VulnWatch VulnWatch
← Back to dashboard
Medium nvd · CVE-2026-9680

CVE-2026-9680: Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP

Published Jul 28, 2026 CVSS 5.8

Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listening on all network interfaces by default.

Affected AI Products

mcp server
Get the weekly digest. Every Monday: top AI security stories of the week. Free.