Systemic command execution vulnerability in Anthropic's official MCP SDKs (Python, TypeScript, Java, Rust) affecting 200,000 instances and 150M+ package downloads. STDIO transport executes passed commands without validation. 43% of MCP servers vulnerable to command injection, 82% to path traversal, 36.7% to SSRF.
Implement MCP server allowlisting immediately. Audit all MCP configurations for command injection risks. Deploy monitoring for anomalous MCP traffic. Disable untrusted MCP server connections and require authentication.
Source: GTIG • Published: 2026-04-15
ShinyHunters hacking group claims breach of American Tower Corporation exfiltrating 5.2+ million records. Same group responsible for Aura data breach and March 2026 Salesforce Aura Campaign affecting 300-400 organizations since September 2025.
Organizations using Salesforce Experience Cloud must audit guest user permissions immediately. Review API endpoint configurations. Implement monitoring for unusual data access patterns. Conduct security assessment of customer-facing portals.
Source: BleepingComputer • Published: 2026-09-03
MCP-SYSTEMIC-DESIGN-FLAW-2026: Systemic command execution vulnerability in Anthropic's official MCP SDKs (Python, TypeScript, Java, Rust) affecting 200,000 instances and 150M+ package downloads. STDIO transport executes passed commands without validation. 43% of MCP servers vulnerable to command injection, 82% to path traversal, 36.7% to SSRF.