CVE-2026-26118Disclosure(microsoft / azure_mcp_server)

MEDIUMCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch microsoft azure_mcp_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network.

5.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • azure_mcp_server

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 20 mentions across 14 observed days

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 11 signals
  • Technical details provided in 16 signals
  • Disclosure: 8 classified signals
  • General: 3 classified signals
  • Peaked 6d ago at 3 mentions (2026-03-18); latest day: 1
  • 20 total mentions across 14 days

Affected systems

Vendors
Products
azure_mcp_server

1 version affected across 1 product

Deep dive

Activity timeline20 mentions / 14d
01223Mentions · 2026-03-10: 2Mentions · 2026-03-11: 1Mentions · 2026-03-12: 2Mentions · 2026-03-14: 1Mentions · 2026-03-15: 1Mentions · 2026-03-16: 1Mentions · 2026-03-17: 1Mentions · 2026-03-18: 3Mentions · 2026-03-19: 1Mentions · 2026-03-21: 1Mentions · 2026-03-25: 3Mentions · 2026-03-30: 1Mentions · 2026-03-31: 1Mentions · 2026-04-22: 1PoC Mentioned / Linked · 2026-03-18: 1Active Exploitation · 2026-03-14: 1Active Exploitation · 2026-04-22: 1Patch / Workaround · 2026-03-14: 1Patch / Workaround · 2026-03-17: 1Patch / Workaround · 2026-03-18: 3Patch / Workaround · 2026-03-19: 1Patch / Workaround · 2026-03-25: 3Patch / Workaround · 2026-03-30: 1Patch / Workaround · 2026-04-22: 1Technical Details · 2026-03-10: 2Technical Details · 2026-03-12: 1Technical Details · 2026-03-14: 1Technical Details · 2026-03-15: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-17: 1Technical Details · 2026-03-18: 3Technical Details · 2026-03-19: 1Technical Details · 2026-03-21: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-30: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-22: 103-1003-1103-1203-1403-1503-1603-1703-1803-1903-2103-2503-3003-3104-22
Signal classification5 categories
Disclosure
840.0%
Patch
630.0%
General
315.0%
Active Exploitation
210.0%
PoC
15.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-102
Disclosure2
2026-03-111
General1
2026-03-122
Disclosure2
2026-03-141
Active Exploitation1
2026-03-151
General1
2026-03-161
Disclosure1
2026-03-171
Patch1
2026-03-183
Disclosure1Patch1PoC1
2026-03-191
Disclosure1
2026-03-211
Disclosure1
2026-03-253
Patch3
2026-03-301
Patch1
2026-03-311
General1
2026-04-221
Active Exploitation1
Full discourse20 posts
  • Karthik Ramadoss@KIntheHouse
    Patch

    36.7% of MCP servers are vulnerable to attack. MCP is how you connect AI agents to your enterprise tools. If your dev teams are deploying them without a security review, you have exposure right now. Microsoft patched CVE-2026-26118 (near-critical) on March 10. This week's AI Waypoints ↗ https://open.substack.com/pub/aiwanderlust/p/ai-waypoints-week-of-march-17-2026?r=kbfaa&utm_medium=ios

    Post summary

    The post highlights that a large portion of MCP servers are vulnerable, notes Microsoft’s patch of CVE-2026-26118, but provides no PoC, exploitation details, or technical specifics.

    1002160
    865 followersView on X
  • しゅん|AIエンジニアの日常@shun_aidev
    PoC

    MCPセキュリティ、また来た。 Token SecurityがRSAC 2026で「MCPwned」を発表予定。Azure MCP ServerのRCE脆弱性でAzureテナント乗っ取りが可能だったという話。 CVE-2026-26118。SSRF経由でmanaged identity tokenが窃取できる。攻撃者がURLを細工するだけ。 3月Patch Tuesdayで修正済みだけど、パッチ当ててない環境は即対応必須。 先週「MCP 60日で30 CVE」の話をしたけど、今度は具体的な攻撃シナリオ付き。 MCPを本番環境で使ってるチーム、セキュリティレビューの優先度を上げたほうがいい。「便利だから繋ぐ」フェーズは終わった。

    Post summary

    A newly disclosed RCE vulnerability (CVE‑2026‑26118) in Azure MCP Server has been demonstrated via the "MCPwned" PoC, enabling SSRF-based token theft and tenant takeover; the issue was patched in March and requires immediate remediation.

    00030128
    106 followersView on X
  • AI Security Guard@ai_security_10x
    Disclosure

    📝 New article: CVE-2026-26118: The First Major MCP-Specific Elevation of Privilege Vulnerability https://moltx.io/articles/2a08119a-7843-4308-8e6f-9ea25ced9a63

    Post summary

    The tweet announces a new article discussing CVE-2026-26118 as an MCP‑specific privilege escalation vulnerability, but it provides no proof‑of‑concept, exploit details, mitigation, or evidence of active exploitation.

    1002078
    3 followersView on X
  • Alexei Belous@AlexeiBelous
    Patch

    Same month, Microsoft patched a separate MCP flaw (CVE-2026-26118) where crafted input exposed managed identity tokens. At RSAC, Token Security demoed MCP RCE to full Azure tenant takeover.

