NSA Warns on MCP Security Gaps — and Three SDK CVEs Prove the Point

identity access free stock image for MCPwatch editorial use

The NSA AISC published the first government cybersecurity guidance on MCP, identifying inverted trust, unsigned tool descriptions, and missing authentication as structural gaps. Three CVEs in the official MCP SDKs — wildcard CORS in Java, JSON key smuggling in Go, and DNS rebinding before v0.25 — prove these are not theoretical risks.

MCP Attacks Hit Developer IDEs: Amazon Q Flaw and Agentjacking

server rack free stock image for MCPwatch editorial use

Wiz discovered CVE-2026-12957 in Amazon Q Developer (CVSS 8.5): opening a repo auto-executes MCP configs, handing cloud credentials to attackers. The same week, Tenet Security disclosed Agentjacking — an 85% success rate attack class using fake Sentry errors to hijack AI coding agents via MCP. Combined with new CVEs in chrome-devtools-mcp and OpenClaw, the developer-tool attack surface for MCP is widening fast.