MCP security intelligence
Track the attack surface around agent tools.
Source-linked analysis of MCP vulnerabilities, incidents, and operator controls for people deciding what to investigate next.
Latest intelligence
New disclosures and incidents, ordered by publication time.

CVE-2026-49471: Serena MCP Dashboard DNS Rebinding Risk
CVE-2026-49471 affects Serena before 1.5.2: an unauthenticated local dashboard can enable DNS rebinding and agent memory poisoning.
Read analysis
CVE-2026-25536: Cross-Client Data Leak in MCP TypeScript SDK Affects Multi-Tenant Deployments
The official Model Context Protocol TypeScript SDK (@modelcontextprotocol/sdk) versions 1.10.0 through 1.25.3 contain a cross-client data leakage vulnerability tracked as CVE-2026-25536 (CVSS 7.1). The flaw ena
Read analysis
NSA Issues MCP Security Design Considerations: What the Government Advisory Means for Your AI Agent Stack
What Happened On May 20, 2026, the US National Security Agency’s Artificial Intelligence Security Center (AISC) published a Cybersecurity Information Sheet (CSI) titled “Model Context Protocol (MCP): Security D
Read analysis
Four CrewAI CVEs Chain Prompt Injection to Host RCE and SSRF (VU#221883)
What Happened On March 30, 2026, CERT/CC published VU#221883, disclosing four vulnerabilities in the CrewAI multi-agent framework. The cluster was reported by security researcher Yarden Porat of Cyata and spans
Read analysisThree ways in
Research the threat, apply a control, or follow the latest reporting.
Intelligence
MCP Watch
Combined CVE and incident coverage with sources and operator implications.
Browse intelligence →Implementation
Security products
Checklists, hardening kits, review workflows, and the offline Scanner + Report Pack.
Compare products →Editorial
Blog
All MCPwatch analysis in chronological order, seven reports per page.
Read the blog →Offline evidence workflow
MCPwatch Exposure Ledger
Match a customer-owned MCP inventory against a bounded source-linked feed, keep unknowns visible, invalidate stale decisions, and package replayable evidence without uploading private inventory.
Professional · $149
Complete internal review workflow
Linux x86_64, one purchasing organization, one-time purchase and 12 months of downloadable offline feed updates.
Review editions →Agency · $399
Authorized client engagements
The same correctness core plus tested multi-client isolation, portfolio freshness and client handoff.
Inspect public sample →