chiprook
← Security
SecurityOctober 6, 2026, 07:00

Google, JPMorgan and two governments fixed the same MCP flaw

Researcher Syed Anas Mohiuddin reported the same SSRF flaw in MCP servers at Google, JPMorgan Chase, Weaviate, France's DINUM and Indonesia's Tangerang city government. Google's issue is tracked as CVE-2026-14540 with a high 8.0 rating, affecting versions 0.3.0 to 1.4.0; all five have shipped fixes. Five US GSA MCP servers and Japan's Digital Agency server remain unfixed.

Google, JPMorgan and two governments fixed the same MCP flaw
#Google#JPMorgan#MCP#Weaviate
Read next
Security

Researcher finds SSRF flaws in MCP servers from Google, Anthropic, Microsoft and Weaviate

Security

XenForo 2.3.13 fixes two authentication flaws

Security

Vulnerability in Google and other AI agents exposes structural flaw in MCP

Security

Ox Security: MCP Servers Create Major Enterprise Governance Gaps