View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Security Assessment Reveals Multiple Vulnerabilities

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Security Assessment Reveals Multiple Vulnerabilities in Internet-Facing MCP Servers
    A dynamic security assessment found numerous vulnerabilities in internet-facing MCP servers.

    • Applies to over 21,000 internet-facing Model Context Protocol (MCP) servers launched since Nov 2024
    • Assessment audited 414 production MCP servers, uncovering 68 vulnerabilities including SQL injection and SSRF
    • Attacks exploit cloud metadata services, prompt template injection, and path traversal via cursor manipulation
    • 91.8% of audited servers lack OAuth authentication and many expose shell execution without access controls
    • 41.6% of servers disappear within three days, indicating rapid deployment cycles without security review
      ๐Ÿ“Ž Coverage: arxiv.org ยท ๐Ÿ“„ Original: arxiv.org ยท ๐Ÿ‘ via arXiv cs.CR
  • Researchers demonstrate stealthy backdoor evading diffusion model semantic watermarks
    A stealthy backdoor method enables evasion of semantic watermarks in latent diffusion models.

    • Applies to Latent Diffusion Models (LDMs) using semantic watermarking for image protection
    • Targets watermark detection pipelines relying on neural networks, specifically VAE encoders
    • Uses GhostVAE to implant a backdoor with a universal trigger via power spectrum regularization
    • Achieves high evasion success (~94.6%) while preserving watermark detection on benign images (~94.4%)
    • Backdoor remains stealthy against 17 defenses across input, parameter, and latent spaces
      ๐Ÿ“Ž Coverage: arxiv.org ยท ๐Ÿ“„ Original: arxiv.org ยท ๐Ÿ‘ via arXiv cs.CR
  • Domain Decoupling Attack exploits DNS validation gap in CDN and shared hosting
    Researchers discovered a Domain Decoupling Attack exploiting DNS-based authorization gaps in shared hosting.

    • Applies to CDN and non-CDN shared hosting environments with shared edge IP addresses
    • Vulnerability arises from DNS-based authorization where allowed domain permissions apply to shared IPs
    • Attack resolves an allowed domain to gain permission for a shared IP, then connects using a hidden domain
    • Uses consistent TLS SNI and HTTP Host headers to evade detection and access other tenants
    • Measurements show high exposure rates: 95.8% overall, 99.26% for CDN domains, 92.75% for non-CDN domains
      ๐Ÿ“Ž Coverage: arxiv.org ยท ๐Ÿ“„ Original: arxiv.org ยท ๐Ÿ‘ via arXiv cs.CR

๐Ÿ”“ CVEs & KEV

  • CVE-2026-56846 โ€” CVSS 7.5 โ€” A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks eva...
  • CVE-2026-6837 โ€” CVSS 7.2 โ€” A post-authentication command injection vulnerability in the "export-cgi" CGI...
  • CVE-2026-8508 โ€” CVSS 6.5 โ€” An improper authentication vulnerability in the "social_login.cgi" CGI progra...
  • CVE-2026-18719 โ€” CVSS 6.3 โ€” cemtan sar2html Search sar2html.py sql injectionA vulnerability was detected ...
  • CVE-2026-58045 โ€” CVSS 6.2 โ€” A flaw in Node.js allows a spoofed TypedArray byteLength to trigger a rea...
  • CVE-2026-58042 โ€” CVSS 5.9 โ€” A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When ...
  • CVE-2026-18720 โ€” CVSS 5.3 โ€” kalcaddle kodbox msgWarning Plugin action improper authorizationA flaw has be...
  • CVE-2026-58041 โ€” CVSS 5.3 โ€” A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created th...
  • CVE-2026-17614 โ€” CVSS 4.4 โ€” Wildfly-core: path traversal on wildfly domain controllerA path traversal fla...
  • CVE-2026-58044 โ€” CVSS 3.7 โ€” A flaw in Node.js HTTP client can cause a request desynchronization for Node....
  • CVE-2026-56845 โ€” CVSS โ€” โ€” An unauthenticated path traversal (LFI) vulnerability exists under /custom-so...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check