Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-35228: Oracle MCP Server Helper Tool flaw allows malicious SQL execution

Oracle disclosed an easily exploitable vulnerability in the Oracle MCP Server Helper Tool (versions 1.0.1-1.0.156) that lets an unauthenticated attacker with HTTP network access compromise the tool and cause it to execute malicious SQL.

Disclosed 5 May 2026 · Record updated 13 September 2026

Impact

An unauthenticated remote attacker can compromise the MCP Server Helper Tool and make it execute malicious SQL, affecting versions 1.0.1 through 1.0.156.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-35228