Karthik Ramadoss[verified]@KIntheHousePatch
The post highlights that a large portion of MCP servers are vulnerable, notes Microsoft’s patch of CVE-2026-26118, but provides no PoC, exploitation details, or technical specifics.
しゅん|AIエンジニアの日常[verified]@shun_aidevPoC
A newly disclosed RCE vulnerability (CVE‑2026‑26118) in Azure MCP Server has been demonstrated via the "MCPwned" PoC, enabling SSRF-based token theft and tenant takeover; the issue was patched in March and requires immediate remediation.
AI Security Guard[verified]@ai_security_10xDisclosure
The tweet announces a new article discussing CVE-2026-26118 as an MCP‑specific privilege escalation vulnerability, but it provides no proof‑of‑concept, exploit details, mitigation, or evidence of active exploitation.
しゅん|AIエンジニアの日常[verified]@shun_aidevDisclosure
The post lists multiple MCP-related CVEs, providing technical impact details and patch status, and urges patch management and input validation as top priorities.
AgentEconomy[verified]@AgentEconoemyDisclosure
The post announces CVE‑2026‑26118 (CVSS 8.8) and notes that raw MCP is not enterprise‑ready, recommending isolated execution as a mitigation, but offers no exploit, patch, or PoC details.
Hermetic[verified]@HermeticSysActive Exploitation
The post details multiple MCP-related CVEs, noting both patches and confirmed active exploitation, including RCEs and OAuth chain breaches, illustrating an escalating risk across the stack.
VPNGUIDER[verified]@vpnguiderDisclosure
The post announces CVE‑2026‑26118, a CVSS‑8.8 SSRF bug in Azure's MCP server that allows privilege escalation, but provides no PoC, exploit code, patch, or live‑attack evidence.
Alexei Belous@AlexeiBelousPatch
Microsoft patched CVE-2026-26118, which involved crafted input exposing managed identity tokens and enabling MCP RCE for a full Azure tenant takeover; no exploit code or active attacks were reported.