Daily digest · Sep 16, 2026
VulnWatch Daily: Critical RCE in LMDeploy, MCP Auth Bypasses, and vLLM DoS
Today's digest highlights a critical pickle deserialization RCE in LMDeploy, unauthenticated file reads in MCP servers leading to token theft, and multiple denial-of-service vectors in vLLM and Chroma affecting multi-tenant isolation.
Subscribers only
The full Daily Briefing is available to VulnWatch subscribers. Subscribe to read this digest and get tomorrow's delivered to your inbox.
See pricing