Thirty-three further MCP security records landed between September 3 and 15; here is each one
Between 2026-09-03 and 2026-09-15, thirty-three more MCP security records were published or entered a GitHub/NVD listing outside the AWS Labs, IBM ContextForge, Langflow, firecrawl-mcp-server, and CKAN MCP Server stories already covered this cycle. They range from a same-day critical authorization bypass in Casdoor's /api/mcp endpoint, unpatched as of this fetch, to a coordinated VulnCheck batch of path-traversal and injection findings against several single-purpose stdio servers published within about thirty minutes on 2026-09-04. A third Kotlin SDK advisory, a ninth MCPHub CVE, a fifth SiYuan record, and a second three-CVE PraisonAI batch extend stories already running. Severity below is stated exactly as each discloser framed it.