Unite.Ai Common SSRF Vulnerability Discovered in Multiple MCP Implementations
Article Content
- •Five organizations, including Google and JPMorgan, confirmed the same SSRF vulnerability.
- •The vulnerability is attributed to unsafe handling of upstream data in MCP servers.
- •CVE-2026-14540 has a high severity rating of 8.0, while CVE-2026-97228 is rated low.
Independent researcher Syed Anas Mohiuddin disclosed a server-side request forgery (SSRF) vulnerability affecting Model Context Protocol (MCP) servers at five organizations, including Google and JPMorgan Chase. The flaw arises from unsafe handling of upstream data and a structural gap in MCP server design. Each organization confirmed and fixed the issue independently, supporting Mohiuddin's hypothesis that the vulnerability is not due to a single implementation error. The vulnerability has been documented under CVE-2026-14540, with a high severity rating of 8.0. A related CVE, CVE-2026-97228, was published later but is rated low severity. The issue remains open in five US federal MCP servers. The findings indicate a broader risk across unrelated systems that utilize the same protocol.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Google and CVE-2026-14540 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which organizations are affected?
What is the severity of the vulnerabilities?
What should organizations do?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…