Sentinelone CVE-2026-91988: Remote Code Execution Vulnerability in atomic-agents-stack
Article Content
- •CVE-2026-91988 allows remote code execution via cleartext HTTP connections.
- •Affected versions are atomic-agents-stack prior to 1.1.0; urgent patching is required.
- •Current intelligence indicates no active exploitation, but risks remain significant.
CVE-2026-91988 is a critical remote code execution vulnerability affecting atomic-agents-stack versions prior to 1.1.0. The flaw allows attackers to exploit cleartext HTTP connections in the HTTP MCP server-registry backend factory. By intercepting and modifying catalog responses, attackers can inject arbitrary commands that are executed on the agent host. This vulnerability poses a serious risk, particularly for organizations using agentic AI workflows with HTTP-based MCP registries. Although current intelligence does not indicate active exploitation, the potential for unauthorized control over agent hosts exists. Organizations are urged to upgrade to the fixed version and disable HTTP registry use. The vulnerability was published on September 15, 2026, and requires urgent remediation. Attackers could potentially manipulate automated workflows, steal secrets, or disrupt services.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-91988 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…