CVE-2026-59563

CVE-2026-59563 published: Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP client or agent to replay a token generated for one resource to affect another resource of the same typ...

View full NVD advisory → ← Back to CVE watch