CVE-2026-23744Active Exploitation(mcpjam / inspector)

CRITICALCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch mcpjam inspector systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vulnerability, which allows an attacker to send a crafted HTTP request that triggers the installation of an MCP server, leading to RCE. Since MCPJam inspector by default listens on 0.0.0.0 instead of 127.0.0.1, an attacker can trigger the RCE remotely via a simple HTTP request. Version 1.4.3 contains a patch.

8.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • inspector

Threat summary

  • Active exploitation appears in 6 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 27 mentions across 17 observed days

What's happening

  • Active exploitation reported across 6 signals
  • Exploit tool or code specified in 8 signals
  • PoC mentioned or linked in 13 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 16 signals
  • General: 6 classified signals
  • Peaked 16d ago at 3 mentions (2026-03-16); latest day: 1
  • 27 total mentions across 17 days

Affected systems

Vendors
Products
inspector

Deep dive

Activity timeline27 mentions / 17d
01223Mentions · 2026-03-16: 3Mentions · 2026-03-29: 1Mentions · 2026-04-01: 2Mentions · 2026-04-02: 2Mentions · 2026-04-11: 1Mentions · 2026-04-25: 3Mentions · 2026-05-31: 1Mentions · 2026-06-07: 1Mentions · 2026-07-08: 1Mentions · 2026-07-15: 1Mentions · 2026-07-17: 1Mentions · 2026-08-02: 2Mentions · 2026-08-22: 3Mentions · 2026-09-09: 1Mentions · 2026-09-12: 2Mentions · 2026-09-16: 1Mentions · 2026-09-17: 1PoC Mentioned / Linked · 2026-03-29: 1PoC Mentioned / Linked · 2026-04-01: 1PoC Mentioned / Linked · 2026-04-02: 2PoC Mentioned / Linked · 2026-06-07: 1PoC Mentioned / Linked · 2026-07-08: 1PoC Mentioned / Linked · 2026-07-15: 1PoC Mentioned / Linked · 2026-07-17: 1PoC Mentioned / Linked · 2026-08-02: 1PoC Mentioned / Linked · 2026-09-09: 1PoC Mentioned / Linked · 2026-09-12: 2PoC Mentioned / Linked · 2026-09-17: 1Exploit Tool / Code · 2026-03-29: 1Exploit Tool / Code · 2026-06-07: 1Exploit Tool / Code · 2026-07-15: 1Exploit Tool / Code · 2026-07-17: 1Exploit Tool / Code · 2026-08-02: 1Exploit Tool / Code · 2026-09-12: 2Exploit Tool / Code · 2026-09-17: 1Active Exploitation · 2026-03-16: 1Active Exploitation · 2026-04-11: 1Active Exploitation · 2026-05-31: 1Active Exploitation · 2026-07-17: 1Active Exploitation · 2026-08-22: 2Patch / Workaround · 2026-04-02: 1Patch / Workaround · 2026-04-25: 1Patch / Workaround · 2026-09-17: 1Technical Details · 2026-03-16: 2Technical Details · 2026-04-02: 1Technical Details · 2026-04-11: 1Technical Details · 2026-04-25: 2Technical Details · 2026-05-31: 1Technical Details · 2026-07-15: 1Technical Details · 2026-07-17: 1Technical Details · 2026-08-02: 2Technical Details · 2026-09-09: 1Technical Details · 2026-09-12: 2Technical Details · 2026-09-16: 1Technical Details · 2026-09-17: 103-1603-2904-0104-0204-1104-2505-3106-0707-0807-1507-1708-0208-2209-0909-1209-1609-17
Signal classification6 categories
Active Exploitation
622.2%
General
622.2%
PoC
622.2%
Exploit
518.5%
Disclosure
311.1%
Patch
13.7%
Referenced assets17 URLs
Classification over time
DateTotalLabels
2026-03-163
Active Exploitation1Disclosure1General1
2026-03-291
PoC1
2026-04-012
General1PoC1
2026-04-022
General1PoC1
2026-04-111
Active Exploitation1
2026-04-253
Disclosure1General1Patch1
2026-05-311
Active Exploitation1
2026-06-071
Exploit1
2026-07-081
PoC1
2026-07-151
Exploit1
2026-07-171
Active Exploitation1
2026-08-022
Exploit1General1
2026-08-223
Active Exploitation2General1
2026-09-091
PoC1
2026-09-122
Exploit2
2026-09-161
Disclosure1
2026-09-171
PoC1
Full discourse20 posts
  • Yusuf Can Çakır@Yusufcancakiir
    Active Exploitation

