ɐpnH[verified]@AlAssaf_HDisclosure
The post discloses CVE-2026-73296 as an unauthenticated remote ADB vulnerability in Microsoft UFO Mobile MCP, providing technical exploitation details and a high CVSS score, but offers no PoC, exploit code, patch, or evidence of active exploitation.
Rıdvan Yağlı[verified]@ridvanyagliPatch
The post announces a high‑severity vulnerability in Microsoft UFO and provides patch guidance, making patch discussion the main focus.
Bussio28Team | Ciberseguridad sin humo[verified]@Bussio28TeamDisclosure
The post announces CVE‑2026‑73296, a high‑severity flaw in Microsoft UFO that can let attackers gain control of Android devices through ADB when MCP services are unauthenticated, and urges users to block ports 8020/8021.
The Daily Tech Feed[verified]@dailytechonxDisclosure
The post announces Microsoft UFO CVE‑2026‑73296 as a high‑risk flaw permitting remote control of Android devices without authentication, providing technical details and remediation advice, but no exploit code or evidence of current exploitation.
セキュリティ対策Lab[verified]@securityLab_jpDisclosure
The article announces CVE-2026-73296, highlighting a vulnerability in Microsoft UFO Mobile MCP that could allow unauthenticated remote control of Android devices, but offers no PoC, exploit details, mitigation, or evidence of active exploitation.
Upwind Security MDR[verified]@UpwindMDRDisclosure
A critical unauthenticated remote control vulnerability (CVE-2026-73296) in Microsoft UFO's streamable HTTP MCP services is disclosed, affecting versions below 3.0.8, with remediation via upgrading to 3.0.8.
SecAlerts@SecAlertsCoDisclosure
A CVE‑2026‑73296 vulnerability with CVSS 9.4 was discovered in Microsoft's UFO automation framework, and fix information is available on SecAlerts.
SDTEK@SDTEKActive Exploitation
CVE-2026-73296 is a critical flaw in Microsoft’s AI agent OS that allows attackers on the same network to silently read OTPs, messages, and screen data, and to type commands on target phones, with no patch available yet.