Critical RCE vulnerability in Windows DNS Server with CVSS 9.8. An unauthenticated attacker can send a specially crafted packet to the DNS service and execute code on the target system with no user interaction required. Part of record-breaking September 2026 Patch Tuesday.
Apply September 2026 patches to all DNS servers immediately. Restrict DNS service access to trusted sources using firewall rules. Implement DNS query monitoring and rate limiting. Consider implementing DNS RPZ for additional protection.
Source: MSRC • Published: 2026-09-08
Authentication bypass vulnerability using alternate path or channel in Citrix NetScaler actively exploited in the wild. Added to CISA KEV catalog September 9, 2026, indicating confirmed active exploitation.
Apply Citrix security updates immediately to all NetScaler appliances. Review authentication logs for bypass attempts. Implement multi-factor authentication where possible. Restrict NetScaler management interface access to trusted networks only. Monitor for suspicious authentication patterns.
Source: CISA • Published: 2026-09-09
Indirect prompt injection vulnerability in Kong Konnect MCP server drives unintended API requests through confused deputy attack pattern. Attackers can manipulate MCP server to make unauthorized API calls on behalf of authenticated clients.
Update Kong Konnect MCP server to patched version. Implement strict input validation and output sanitization for all MCP interactions. Apply confused deputy attack mitigations including request validation and authorization checks for all API calls.
Source: OX Security • Published: 2026-04-01
Unsanitized shell invocation vulnerability in iOS-simulator-mcp via tool arguments. Malicious arguments passed through MCP protocol can result in arbitrary command execution on the host system running the simulator.
Update iOS-simulator-mcp to patched version. Implement strict input sanitization for all tool arguments. Use parameterized commands instead of shell invocation. Restrict MCP server execution permissions and implement sandboxing.
Source: OX Security • Published: 2026-04-01
Content-injection script gadgets vulnerability in 5ire desktop MCP client via compromised MCP servers. Malicious MCP servers can inject script gadgets that execute in the client context, potentially leading to code execution or data exfiltration.
Update 5ire desktop MCP client to patched version. Implement Content Security Policy for all MCP server responses. Sanitize all content received from MCP servers before rendering. Use sandboxed rendering contexts for untrusted MCP content.
Source: OX Security • Published: 2026-04-01
CVE-2026-69730: Critical RCE vulnerability in Windows DNS Server with CVSS 9.8. An unauthenticated attacker can send a specially crafted packet to the DNS service and execute code on the target system with no user interaction required. Part of record-breaking September 2026 Patch Tuesday.