    Found an open directory hosting a layered financial fraud operation across three simultaneous tracks: a Magecart-style card skimmer chain, a mass CVE exploitation framework, and a trojan distributed through Chinese streaming software packaging. All of it feeding the same PII collection pipeline. The skimmer track starts with FOFA. The actor runs automated queries targeting WooCommerce, Magento, and Stripe-integrated checkout pages, sorting results into structured target lists by category: builder_woo_checkout, stripe_woo_checkout, magento_checkout, checkout_cdn_js. Output lands in pii_consolidated.csv, with a second batch file visible alongside it. This has been running in passes. The skimmer component is a WooCommerce and Stripe-targeted Magecart payload. Injection engine supports page-level download, mitmproxy transparent proxy, and browser console delivery. C2 receiver runs on the same host. Target profile: Stripe Elements checkout pages, WooCommerce wc-ajax endpoints. The exploitation track runs in parallel. poc_scanner.py drives 300 concurrent probes against FOFA-sourced targets through a three-stage pipeline: liveness check, service fingerprinting, then PoC verification. CVEs being actively weaponized: CVE-2026-21858 — n8n unauthenticated RCE, CVSS 10.0 CVE-2026-6815 — Casdoor path traversal to RCE, CVSS 9.8 CVE-2026-32604 — Spinnaker shell injection, CVSS 10.0 CVE-2026-34486 — Tomcat Tribes auth bypass to RCE, CVSS 9.8 CVE-2026-25212 — Percona PMM RCE, CVSS 9.9 CVE-2026-35273 — PeopleSoft unauthenticated SSRF to RCE, CVSS 9.8 CVE-2026-23744 — MCPJam Inspector unauthenticated RCE, CVSS 9.8 CVE-2026-42167 — ProFTPD CVE-2026-6182 — SQL injection auth bypass CVE-2025-24587, CVE-2025-4396 A separate WordPress track runs alongside: mass SQL injection via wp_sqli_mass.py, aggressive dump via wp_aggressive_dump.py, PhpMyAdmin brute-force against the same pool. The trojan track is socially engineered. 直播助手化.v2.exe presents as a legitimate Chinese streaming helper application. VMProtect 3.2–3.5 wrapping. 29/70 on VirusTotal at time of analysis. Family: flystudio, chinad, dlii. It ships with HPSocket4C.dll, pb.dll, pb64.dll, and gzip.dll as side-loaded components. The infection surface is Chinese-speaking streaming users who would recognize the product name as familiar tooling. C2 routes through v2ray. Two license spoofing servers complete the toolkit. bypass_server.py impersonates http://premium.dotbypasser.workers.dev, handling RSA-OAEP encrypted license exchange and returning forged validation responses with 10-year expiry timestamps. fake_auth_server.py covers a separate streaming platform, impersonating http://api.vmks.cn and related domains, returning fake authorization tokens. Both appear to serve tooling distribution rather than direct victim infrastructure. One additional finding on the C2 host: evidence of AI-assisted offensive operations. A DeepSeek API configuration points to http://api.deepseek.com through an Anthropic-compatible interface, and a structured offensive security framework containing 70+ purpose-built skill modules for vulnerability classes including SQLi, XSS, SSRF, RCE, IDOR, OAuth, SAML, cloud misconfiguration, Kubernetes, CI/CD, M365/Entra, VMware vCenter, and supply chain recon. The actor is running systematized, AI-assisted attack methodology. This pattern is increasingly documented across financially motivated operations. OPSEC failure on an otherwise capable operator. filter_cn.py is on the box and actively used. It strips Chinese IP ranges from FOFA output sets before exploitation runs begin. The actor is deliberately skipping domestic targets, a consistent behavioral marker across Chinese financially motivated operations. Additionally, the FOFA API credential is hardcoded in cleartext across the client scripts. Easy attribution anchor.

