A design choice in the MCP SDKs allows remote code execution across the AI supply chain.
Cybersecurity researchers have discovered a critical "by design" weakness in the Model Context Protocol's (MCP) architecture ...
The prompt-injection issue in the agentic AI product for filesystem operations was a sanitization issue that allowed for ...
A surge in AI agent adoption is exposing critical systems online ...
CVE-2026-5760 (CVSS 9.8) exposes SGLang via /v1/rerank endpoint, enabling RCE through malicious GGUF models, risking server ...
The critical remote code execution flaw (CVE-2026-1731) in the remote monitoring and management tool can be exploited to ...
Proof-of-concept exploit code has been published for a critical remote code execution flaw in protobuf.js, a widely used ...
A prompt injection flaw in Google’s Antigravity IDE turns a file search tool into a remote code execution vector, bypassing ...
Administrators of websites running the Drupal content management software (CMS) are urged to take immediate action to mitigate a newly discovered a vulnerability that can lead to remote execution of ...
The security defects could be exploited for remote code execution, OS command injection, and WAF detection bypass.
Unsafe defaults in MCP configurations open servers to possible remote code execution, according to security researchers who ...
Splunk has released patches that resolve high- and medium-severity vulnerabilities in Splunk Enterprise and MCP Server.