logo

Six MCP Security Incidents Every Security Leader Should Know | UpGuard

ID: 12a584e6-cc9b-5e98-af90-63c242d0d39a

STIX ID: report--12a584e6-cc9b-5e98-af90-63c242d0d39a

Feed Name: UpGuard Blog

Threat Score
88/100

Date Published: 2026-05-15

Date Updated: 2026-05-20

...
...

**Executive summary:** This report describes six documented MCP-targeted incidents—including supply-chain registry poisoning with a trojanized MCP server (SmartLoader/StealC), a critical OAuth RCE in mcp-remote (CVE-2025-6514) affecting a widely used adapter, multiple prompt-injection exfiltration cases (GitHub issues, support tickets), package impersonation that silently BCC'd emails, and a destructive VS Code extension prompt-injection—highlighting systemic gaps (implicit agent trust, lack of registry/network visibility, and developer-focused attack surface) and advising visibility and permission controls for mid-market teams.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.