CVE-2026-7600Disclosure

LOWCVSS 2.1 · LOW

Exploit discussion active in current signal (5 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A flaw has been found in ArtMin96 yii2-mcp-server 1.0.2. This impacts the function yii_command_help/yii_execute_command of the file src/index.ts of the component MCP Interface. Executing a manipulation can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 5 total mentions across 1 day

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-05-02: 5PoC Mentioned / Linked · 2026-05-02: 1Patch / Workaround · 2026-05-02: 1Technical Details · 2026-05-02: 305-02
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets4 URLs
Full discourse5 posts
  • NerdieNews@NewsNerdie
    Patch

    ⚠️ CVE-2026-7600 in ArtMin96 yii2-mcp-server lets attackers execute OS commands remotely. This agentic AI vulnerability can lead to complete server compromise. Remove version 1.0.2 today. #NerdieNews #CyberSecurity #InfoSec #ThreatIntel #APT https://t.co/69sXCGTNYo

    Post summary

    CVE-2026-7600 allows remote command execution on ArtMin96 yii2-mcp-server; users are urged to remove the vulnerable v1.0.2 to mitigate the risk.

    0000041
    57 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-7600 📊 Severity: 6.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7600 #CVE-2026-7600 #CVE #Medium #CyberSecurity #InfoSec https://t.co/XcCK6RLmgk

    Post summary

    The tweet announces CVE-2026-7600, indicating a medium‑risk vulnerability with a severity score of 6.3, but provides no detailed technical information, proof of concept, or mitigation guidance.

    0000046
    151 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-7600 A flaw has been found in ArtMin96 yii2-mcp-server 1.0.2. This impacts the function yii_command_help/yii_execute_command of the file src/index.ts of the component MCP In… https://www.cve.org/CVERecord?id=CVE-2026-7600 ----- Traducción: Se ha encontrado … http://infoflow.cloud`

    Post summary

    The tweet merely announces CVE‑2026‑7600 in ArtMin96 yii2‑mcp‑server with a short reference link, lacking detailed technical or exploit information.

    0000038
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7600 A flaw has been found in ArtMin96 yii2-mcp-server 1.0.2. This impacts the function yii_command_help/yii_execute_command of the file src/index.ts of the component MCP In… https://www.cve.org/CVERecord?id=CVE-2026-7600

    Post summary

    A new CVE-2026-7600 vulnerability has been disclosed, affecting the yii2‑mcp‑server 1.0.2 component’s yii_command_help/yii_execute_command functions; no PoC, exploit, or patch information is provided.

    00000253
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7600 Remote OS Command Injection in ArtMin96 yii2-mcp-server 1.0.2 MCP Interface https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7600

    Post summary

    The text announces a new vulnerability, Remote OS Command Injection in ArtMin96 yii2-mcp-server 1.0.2, without providing PoC, exploit code, or mitigation details.

    0000058
    4.0K followersView on X

Explore more