CVE-2026-11624 - Vulnerability Details

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
June 13, 2026
Last Seen
June 14, 2026

CVE-2026-11624 is a vulnerability tracked by ThreatCluster, appearing in 1 threat cluster built from 3 intelligence report mentions.

CVE-2026-11624 is a vulnerability tracked across 1 threat cluster and 3 intelligence report mentions on ThreatCluster. First observed June 13, 2026; most recent activity June 14, 2026.

Related Threat Clusters

  • Critical CVE-2026-11624 Vulnerability in Model Context Protocol

    CVE-2026-11624, published on June 13, 2026, exposes the Model Context Protocol to DNS rebinding attacks due to improper validation of the 'Origin' header. This vulnerability allows unauthenticated attackers to bypass…

    3 articles · Updated June 14, 2026

Recent Intelligence Reports

  • CVE-2026-11624 INCIBE-CERT - Vulnerabilities RSS / 15h The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming connections to prevent DNS rebinding attacks. If either flag is set to "*", the server will output a startup warning about potential vulnerabilities. — www.incibe.es · June 14, 2026
  • CVE-2026-11624 Newest CVEs from Tenable / 9h Critical Severity Description The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming connections to prevent DNS rebinding attacks. Prior to the v0.25.0 release, users had no way to validate the origin's host. In v0.25.0, a new "--allowed-hosts" flag was introduced alongside the existing "--allowed-origins" flag, enabling users to specify permitted hosts at server startup. Both flags default t — www.tenable.com · June 14, 2026
  • CVE-2026-11624 - Exploits & Severity — Feedly · June 13, 2026

Frequently asked questions

What is CVE-2026-11624?

CVE-2026-11624 is a vulnerability tracked by ThreatCluster, appearing in 1 threat cluster built from 3 intelligence report mentions.

Is CVE-2026-11624 still active?

The most recent intelligence report mentioning CVE-2026-11624 on ThreatCluster is dated June 14, 2026. Activity was first observed June 13, 2026, giving a tracked span from then to June 14, 2026.

What is CVE-2026-11624 associated with?

Across ThreatCluster reporting, CVE-2026-11624 most frequently co-occurs with DNS Rebinding, Man-in-the-Middle, CWE-200 - Exposure of Sensitive Information, CWE-287 - Improper Authentication, Model Context Protocol DNS Rebinding Vulnerability.

What are the latest developments involving CVE-2026-11624?

The most significant recent cluster is “Critical CVE-2026-11624 Vulnerability in Model Context Protocol” (3 articles · Updated June 14, 2026). CVE-2026-11624 appears across 1 threat cluster in total, listed above with sources.

How much reporting does ThreatCluster have on CVE-2026-11624?

CVE-2026-11624 appears in 3 intelligence report mentions across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown