CVE Feed
- CVE-2026-7600 – ArtMin96 yii2-mcp-server MCP index.ts yii_execute_command os command injection May 2, 2026
- CVE-2026-7599 – Dayoooun hwpx-mcp MCP index.ts export_to_html path traversal May 1, 2026
- CVE-2026-7597 – mem0ai mem0 faiss.py pickle.dump deserialization May 1, 2026
- CVE-2026-7598 – libssh2 userauth.c userauth_password integer overflow May 1, 2026
- CVE-2026-7595 – nextlevelbuilder ui-ux-pro-max-skill Tailwind Config Generator tailwind_config_gen.py _format_plugins code injection May 1, 2026
- CVE-2026-7596 – nextlevelbuilder ui-ux-pro-max-skill Slide Generator generate-slide.py data.get cross site scripting May 1, 2026
- CVE-2026-39805 – CL.CL HTTP request smuggling via duplicate Content-Length in bandit May 1, 2026
- CVE-2026-39807 – Client-supplied URI scheme trusted without transport verification in bandit May 1, 2026
- CVE-2026-42786 – WebSocket fragmented message reassembly unbounded in bandit May 1, 2026
- CVE-2026-42788 – HTTP/2 frame size limit checked after body is buffered in bandit May 1, 2026
- CVE-2026-7593 – Sunwood-ai-labs command-executor-mcp-server MCP index.ts execute_command os command injection May 1, 2026
- CVE-2026-7594 – Flux159 mcp-game-asset-gen MCP index.ts image_to_3d_async path traversal May 1, 2026
- CVE-2025-12993 – Apache HTTP Server Cross-Site Scripting Vulnerability May 1, 2026
- CVE-2026-39804 – WebSocket permessage-deflate inflate has no output-size cap in bandit May 1, 2026
- CVE-2026-7592 – itsourcecode Courier Management System edit_staff.php sql injection May 1, 2026
- CVE-2025-8903 – Apache HTTP Server Remote Code Execution Vulnerability May 1, 2026
- CVE-2026-7589 – ghantakiran splunk-mcp-integration CSV Export csv_export.py create_csv_export path traversal May 1, 2026
- CVE-2026-7590 – eyal-gor p_69_branch_monkey_mcp Preview Endpoint advanced.py os command injection May 1, 2026
- CVE-2026-7591 – TimBroddin astro-mcp-server MCP Tool Query Construction index.ts sql injection May 1, 2026
Microsoft Security
- Microsoft Agent 365, now generally available, expands capabilities and integrations May 1, 2026​Today we’re announcing the general availability of Agent 365, plus previews of new capabilities to discover and manage shadow AI agents, including local agents like OpenClaw and Claude Code. The post Microsoft Agent 365, now generally available, expands capabilities and integrations appeared first on Microsoft Security Blog.Nirav Shah, Rob Lefferts and Jason Roszak
- What’s new, updated, or recently released in Microsoft Security April 30, 2026Stay ahead of emerging threats with Microsoft’s newest security innovations and updates, delivered through the In the Loop series. The post What’s new, updated, or recently released in Microsoft Security appeared first on Microsoft Security Blog.Alym Rayani
- Email threat landscape: Q1 2026 trends and insights April 30, 2026In early 2026, email threats increased with a rise in credential phishing, QR code phishing, and CAPTCHA-gated campaigns, highlighted by Microsoft’s disruption of the Tycoon2FA phishing platform which led to a 15% volume decrease and shifts in threat actor tactics. The post Email threat landscape: Q1 2026 trends and insights appeared first on Microsoft Security […]Microsoft Threat Intelligence and Microsoft Defender Security Research Team
- 8 best practices for CISOs conducting risk reviews April 29, 2026Embracing strong proactive security is something we can all do to mitigate our increased exposure to security threats. The post 8 best practices for CISOs conducting risk reviews appeared first on Microsoft Security Blog.Rico Mariani
- Simplifying AWS defense with Microsoft Sentinel UEBA April 28, 2026Learn how Microsoft Sentinel UEBA helps defenders distinguish benign AWS activity from attacker behavior by enriching raw CloudTrail logs with clear, binary behavioral signals derived from baseline user, peer, and device behavior patterns. The post Simplifying AWS defense with Microsoft Sentinel UEBA appeared first on Microsoft Security Blog.Microsoft Defender Security Research Team



