Tools AI Risk Radar ai-incident-0001
Incident record
IBM's MCP Gateway carried four separate holes, all fixed now
- Severity
- High
- Status
- Patched
- Type
- Data Leak
- Target
- IBM ContextForge MCP Gateway
- Actor
- researcher
- CVE
- CVE-2026-18905
What happened
Four CVEs in one product: CVE-2026-18905 (DNS-rebinding information disclosure during tool invocation, fixed 1.0.7), CVE-2026-77822 (SSRF via DNS rebinding on the A2A agent-invocation endpoint, fixed 1.0.9), CVE-2026-18486 (improper jq-filter validation exposing credentials and enabling privilege escalation, fixed 1.0.8, with IBM advising rotation of JWT, auth, database and Redis secrets), and CVE-2026-18489 (the Translate utility leaking data across sessions). IBM's bulletins are dated 2 September.
Sources
- IBM security bulletin 7286053www.ibm.com/support/pages/node/7286053
- IBM security bulletin 7286052www.ibm.com/support/pages/node/7286052
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026