Skip to content

CVE-2026-12958

CVE

Threat entity extracted from intelligence sources

Frequency
8
occurrences
First Seen
June 26, 2026
Last Seen
July 10, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A high-severity vulnerability (CVE-2026-12957) in Amazon Q Developer for Visual Studio Code allowed attackers to execute arbitrary code and steal AWS credentials by automatically loading malicious MCP server configurations from cloned repositories. Discovered by Wiz Research, the flaw permits silent...

A vulnerability named GhostApproval has been discovered in six major AI coding assistants, including Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, and Windsurf. This flaw allows malicious repositories to trick AI agents into accessing files outside their designated...

Public Exploits

Checking GitHub for proof-of-concept code…