    Post summary

    The post documents an active, large‑scale exploitation operation targeting multiple high‑impact CVEs using custom scripts, with detailed vulnerability information provided.

    215054404.8K
    1.6K followersView on X
  • Dark Web Informer@DarkWebInformer
    Exploit

    ‼️ CVE-2026-23744: MCPJam Inspector RCE Exploit GitHub: https://github.com/CerberusMrXi/CVE-2026-23744-MCPJam-Exploit Features: ▪️Multi-payload Support: Includes Bash, Python, Netcat, Perl, PHP, and Base64 payloads. ▪️Command Execution: Execute commands on the target system with output capture. ▪️Target Scanning: Scan multiple targets with configurable rate limiting. ▪️Session Management: Persistent session management for ongoing testing. ▪️Proxy Support: Integrate with proxies for anonymous or routed traffic. ▪️Target Fingerprinting: Identify target system characteristics. ▪️Auto-listener Setup: Automatically configure listeners for reverse shells.

    Post summary

    The post announces a GitHub‑hosted exploit tool for CVE‑2026‑23744, detailing payload support and command‑execution features, but does not mention active exploitation, patches, or debunking.

    1160652910.8K
    234.5K followersView on X
  • Ryx@PadhiyarRushi
    PoC

    One HTTP request → RCE on an MCP development tool. CVE-2026-23744 (MCPJam inspector ≤1.4.2): listens on 0.0.0.0 by default. Crafted request installs and runs a malicious MCP server. Public PoC exists!! Patch is 1.4.3, anything still on older builds is exposed. https://github.com/boroeurnprach/CVE-2026-23744-PoC #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #AgentSecurity #RCE

    Post summary

    The tweet details CVE-2026-23744, an RCE vulnerability in MCPJam inspector, highlighting the availability of a public PoC on GitHub and noting that the fix is in version 1.4.3.

    5202892.0K
    953 followersView on X
  • CrowdSec@Crowd_Security
    Active Exploitation

    🚨 In this week’s threat alert, CrowdSec reports on CVE-2026-23744, a critical RCE in MCPJam Inspector. Exploitation attempts are rising, targeting exposed dev environments. Learn how the vulnerability works and how to secure your systems in our latest article 👉 https://www.crowdsec.net/vulntracking-report/cve-2026-23744 #CVE #CVE202623744 #threatalert #RCE #cybersecurity

    Post summary

    The post highlights that CVE‑2026‑23744, a critical remote code execution flaw in MCPJam Inspector, is seeing rising exploitation attempts and urges readers to secure systems.

    00030283
    19.5K followersView on X
  • Lyrie.ai@lyrie_ai
    Exploit

    Source: X search for RCE 2026 exploit Posted: 2026-07-15T18:40:11.000Z Likes: 43 ‼️ CVE-2026-23744: MCPJam Inspector RCE Exploit GitHub: https://github.com/CerberusMrXi/CVE-2026-23744-MCPJam-Exploit Features: ▪️Multi-payload Support: Includes Bash, Python, Netcat, Perl, PHP, and Base64 payloads.

    Post summary

    The tweet shares a GitHub-based exploit for CVE‑2026‑23744 with multi‑payload support, confirming a PoC and basic RCE details but without evidence of active exploitation or remediation.

    10010110
    325 followersView on X
  • Subrat Samantaray@0xSubrat
    Active Exploitation

    Finally rooted DevHub on HackTheBox Season 11! CVE-2026-23744 RCE → mcp-dev → Jupyter token hijack → lateral move to analyst → hidden OPSMCP API → dumped root SSH key → ROOTED Never give up, keep hacking! https://labs.hackthebox.com/achievement/machine/2186520/903 #HackTheBox #HTB #CyberSecurity #InfoSec

    Post summary

    The post confirms CVE-2026-23744 was successfully exploited on a HackTheBox machine, achieving root access via a Jupyter token hijack and lateral moves.

    00020127
    112 followersView on X
  • Sergio®@elkarkaman
    Disclosure

    CVE-2026-23744: Vulnerabilidad crítica de ejecución remota de código en MCPJam Inspector dirigida a desarrolladores. Enlace https://www.crowdsec.net/vulntracking-report/cve-2026-23744?utm_campaign=9641866-%5BBrand%5D%20Monday%20Threat%20Alert&utm_medium=email&_hsenc=p2ANqtz-97bd4gQP2bkBhrFSsuXf61RzP5Ts6LNCUtIwN-OwaR8xeeFRLTCYshGmisgUxKtega4AoIRjaC068O5Qu6xkNEWUCc6Q&_hsmi=408957439&utm_content=408957439&utm_source=hs_email https://t.co/VHxFIRFgQT

    Post summary

    A critical remote code execution vulnerability (CVE‑2026‑23744) affecting MCPJam Inspector is announced, with no evidence of exploitation, PoC, or patch discussed.

    0101077
    2.5K followersView on X
  • SAQER@saqer_one
    General

    AI開発ツールを標的とした攻撃は深刻 ※開発ツールが企業セキュリティの弱点に。 https://nvd.nist.gov/vuln/detail/CVE-2026-23744

    Post summary

    The post highlights CVE‑2026‑23744, noting that attacks on AI development tools are serious, but provides no technical details, PoC, or mitigation information.

    0002070
    12.0K followersView on X
  • botmonster@botmonster
    Disclosure

    CVE-2026-23744 gave zero-click RCE on MCPJam Inspector at CVSS 9.8. A booby-trapped PDF tripped a physical pump via a Claude MCP link. LlamaFirewall cut attack success over 90% scanning the reasoning. https://botmonster.com/ai/ai-coding-agent-insider-threat-prompt-injection-mcp-exploits/?utm_source=twitter&utm_medium=social #ClaudeAI

    Post summary

    The text announces CVE-2026-23744, a zero-click RCE in MCPJam Inspector with a CVSS of 9.8, and illustrates an attack using a booby-trapped PDF.

    10000114
    62 followersView on X
  • Lyrie.ai@lyrie_ai
    Exploit

    CVE-2026-23744: ‼️ CVE-2026-23744: MCPJam Inspector RCE Exploit GitHub: Features: ▪️Multi-payload Support: Includes Bash, Python, Netcat, Perl, PHP, and Base64 payloads. ▪️Command Execution: Execute commands on the target system with output capture.…

    Post summary

    The message advertises a GitHub exploit script for CVE-2026-23744 that supports multiple payloads and enables remote command execution, but makes no claim of active exploitation or available patches.

    10000116
    325 followersView on X
  • S. Markakis@_SP1R4
    PoC

    Rooted DevHub on HTB — a chain through an AI/MCP developer toolchain, no memory-corruption anywhere: CVE-2026-23744 (unauth RCE in MCPJam Inspector) → SSH → a Jupyter token leaked in ps → code exec as analyst → a "hidden" root MCP tool with a hardcoded API key dumps root's SSH key. https://s-markakis.github.io/writeups/htb-devhub.html

    Post summary

    The linked writeup demonstrates a chain for CVE-2026-23744, showcasing an unauthenticated RCE in MCPJam Inspector that leads to SSH key compromise via a Jupyter token leak and a hidden root tool, providing clear PoC details.

    0001054
    150 followersView on X
  • strikoder@Strikoder
    General

    After a month break, I'm back! New HackTheBox walkthrough: Kobold MCPJam CVE-2026-23744 RCE (no auth, direct spawn) → PrivateBin template cookie traversal → Docker privileged container escape. https://youtu.be/tLMPtvQzXC8 #HackTheBox #Docker #ContainerEscape #MCPJam #CVE

    Post summary

    The post references CVE‑2026‑23744, describing its RCE nature and an associated demonstration link, but does not provide a PoC code, patch, or evidence of active exploitation.

    0001090
    44 followersView on X
  • sckull@sckull_
    Exploit

    HackTheBox - Kobold 💥 MCPJam (CVE-2026-23744) para acceso inicial 📂 LFI en PrivateBin (CVE-2025-64714) para leer configuraciones y credenciales 🐳 Contenedor Docker privilegiado en Arcane para escalar privilegios https://sckull.github.io/posts/kobold/

    Post summary

    The post outlines an exploit chain for HackTheBox's Kobold: initial access via MCPJam (CVE‑2026‑23744), exploitation of an LFI in PrivateBin (CVE‑2025‑64714) to read configurations, and privilege escalation through a privileged Docker container, all referenced in an external write‑up.

    0001091
    178 followersView on X
  • Lion systems@LSystemsMx
    Disclosure

    🔌 3. The MCP Vulnerability Race Critical RCEs in MCP servers (like the recent CVE-2026-23744) are emerging. If your agents are roaming free in your host environment via MCP without Wasm sandboxing, you're gambling with your kernel. Isolation is not optional in 2026. ⚡📦 #Wasm

    Post summary

    The tweet alerts to emerging critical RCEs in MCP servers, notably CVE‑2026‑23744, warning about lack of Wasm sandboxing, but offers no PoC, exploit, patch, or evidence of active exploitation.

    1000049
    5 followersView on X
  • Sattyam Jain@Sattyamjjain
    Patch

    Shipping in agent-airlock v0.5.6 today: — bind_address_guard (rejects 0.0.0.0 dev-mode MCP servers without auth — covers CVE-2026-23744) — argv_guard (catches kubectl-flag injection from CVE-2026-39884) — Claude Managed Agents audit hook for managed-agents-2026-04-01

    Post summary

    Agent‑airlock v0.5.6 introduces mitigations for CVE-2026-23744 and CVE-2026-39884, providing new safeguards but no evidence of active exploitation or PoC.

    1000039
    66 followersView on X
  • Sattyam Jain@Sattyamjjain
    General

    This is now the cadence. OpenAI ships a model on Thursday. Two SSRF CVEs land Friday. Anthropic ships Managed Agents Apr 8 with bash + code_execute server-side tools. CVE-2026-23744 (MCPJam Inspector RCE, CVSS 9.8) sits unpatched on every default install of <=1.4.2.

    Post summary

    The text announces release dates of OpenAI and Anthropic products, references two SSRF CVEs, and highlights an unpatched RCE vulnerability with a CVSS 9.8 score, but provides no exploit, patch, or active exploitation details.

    1000039
    66 followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [CRITICAL] Active exploitation detected: CVE-2026-23744 Exploit in the wild confirmed for CVE-2026-23744 (CVSS 9.8). MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 ... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    CVE-2026-23744 is reportedly being actively exploited in the wild with a CVSS score of 9.8, but the post provides no PoC, exploit code, or patch details.

    0001055
    5.6K followersView on X
  • SadishYT@Sadishyt
    General

    CVE-2026-23744 MCPJam inspector is the local-first development platform for MCP servers. #infosec #Hacking #infosecurity #Malware #bugbountytips #CTF #BugBounty #vulnerability #pwn #CyberSecurityAwareness #CyberSecurity #cybersecuritytips https://t.co/rPXuhzZORx

    Post summary

    The tweet merely references the CVE without providing any PoC, exploit details, patches, technical specifics, or evidence of active exploitation.

    0001067
    12 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    Active Exploitation

    Cytellite recent detection targeting CVE-2026-23744 — Limited Network LTD Visit -- https://cti.loginsoft.com/ip/77.90.185.20 #Loginsoft #Cytellite #Cybersecurity #CVE202623744 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/8nV73OTB4K

    Post summary

    The tweet reports a recent detection of active exploitation for CVE-2026-23744, with a link to a CTI reference, but provides no further technical or mitigation details.

    0000019
    23 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    General

    Cytellite recent detection targeting CVE-2026-23744 — Limited Network LTD Visit -- https://cti.loginsoft.com/ip/77.90.185.20 #Loginsoft #Cytellite #Cybersecurity #CVE202623744 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/b0icD2ZXlo

    Post summary

    The tweet announces detection of CVE-2026-23744 by Cytellite but provides no technical or exploitation details.

    0000021
    23 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmcpjaminspector---

Explore more