A critical prompt injection vulnerability in Upstash's Context7 documentation server, installed by millions of developers, has no documented fix four days after disclosure. Researchers say it may be a regression of a bug patched in February.
A critical prompt injection vulnerability in Upstash's Context7 documentation server, installed by millions of developers, has no documented fix four days after disclosure. Researchers say it may be a regression of a bug patched in February.
CVE-2026-59726, dubbed RufRoot, is a CVSS 10.0 flaw in Ruflo's MCP bridge that lets unauthenticated attackers execute shell commands, steal LLM API keys, and poison the platform's persistent AI memory store. Patch ships quickly; poisoned AgentDB entries do not self-clear.
CVE-2026-10591 in AWS Kiro allowed a hidden prompt injection payload on a web page to silently rewrite the IDE's MCP server config and execute attacker code with developer privileges, bypassing all user-approval prompts.
Unit 42 researchers found five malicious skills on ClawHub that slipped past automated scanners, delivering AMOS malware and running agentic financial scams. The AI agent skill marketplace is the new npm — and it has the same supply chain problem.
Research published in June 2026 documents a new supply-chain attack class targeting AI coding agent skill ecosystems: VulMask disguises malicious payloads as security vulnerabilities inside skill auxiliary resources, evading automated scanners. A Snyk audit of 3,984 skills found 13.4% carry critical-severity issues.
Salt Security's 1H 2026 State of AI and API Security report finds 92% of organizations lack the maturity to defend AI agent environments, while 99% of attack attempts originate from authenticated sources — rogue agents operating with legitimate credentials and no human oversight.
Orca Security's 2026 State of AI Security Report finds that nearly all AI vulnerability alerts with available patches are ignored, while 74% of companies carry at least one critical CVE in their AI stack.
CVE-2026-21858 gives unauthenticated attackers full code execution on n8n workflow servers. Langflow's new IDOR vulnerability has been added to CISA KEV. GitHub Copilot's MCP integration carries a prompt-injection-to-RCE chain. AI automation infrastructure is becoming a primary attack surface.
Microsoft Incident Response published research showing how attackers can hijack agentic AI workflows by planting hidden instructions in MCP tool description fields — a vector that bypasses most current enterprise controls because each step the agent takes looks routine.
Nine vulnerabilities including a hardcoded authentication bypass and critical MCP command injection were disclosed in PraisonAI, with scanners targeting the auth bypass endpoint less than four hours after the advisory went public.
CVE-2026-12957 lets a malicious repository silently execute arbitrary commands the moment a developer opens it in Amazon Q Developer, exfiltrating AWS credentials with no user interaction required.
A Censys scan found 12,520 publicly exposed MCP services — 40% with no authentication at all. Combined with 106 zero-days found in an automated academic scan and a CVSS 10.0 flaw in a popular MCP server, the AI agent infrastructure layer is becoming one of 2026's most under-patched attack surfaces.
A three-flaw chain in Microsoft AutoGen Studio's MCP WebSocket surface lets a malicious webpage execute arbitrary commands on the host via an AI browsing agent. Microsoft patched in June 2026.
Sophos researchers uncovered an operational threat actor lab using Claude Opus 4.5, Cursor, and MCP to build and test EDR evasion malware against live Sophos, CrowdStrike, and Microsoft Defender installations.
Tenet Security's Threat Labs published research on June 17 demonstrating how a single fake Sentry error event can hijack AI coding agents like Claude Code and Cursor into executing arbitrary code on developer machines — no phishing, no infrastructure access, 85% success rate across 100+ tested organisations.
Adversa AI disclosed SymJack (symlink hijacking to plant malicious MCP servers) and TrustFall (trust dialog bypass) hitting six AI coding agents including Copilot and Cursor.
CISA added CVE-2026-42271 to KEV after Horizon3.ai chained the LiteLLM MCP command injection flaw with a Starlette auth bypass for unauthenticated RCE. Federal deadline: June 22.
The NSA AISC's May 2026 CIS on MCP security: authentication gaps, tool poisoning via unsigned dynamic discovery, session-identity binding failures, and compensating controls.