logo

Gemini MCP Tool 0-Day Vulnerability Exposes Systems to Remote Code Execution

ID: 25a7c107-1355-5736-aeb4-f0028b90f285

STIX ID: report--25a7c107-1355-5736-aeb4-f0028b90f285

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-01-28

Date Updated: 2026-04-22

Author: Divya

...
...

A critical zero-day (CVE-2026-0755) has been disclosed in gemini-mcp-tool that allows unauthenticated, network-accessible command injection and arbitrary code execution (CVSS 9.8). Disclosed by Trend Micro ZDI (ZDI-26-021 / ZDI-CAN-27783) with no vendor patch available at time of publication; immediate mitigations recommended include network isolation, strict access controls, and limiting exposure until remediation is provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.