chiprook
← Security
SecuritySeptember 29, 2026, 10:29

Researcher finds SSRF flaws in MCP servers from Google, Anthropic, Microsoft and Weaviate

Over nine months in 2026 a researcher found the same SSRF bug shape in MCP servers shipped by Google, Anthropic, Microsoft and Weaviate. Google assigned CVE-2026-14540 (CVSS 8.0) and fixed it in mcp-toolbox v1.5.0; the other vendors have not confirmed fixes.

Researcher finds SSRF flaws in MCP servers from Google, Anthropic, Microsoft and Weaviate
#Google#Anthropic#Microsoft#Weaviate
Read next
Security

Researchers use AI to find widespread software decoder flaw

Security

Ox Security: MCP Servers Create Major Enterprise Governance Gaps

Security

The MCP server that changes its mind after you approve it

Security

Tool Poisoning on MCP Servers: The Attack Vector Nobody's Patching