 Sept 2026 | SSRF vulnerability in OWL DocumentProcessingToolkit | OWL | other | prompt injection | | confirmed |
| 4 Sept 2026 | LaVague 0.2.35 Remote Code Execution via Prompt Injection | LaVague | coding | prompt injection | | reported |
| 4 Sept 2026 | CodeWhale SSRF bypass via DNS pinning TOCTOU | CodeWhale | browsing | tool misuse | | confirmed |
| 4 Sept 2026 | OGX Unauthenticated Server-Side Request Forgery via MCP Tool | OGX | other | excessive permissions | | reported |
| 4 Sept 2026 | Multiple vulnerabilities in IBM ContextForge and Langflow OSS | IBM | other | excessive permissions | | reported |
| 4 Sept 2026 | LobeChat webhook signature verification bypass in QQ and Feishu adapters | LobeHub | workflow | misconfiguration | | reported |
| 4 Sept 2026 | Postgres MCP Pro 0.3.0 restricted-mode bypass via RangeFunction | Postgres MCP Pro | coding | misconfiguration | | reported |
| 4 Sept 2026 | Arbitrary local file read in firecrawl-mcp-server 3.20.2 | firecrawl | coding | excessive permissions | | reported |
| 4 Sept 2026 | excel-mcp-server path confinement bypass in stdio mode | excel-mcp-server | other | misconfiguration | | reported |
| 4 Sept 2026 | git-mcp-server argument injection in git tools | git-mcp-server | coding | prompt injection | | reported |
| 4 Sept 2026 | xiaobei webhook endpoint lacks authentication, allows SSRF attacks | xiaobei | workflow | misconfiguration | | reported |
| 4 Sept 2026 | LLaMA-Factory SSRF vulnerability in OpenAI API handler | LLaMA-Factory | coding | misconfiguration | | reported |
| 4 Sept 2026 | Xinference unauthenticated arbitrary-path file read vulnerability | Xinference | other | excessive permissions | | reported |
| 4 Sept 2026 | ms-swift 4.5.2 SSRF via unvalidated media URLs | ms-swift | coding | tool misuse | | reported |
| 4 Sept 2026 | CodeWhale Multiple Critical Vulnerabilities in v0.8.37-0.8.63 | CodeWhale | coding | excessive permissions | | confirmed |
| 4 Sept 2026 | Multiple vulnerabilities in Amazon AWS Labs MCP servers | Amazon | workflow | prompt injection | | confirmed |
| 4 Sept 2026 | cli-mcp-server command allowlist bypass via shell operators | cli-mcp-server | coding | misconfiguration | | reported |
| 3 Sept 2026 | Helicone vault key exposure via inadequate org validation | Helicone | other | misconfiguration | | reported |
| 3 Sept 2026 | Multiple vulnerabilities in simular-ai Agent-S | simular-ai | other | tool misuse | | reported |
| 3 Sept 2026 | Langgenius Dify XSS via redirect_url parameter in Splash Layout | Langgenius | other | prompt injection | | reported |
| 3 Sept 2026 | Cheshire Cat AI memory endpoint lacks per-user filtering | Cheshire Cat AI | other | excessive permissions | | reported |
| 3 Sept 2026 | Missing Authorization in MountDev AI MCP Connector for WordPress | Cascadia Web Services | other | excessive permissions | | reported |
| 3 Sept 2026 | CKAN MCP Server: Information disclosure via verbose error reflection | aborruso | other | data leak | | reported |
| 3 Sept 2026 | agent-squad Resource Exhaustion Vulnerability in Streaming | 2FastLabs | workflow | tool misuse | | reported |
| 3 Sept 2026 | Orval: Multiple RCE vulnerabilities in code generation | Orval | coding | prompt injection | | reported |
| 3 Sept 2026 | Multiple vulnerabilities in n8n workflow automation platform | n8n | workflow | tool misuse | | confirmed |
| 3 Sept 2026 | Broken Access Control in Agentimus AI SEO Plugin | Agentimus | other | excessive permissions | | reported |