CVE-2026-73497

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-15: 109-15
Full discourse1 post
  • Upwind Security MDR@UpwindMDR

    🚨 HIGH - Dual Vulnerabilities in MCP Atlassian (CVE-2026-73496 & CVE-2026-73497) MCP Atlassian patched two flaws allowing local file disclosure and SSRF attacks: • CVE-2026-73496: Path traversal in attachment uploads allows attackers to read arbitrary server files and secrets. • CVE-2026-73497: TOCTOU DNS-rebinding SSRF flaw enables access to internal endpoints and cloud metadata. 👉 Affected: mcp-atlassian prior to 0.22.0 | Upgrade to version 0.22.0 or later immediately

    0000050
    303 followersView on X

Explore more