AI Governance Institute
← News
Research2026-10-09

Google, JPMorgan, and Two Governments Exposed by Recurring MCP Server Flaw

Source

MCP for agent-to-agent comms may be the riskiest protocol you've never heard of

Ars Technica

Via Ars Technica

What happened

Researchers disclosed a recurring server-side request forgery weakness in MCP servers operated by five named organizations: Google, JPMorgan Chase, Weaviate, France's DINUM, and Tangerang City. The flaw lets an attacker or compromised AI agent manipulate where an agent's outbound requests are sent. MCP, or Model Context Protocol, is the emerging standard for connecting AI agents to external tools, data sources, and other agents. As reported by Ars Technica, agents exploiting the flaw could pivot malicious instructions across agent-to-agent communication paths, effectively using one compromised agent as a launchpad against others. The site has previously covered 68 MCP Server CVEs in One Month. It has also covered a CVE-2026-75130 MCP bug with no documented fix. This research follows that broader pattern of MCP security failures. Researchers concluded that MCP deployments need destination validation, network isolation, explicit authorization for sensitive inter-agent transactions, and security testing of delegation paths.

Why it matters

  • ·The named victims include a global systemically important bank and two government bodies. Regulators monitoring these sectors will scrutinize MCP deployments under the EU AI Act (Regulation (EU) 2024/1689) and financial sector model risk frameworks.
  • ·The flaw is structural and recurring, not a single misconfiguration. It reappeared across five unrelated organizations using MCP. Any compliance team that approved an MCP-based agentic deployment without reviewing outbound request controls and inter-agent authorization has an open gap in its current risk posture.
  • ·Agent-to-agent attacks bypass the controls most organizations rely on. Human approval gates and logging are typically set where a human interacts with an agent, not along internal agent-to-agent paths. This finding directly challenges the assumption that oversight of the first agent in a chain is sufficient.

Governance controls affected

What to do now

  • ☐Ask your engineering or infrastructure team to produce a list of every MCP server your organization operates or connects to, including those managed by third-party vendors, and confirm which ones are in production with live agent traffic.
  • ☐For each MCP server identified, ask whether outbound requests from agents are validated against an approved list of destinations, or whether an agent can be instructed to send requests to arbitrary internal or external addresses.
  • ☐Review whether your inter-agent communication paths, meaning cases where one AI agent instructs or calls another, require explicit authorization before sensitive actions are taken, and document where no such requirement exists.
  • ☐Instruct your security team to include MCP delegation paths in the next scheduled adversarial test of your agentic systems, specifically testing whether a compromised downstream agent can relay instructions back upstream.
  • ☐If your organization is a financial institution or government body, assess whether this finding must be disclosed under existing model risk management or operational resilience reporting requirements, and log the assessment decision with rationale.

What to watch next

The breadth of named victims across private and public sectors will likely draw regulatory attention to MCP as infrastructure requiring formal security review, not just vendor assurance. Compliance teams should watch for updated guidance from the Five Eyes Guidance on the Careful Adoption of Agentic AI Services. They should also monitor financial regulators who have already signaled concern about agentic risk in bank supervision. Recurring MCP vulnerabilities now span dozens of CVEs and multiple named enterprises. This pattern is likely to inform forthcoming standards work. Watch for updates to the CIS MCP Benchmark and related agent security baselines.

Related Coverage

Corporate Policy2026-10-08

AWS Strands Box Raises the Bar for Agent Behavioral Containment

Amazon Web Services has released Strands Box in developer preview, an open-source tool that enforces behavioral policies on AI agents at the operating system level. It intercepts agent actions across shell commands, Python scripts, and connections to external tool services. Organizations can set limits such as blocking network requests or capping the rate at which an agent can post messages. Analysts note it complements but does not replace access management, monitoring, and human oversight controls.

Research2026-10-02

Six Agentic Failure Modes Show Soft Guardrails Are Not Enough

A practitioner analysis published by CSO Online identifies six named failure modes in deployed AI agents, including prompt injection, context manipulation, and authorization abuse. The analysis draws on real incidents, including the OpenAI Atlas browser hijack and the Microsoft 365 Copilot EchoLeak exploit. It concludes that enterprises relying solely on vendor-configured content filters and system-prompt instructions have not closed the control loop.

Corporate Policy2026-10-08

Google's Agentic Gemini Gives AI Its Own Email Address and Audit Trail

Google has launched an enterprise agentic AI product built on Gemini, announced at a Google Cloud event on October 8, 2026. The agent operates with its own Workspace account and email address, takes autonomous action across connected business systems, and supports multi-model orchestration including Anthropic's Claude. Google stated it will prioritize business deployment before consumer rollout, citing security, scale, and performance as unresolved challenges.