Gemini MCP Tool 0-Day Vulnerability Exposes Systems to Remote Code Execution
ID: 25a7c107-1355-5736-aeb4-f0028b90f285
STIX ID: report--25a7c107-1355-5736-aeb4-f0028b90f285
Feed Name: GBHackers
Threat Score
A critical zero-day (CVE-2026-0755) has been disclosed in gemini-mcp-tool that allows unauthenticated, network-accessible command injection and arbitrary code execution (CVSS 9.8). Disclosed by Trend Micro ZDI (ZDI-26-021 / ZDI-CAN-27783) with no vendor patch available at time of publication; immediate mitigations recommended include network isolation, strict access controls, and limiting exposure until remediation is provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
