Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-9680: Alibabacloud RDS OpenAPI MCP Server Exposed

Alibabacloud RDS OpenAPI MCP server improperly exposes MCP endpoints listening on all network interfaces by default, allowing remote attackers to invoke exposed MCP tools.

Disclosed 28 July 2026 · Record updated 13 September 2026

Impact

Remote attackers can invoke exposed MCP tools via network access to an MCP endpoint listening on all network interfaces

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-9680