A critical vulnerability, CVE-2026-52830(CVSS 9.4), has been identified in fast-mcp-telegram, an MCP (Model Context Protocol) server that enables Telegram integrations. The flaw affects all versions prior to 0.19.1 and allows unauthenticated remote attackers to bypass session authentication through improper validation of HTTP Bearer tokens. Successful exploitation can provide unauthorized access to the default Telegram session, exposing sensitive information and enabling misuse of Telegram-connected MCP services. The vulnerability stems from the application's authentication logic, which generates a session file path directly from the supplied Bearer token without adequately sanitizing or normalizing user input. While the reserved session name "telegram" is explicitly blocked, the application does not properly prevent directory traversal sequences such as `../`. By crafting a malicious Bearer token that references the default legacy session file, an attacker can force the application to load an existing session and authenticate without valid credentials. Because the attack requires no prior authentication and can be executed remotely over HTTP, internet-facing deployments are particularly vulnerable. The flaw bypasses authentication controls rather than stealing credentials, making it highly effective against exposed MCP servers. Organizations using fast-mcp-telegram should immediately upgrade to version 0.19.1 or later, restrict external access to MCP services, monitor authentication logs for suspicious requests, and validate session file security to mitigate the risk of unauthorized access.
Researchers H0j3n and Aniq Fakhrul disclosed a proof-of-concept exploit named Certighost for CVE-2026-54121, an Active Directory Certificate Services (AD CS) vulnerability patched ...
At the core of an advanced malvertising attack scheme known as FakeAgent, SectopRAT was utilized by the cybercriminals in exploiting Anthropic’s Claude platform for the distribut...
Researchers at Group-IB have uncovered a previously undocumented cyber espionage campaign, tracked as JadeProx, targeting government, healthcare, and education organizations across...