CVE-2026-11624 is a vulnerability tracked by ThreatCluster, appearing in 1 threat cluster built from 3 intelligence report mentions.
CVE-2026-11624 is a vulnerability tracked across 1 threat cluster and 3 intelligence report mentions on ThreatCluster. First observed June 13, 2026; most recent activity June 14, 2026.
CVE-2026-11624, published on June 13, 2026, exposes the Model Context Protocol to DNS rebinding attacks due to improper validation of the 'Origin' header. This vulnerability allows unauthenticated attackers to bypass…
CVE-2026-11624 is a vulnerability tracked by ThreatCluster, appearing in 1 threat cluster built from 3 intelligence report mentions.
The most recent intelligence report mentioning CVE-2026-11624 on ThreatCluster is dated June 14, 2026. Activity was first observed June 13, 2026, giving a tracked span from then to June 14, 2026.
Across ThreatCluster reporting, CVE-2026-11624 most frequently co-occurs with DNS Rebinding, Man-in-the-Middle, CWE-200 - Exposure of Sensitive Information, CWE-287 - Improper Authentication, Model Context Protocol DNS Rebinding Vulnerability.
The most significant recent cluster is “Critical CVE-2026-11624 Vulnerability in Model Context Protocol” (3 articles · Updated June 14, 2026). CVE-2026-11624 appears across 1 threat cluster in total, listed above with sources.
CVE-2026-11624 appears in 3 intelligence report mentions across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.