Week of Apr 13–19, 2026
New findings
Attacks & incidents
OX Security reports that MCP's STDIO transport turns configuration into OS command execution, and that frameworks exposing that configuration to users, networks or prompt injection inherited remote code execution, with 12+ CVEs across projects such as LangFlow, LiteLLM, Flowise and Windsurf. The Hacker News reports Anthropic characterized the protocol behavior as expected and did not change the reference design.
Pluto Security found that nginx-ui's MCP integration left a message endpoint effectively unauthenticated under default settings, letting anyone reach its administrative MCP tools and take over the web server. The flaw (CVSS 9.8) was fixed in version 2.3.4 on 2026-03-15, and Recorded Future listed it among actively exploited vulnerabilities in March 2026.
Policy & standards
Google DeepMind's Frontier Safety Framework version 3.1 introduced Tracked Capability Levels for earlier warning in CBRN and ML R&D and misalignment, and raised the recommended security for the CBRN, cyber and harmful manipulation CCLs to Security Level 2+. The cyber CCL definition itself, Cyber uplift level 1, is unchanged from v3.0.