AI Governance Institute
← News
Research2026-09-11

68 MCP Server CVEs in One Month Expose a Systemic Agent Supply Chain Gap

What happened

Adversa AI published its MCP security September 2026: Deadbugz + 3 server CVEs roundup on September 7, 2026, documenting 68 reportable vulnerabilities discovered across audited MCP servers during the preceding period. The vulnerability classes identified include SQL injection, server-side request forgery targeting cloud metadata services, prompt template injection, and path traversal, each of which can enable data exfiltration, credential theft, or agent hijacking in a live enterprise deployment. The report names specific CVEs alongside a campaign tracked as Deadbugz, providing concrete artifacts that compliance and security teams can use to assess exposure in their own toolchains. This roundup follows a prior audit finding that 91.8% of audited MCP servers lack OAuth, and builds on related research on MCP server context injection across 19 servers, confirming that the MCP layer represents a repeating, systemic vulnerability pattern rather than an isolated finding. Enterprises relying on agentic platforms that connect to external MCP servers are exposed through dependencies they have typically not evaluated as part of their standard AI procurement or vendor risk processes.

Why it matters

  • ·Most enterprise vendor due diligence programs assess the AI model or agent platform, but not the MCP server layer those platforms depend on. With 68 vulnerabilities catalogued in a single month, including SSRF flaws that can harvest cloud metadata credentials, the MCP server tier now represents a material, ungoverned segment of the agent supply chain that procurement risk assessments must explicitly cover.
  • ·SSRF and SQL injection flaws in MCP servers can compromise the integrity of agent audit trails and expose regulated data, creating direct exposure under data protection regimes and sector-specific rules. Organizations in financial services, healthcare, and critical infrastructure face the highest consequence if an MCP server vulnerability enables credential exfiltration or unauthorized data access during an agent workflow.
  • ·The pattern documented across prior MCP audits and this month's findings signals that MCP server insecurity is structural, not episodic. Compliance teams that have not added MCP server dependency mapping and vulnerability tracking to their agent governance programs are operating with a control gap that regulators and insurers are increasingly likely to treat as a failure of reasonable care.

Governance controls affected

What to do now

  • ☐Inventory every MCP server your agentic platforms connect to, including third-party and open-source implementations, and confirm whether each has been assessed for SQL injection, SSRF, path traversal, and prompt template injection vulnerabilities.
  • ☐Map the Deadbugz campaign indicators and the three named CVEs from the Adversa AI September 2026 report against your current MCP server deployments and initiate patching or isolation for any confirmed matches.
  • ☐Extend your AI vendor due diligence questionnaire to explicitly cover MCP server security controls, including authentication mechanisms, input validation practices, and patch cadence, for all agent toolchain dependencies.
  • ☐Apply network-layer isolation controls to MCP servers so that cloud metadata service endpoints are unreachable from agent-accessible server processes, directly mitigating the SSRF class of vulnerabilities documented in this report.
  • ☐Establish a recurring MCP server vulnerability monitoring workflow, tied to your existing CVE tracking process, so that newly disclosed flaws in this layer trigger re-assessment of deployed agent toolchains within a defined SLA.

What to watch next

Adversa AI has signaled ongoing audit activity across MCP server implementations, and the Deadbugz campaign suggests active exploitation interest in this vulnerability class. Compliance teams should monitor whether any of the three named CVEs attract CISA Known Exploited Vulnerability designations, which would trigger mandatory remediation timelines for organizations subject to federal contract requirements. The OWASP GenAI MCP server security baseline and the MCP Project sandboxing guidance are both live reference points that regulators and auditors are beginning to cite as minimum standards, and teams that have not yet mapped controls against those baselines should prioritize that gap before the next audit cycle.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-10-01

Akamai: MCP Attack Surface Requires Zero Trust Controls and Machine Identity Governance

Akamai published a research report arguing that the Model Context Protocol (MCP) has become a significant enterprise attack surface. MCP is the standard that lets AI agents connect to external tools and systems. The report finds that malicious MCP servers can manipulate AI agent behavior through prompt injection and cross-server attacks. Akamai calls for organizations to inventory MCP servers, enforce least-privilege permissions, govern machine identities, and monitor autonomous agent activity.

Research2026-09-19

BragJack Attack Turns Browser Extensions Into AI Agent Hijack Tools

Security researcher Gal Weizman disclosed a new attack class called BragJack, showing how a single malicious browser extension can seize control of AI agents in Chrome, Edge, Perplexity Comet, Opera Neon, and Claude for Chrome. Using a native browser mechanism, attackers can force hijacked agents to read local files, capture screenshots, access browsing history, and send emails on behalf of victims. Enterprise compliance programs are directly affected because the attacks exploit privileged AI agent access, not conventional malware, complicating detection and existing endpoint controls.

Corporate Policy2026-10-01

Microsoft Entra MCP Firewall Makes Agent Traffic Control a Named Governance Requirement

Microsoft has previewed an Entra MCP Firewall that gives administrators centralized visibility and policy control over traffic between AI agents and external tool servers. The guidance pairs the firewall with requirements for unique agent identities, time-limited access elevations, tool allowlists, and full logging. The announcement marks the first major identity platform vendor to ship a named product addressing the agent-to-tool control gap.