CVE-2026-32625 - Vulnerability Details

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
June 3, 2026
Last Seen
June 3, 2026

CVE-2026-32625 is a vulnerability tracked across 2 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed June 3, 2026; most recent activity June 3, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • CVE-2026-32625 INCIBE-CERT - Vulnerabilities RSS / 7h Gravedad 3.1 (CVSS 3.1 Base Score) Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score) — www.incibe.es · June 3, 2026
  • CVE-2026-32625 Valters IT Hub / 2h The flaw resides in the Model Context Protocol (MCP) server integration, where the application resolves environment variable placeholders against the server's during Zod schema validation of user-supplied MCP server URLs. An authenticated attacker can craft a malicious MCP server configuration with a URL containing environment variable references (e.g., ). When the server validates this URL, it substitutes the placeholder with the actual environment variable va — www.valtersit.com · June 3, 2026
  • CVE-2026-32625 - Exploits & Severity — Feedly · June 3, 2026

CVSS v3.1 Breakdown