    Post summary

    Microsoft patched CVE-2026-26118, which involved crafted input exposing managed identity tokens and enabling MCP RCE for a full Azure tenant takeover; no exploit code or active attacks were reported.

    1001038
    6 followersView on X
  • しゅん|AIエンジニアの日常@shun_aidev
    Disclosure

    MCP関連のCVEが3月だけで立て続けに出てる。整理する。 ① CVE-2026-26118(Azure MCP Server) - SSRF → managed identity token窃取 → Azure全リソースへの権限昇格 - CVSS 8.8。3/10パッチ済み ② CVE-2025-59536(Claude Code) - プロジェクトファイル経由RCE - リポジトリcloneだけで攻撃成立 ③ CVE-2026-21852(Claude Code) - ANTHROPIC_BASE_URL上書きによるAPIキー漏洩 - サプライチェーン攻撃にスケール 共通点: MCPサーバーが新たなアタックサーフェスになってる。信頼境界の設計が追いついてない。 先月「MCP 60日で30 CVE」って話をしたけど、ペースが加速してる。Token SecurityのMCPwned研究がRSAC 2026で発表予定。 MCPを本番で使ってるなら、パッチ管理と入力バリデーションは最優先。「便利だから繋ぐ」フェーズは完全に終わった。

    Post summary

    The post lists multiple MCP-related CVEs, providing technical impact details and patch status, and urges patch management and input validation as top priorities.

    00020175
    104 followersView on X
  • Alexei Belous@AlexeiBelous
    Patch

    Same patch batch fixed CVE-2026-26118, an SSRF in Azure MCP Server leaking managed identity tokens. A lateral movement path through the protocol built to make AI agents safe.

    Post summary

    The patch batch fixed CVE‑2026‑26118, an SSRF flaw in Azure MCP Server that leaked managed identity tokens, indicating a vendor update was issued to address the vulnerability.

    1001043
    2 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26118 Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-26118

    Post summary

    The post reports CVE‑2026‑26118 as a server‑side request forgery that can elevate privileges in Azure MCP Server, but provides only a brief description without PoC, exploit, or patch information.

    10010182
    56.7K followersView on X
  • Luna Kel@SecuringAgents
    Patch

    🚨 CVE-2026-26118 — Azure MCP Server has a high-severity SSRF (CVSS 8.8) that allows token theft and privilege escalation over the network. Patched in March 2026 Patch Tuesday. The MCP + SSRF combination is worth unpacking. 🧵

    Post summary

    The tweet notes a high‑severity SSRF vulnerability in Azure MCP Server, details its potential impact, and confirms it was patched in March 2026.

    1000050
    1 followersView on X
  • AgentEconomy@AgentEconoemy
    Disclosure

    Three signals in one week: - Gartner briefing CISOs on Copilot risks - Lazarus draining Bitrefill via production keys - Azure MCP CVE-2026-26118 (CVSS 8.8) Raw MCP isn't enterprise-ready. Isolated execution is the minimum. https://ai-agent-economy.hashnode.dev/why-agentpay-mcp-is-enterprise-safe-isolated-execution-vs-raw-mcp-1

    Post summary

    The post announces CVE‑2026‑26118 (CVSS 8.8) and notes that raw MCP is not enterprise‑ready, recommending isolated execution as a mitigation, but offers no exploit, patch, or PoC details.

    0001037
    45 followersView on X
  • Cipher@elagentecapital
    Patch

    Report #2026-03-18-01: Microsoft patched CVE-2026-26118 in Azure MCP Server Tools. Impact: HIGH. SSRF in MCP tooling can turn user input into cloud-side requests with the server's identity. https://www.cve.org/CVERecord?id=CVE-2026-26118

    Post summary

    Microsoft released a patch for the high‑impact SSRF vulnerability CVE-2026-26118 in Azure MCP Server Tools, mitigating the risk of server‑side request forgery.

    1000027
    3 followersView on X
  • Cipher@elagentecapital
    General

    Why it matters: CVE-2026-26118 can coerce an MCP-backed agent to request an attacker URL and leak its managed identity token. CVE-2026-26144 can push Copilot Agent mode toward zero-click data exfil from hostile Excel content.

    Post summary

    The post outlines how CVE‑2026‑26118 and CVE‑2026‑26144 could facilitate agent coercion and zero‑click exfiltration but does not mention PoC, exploit code, patches, or actual attacks.

    1000054
    3 followersView on X
  • ナタリー 🌙@natalie_avfieb
    Active Exploitation

    CVE-2026-26118 — Azure MCP ServerにCVSS 8.8の権限昇格。今月修正されたけど、クラウド側のMCPも標的になってる。ローカルだけ気にしてれば良い時代じゃない。

    Post summary

    CVE-2026-26118 is a privilege‑escalation vulnerability on Azure MCP Server, patched this month, yet there are reports of it being actively targeted in the cloud, underscoring the need for immediate remediation.

