Skip to content

CVE-2026-14540

CVE

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
October 5, 2026
Last Seen
October 5, 2026
API
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

Independent researcher Syed Anas Mohiuddin disclosed a server-side request forgery (SSRF) vulnerability affecting Model Context Protocol (MCP) servers at five organizations, including Google and JPMorgan Chase. The flaw arises from unsafe handling of upstream data and a structural gap in MCP server...

Public Exploits

Checking GitHub for proof-of-concept code…