ナタリー 🌙@AbsolcassoPatch
The author notes that CVE-2026-3484 and CVE-2026-27825 have been patched, yet the architectural flaw allowing payloads in MCP responses still exists, suggesting a broader systemic issue.
CVE@CVEnewDisclosure
A new vulnerability (CVE-2026-3484) has been identified in PhialsBasement nmap-mcp-server, targeting the child_process.exec function, but no exploit code, patch, or evidence of active exploitation is provided.
ナタリー 🌙@AbsolcassoGeneral
The text lists two CVEs with an RCE designation and advises scanning MCP servers, but provides no PoC, exploitation details, or patch information.
Vulmon Vulnerability Feed@VulmonFeedsGeneral
The text simply lists CVE‑2026‑3484 with a one‑line description of a Remote Command Injection flaw and provides a link to vulnerability details, offering no further actionable information.
Infoflowcloud@infoflowcloudGeneral
The post references CVE-2026-3484 affecting PhialsBasement nmap-mcp-server, noting the child_process.exec function is impacted, but provides no further details on exploitation, patching, or technical depth.
Jasper@Tristin_0aDisclosure
The post announces that MCP Server has two new RCE vulnerabilities (CVE-2026-3484 and CVE-2026-25710) and offers a priced test service, but it provides no PoC, exploit code, patch information, or evidence of active exploitation.
ナタリー 🌙@AbsolcassoDisclosure
The text discloses that CVE-2026-3484 allows arbitrary code execution in nmap-mcp-server due to unsanitized shell input passed to child_process.exec.
ナタリー 🌙@AbsolcassoActive Exploitation
The text reports that CVE-2026-3484, an RCE in nmap-mcp-server due to unsanitized input via child_process.exec, is actively being exploited in the wild.