    0001056
    79 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-26118 - High Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network. https://www.thehackerwire.com/vulnerability/CVE-2026-26118/ https://t.co/9ef5EhqQZk

    Post summary

    The post announces a newly disclosed high‑severity SSRF vulnerability (CVE-2026‑26118) in Azure MCP Server that permits privilege elevation for authorized attackers. No PoC, exploit code, or active exploitation information is mentioned.

    0001041
    133 followersView on X
  • Hermetic@HermeticSys
    Active Exploitation

    The MCP vulnerability pattern: Jan-Feb: 30 CVEs filed in 60 days March: Microsoft MCP server patched (CVE-2026-26118) April 14: MCPwn — nginx-ui MCP endpoint, CVSS 9.8 April 15: MCPwnfluence — Atlassian MCP server, unauthenticated RCE April 19: Vercel breached via AI tool OAuth chain April 21: OX Security finds RCE in Anthropic's MCP SDK itself The progression: individual servers → platform breaches → the protocol SDK. Each layer up is a larger blast radius. The credential isolation problem isn't getting better. It's moving up the stack.

    Post summary

    The post details multiple MCP-related CVEs, noting both patches and confirmed active exploitation, including RCEs and OAuth chain breaches, illustrating an escalating risk across the stack.

    0000084
    10 followersView on X
  • Aakash Rahsi@rahsi_aaka
    General

    CVE-2026-26118 | Azure MCP Server Tools Elevation of Privilege Vulnerability https://www.aakashrahsi.online/post/cve-2026-26118 https://t.co/Zf2b8Z66nh

    Post summary

    The tweet merely references CVE-2026-26118 with a brief title and two links but provides no further detail on exploitation, patches, or technical specifics beyond the vulnerability type.

    0000030
    1 followersView on X
  • Luna Kel@SecuringAgents
    Patch

    Action required: → Apply March 2026 Microsoft security updates → Review Azure MCP Server configurations → Restrict network egress to known-safe internal endpoints (defense in depth) → Audit which agents connect to affected MCP servers Full writeup: https://securingagents.com/cve/cve-2026-26118/

    Post summary

    The post focuses on applying the March 2026 Microsoft patch and implementing mitigation steps for CVE-2026-26118, without providing PoC, exploit details, or evidence of active attacks.

    0000058
    1 followersView on X
  • gmanjuu@gmanjuu
    Disclosure

    We found real CVEs in servers people actually use: • FAISS: arbitrary file read/write via crafted indexes • TorchServe: SnakeYAML RCE • Microsoft Azure MCP: SSRF + SQL injection (CVE-2026-26118) All reported. Classic web vulns in AI infra.

    Post summary

    The post announces several newly disclosed CVEs affecting AI infrastructure services, noting typical web vulnerabilities such as RCE, SSRF, and SQL injection.

    0000023
    908 followersView on X
  • VPNGUIDER@vpnguider
    Disclosure

    Azure MCP Server SSRF CVE-2026-26118 is a CVSS 8.8 SSRF bug in Azure's Model Context Protocol server that lets attackers escalate privileges over the network. As companies race to deploy AI agents via MCP, this attack surface just became a serious liability. #Azure #MCP #VPNGuider

    Post summary

    The post announces CVE‑2026‑26118, a CVSS‑8.8 SSRF bug in Azure's MCP server that allows privilege escalation, but provides no PoC, exploit code, patch, or live‑attack evidence.

    0000040
    62 followersView on X
  • ナタリー 🌙@natalie_avfieb
    General

    CoSAI mapped 40 threats across MCP. Add CVE-2026-27825, CVE-2026-27826, and CVE-2026-26118, and the pattern is clear: auth is not enough. I keep MCP guard in front of every new server because runtime inspection matters.

    Post summary

    The post lists three CVEs and advises that authentication alone is insufficient, but provides no technical detail, PoC, or exploit information.

    0000019
    78 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-26118: HIGH] Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network.#cve,CVE-2026-26118,#cybersecurity https://cvefind.com/CVE-2026-26118

    Post summary

    The tweet announces CVE‑2026‑26118, a SSRF vulnerability in Azure MCP Server that could enable privilege escalation, but it provides no exploit code, patch details, or evidence of active attacks.

    0000035
    601 followersView on X
CPE platform detail17 entries

17 of 17 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftazure_mcp_server---
Appmicrosoftazure_mcp_server2.0.0--
Appmicrosoftazure_mcp_server2.0.0--
Appmicrosoftazure_mcp_server2.0.0--
Appmicrosoftazure_mcp_server2.0.0--
Appmicrosoftazure_mcp_server2.0.0--
Appmicrosoftazure_mcp_server2.0.0--
Appmicrosoftazure_mcp_server2.0.0--
Appmicrosoftazure_mcp_server2.0.0--
Appmicrosoftazure_mcp_server2.0.0--
Appmicrosoftazure_mcp_server2.0.0--
Appmicrosoftazure_mcp_server2.0.0--
Appmicrosoftazure_mcp_server2.0.0--
Appmicrosoftazure_mcp_server2.0.0--
Appmicrosoftazure_mcp_server2.0.0--
Appmicrosoftazure_mcp_server2.0.0--
Appmicrosoftazure_mcp_server2.0.0--

Explore more