Skip to content
CVE-2026-91988: Remote Code Execution Vulnerability in atomic-agents-stack

CVE-2026-91988: Remote Code Execution Vulnerability in atomic-agents-stack

First seen 19 Sep 2026, 21:21 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 19, 2026 at 22:21 UTC
  • CVE-2026-91988 allows remote code execution via cleartext HTTP connections.
  • Affected versions are atomic-agents-stack prior to 1.1.0; urgent patching is required.
  • Current intelligence indicates no active exploitation, but risks remain significant.

CVE-2026-91988 is a critical remote code execution vulnerability affecting atomic-agents-stack versions prior to 1.1.0. The flaw allows attackers to exploit cleartext HTTP connections in the HTTP MCP server-registry backend factory. By intercepting and modifying catalog responses, attackers can inject arbitrary commands that are executed on the agent host. This vulnerability poses a serious risk, particularly for organizations using agentic AI workflows with HTTP-based MCP registries. Although current intelligence does not indicate active exploitation, the potential for unauthorized control over agent hosts exists. Organizations are urged to upgrade to the fixed version and disable HTTP registry use. The vulnerability was published on September 15, 2026, and requires urgent remediation. Attackers could potentially manipulate automated workflows, steal secrets, or disrupt services.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-15
CVE-2026-91988 published
CVE-2026-91988 was published to the National Vulnerability Database, detailing a critical RCE vulnerability.
Sentinelone
2026-09-16
Redpacketsecurity issues CVE alert
Redpacketsecurity alerts organizations about the CVE-2026-91988 vulnerability, emphasizing the need for urgent remediation.
Redpacketsecurity
2026-09-19
Sentinelone article published
Sentinelone publishes an article detailing the technical aspects and mitigation strategies for CVE-2026-91988.
Sentinelone

More articles in this cluster (2)

Following this threat?

Track CVE-2026-91988 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed