Desk/2026-W16

Week of Apr 13–19, 2026

3 records0 status changes on new evidence1 new findings

New findings

Attacks & incidents

Apr 15, 2026
OX Security advisory: MCP STDIO configuration enables command execution across agent frameworks
AttackVulnerability disclosureOX Security, Anthropic

OX Security reports that MCP's STDIO transport turns configuration into OS command execution, and that frameworks exposing that configuration to users, networks or prompt injection inherited remote code execution, with 12+ CVEs across projects such as LangFlow, LiteLLM, Flowise and Windsurf. The Hacker News reports Anthropic characterized the protocol behavior as expected and did not change the reference design.

Apr 15, 2026
MCPwn: unauthenticated MCP endpoint in nginx-ui exploited in the wild (CVE-2026-33032)
AttackVulnerability disclosurePluto Security, Recorded Future, nginx-ui project

Pluto Security found that nginx-ui's MCP integration left a message endpoint effectively unauthenticated under default settings, letting anyone reach its administrative MCP tools and take over the web server. The flaw (CVSS 9.8) was fixed in version 2.3.4 on 2026-03-15, and Recorded Future listed it among actively exploited vulnerabilities in March 2026.

Policy & standards