CVE-2026-9680: Alibabacloud RDS OpenAPI MCP Server Exposed
Alibabacloud RDS OpenAPI MCP server improperly exposes MCP endpoints listening on all network interfaces by default, allowing remote attackers to invoke exposed MCP tools.
Disclosed 28 July 2026 · Record updated 13 September 2026
Impact
Remote attackers can invoke exposed MCP tools via network access to an MCP endpoint listening on all network interfaces
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-9680
