chiprook
← Security
SecurityOctober 4, 2026, 08:47

Four MCP servers hit by unauthenticated CVEs in 48 hours

Between September 14 and 15, NVD published four CVEs for MCP servers scoring 9.8 to 10.0: Bifrost, mysql-mcp-server, IBM's mcp-contextforge-gateway and @zereight/mcp-gitlab. All four expose tools without authentication, and fixes for two of them shipped back in June.

Four MCP servers hit by unauthenticated CVEs in 48 hours
#IBM#GitLab#MySQL#MCP
Read next
Security

CVE-2026-85706: unauthenticated file read in GitLab exploited

AI

IBM brings Bob to self-hosted and air-gapped environments

Software

GitLab 19.4 adds agentic automation tools

Science

Four astronauts reach ISS in 8 hours, setting US speed record