Product
critical
advisory
Unauthenticated Remote Access and Credential Exposure in Telnyx MCP Server
2 TTPs 1 CVEThe Telnyx MCP server improperly bound its HTTP listener to all interfaces and failed to enforce authentication, allowing unauthenticated remote attackers to trigger tool dispatch and leak internal API credentials.
MCP server
2t
1c
high
advisory
Java-SDK DNS Rebinding Vulnerability in MCP Server
2 rules 2 TTPsA DNS rebinding vulnerability exists in java-sdk versions prior to 1.0.0, allowing an attacker to access a locally or network-private java-sdk MCP server via a victim's browser, potentially enabling unauthorized tool calls to the server.
Java SDK +1
dns-rebinding
java-sdk
mcp
cve-2026-35568
2r
2t