Skip to content

CVE-2026-91988

CVE

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
September 16, 2026
Last Seen
September 19, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

CVE-2026-91988 is a critical remote code execution vulnerability affecting atomic-agents-stack versions prior to 1.1.0. The flaw allows attackers to exploit cleartext HTTP connections in the HTTP MCP server-registry backend factory. By intercepting and modifying catalog responses, attackers can inje...

Public Exploits

Checking GitHub for proof-of-concept code…