<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://mcp-news.com/news/cloudflare-publishes-2026-07-28-engineering-post</loc>
    <news:news>
      <news:publication>
        <news:name>MCP News</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-06</news:publication_date>
      <news:title>Cloudflare publishes an engineering post on the 2026-07-28 revision and says createMcpHandler has graduated into the official TypeScript SDK</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://mcp-news.com/news/missionsquad-mcp-api-two-cves</loc>
    <news:news>
      <news:publication>
        <news:name>MCP News</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-06</news:publication_date>
      <news:title>Two CVEs published for MissionSquad mcp-api, a command injection and an SSRF, each fixed in a point release</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://mcp-news.com/news/aws-documentdb-mcp-server-read-only-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>MCP News</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-05</news:publication_date>
      <news:title>AWS Labs DocumentDB MCP Server read-only mode bypassed via write-capable aggregation stages</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://mcp-news.com/news/csharp-sdk-2-1-0-subscriptions-listen-handler</loc>
    <news:news>
      <news:publication>
        <news:name>MCP News</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-05</news:publication_date>
      <news:title>C# SDK v2.1.0 adds a public subscriptions/listen server handler and HTTP transport fallback fixes</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://mcp-news.com/news/langflow-oss-mcp-cves-reach-nvd</loc>
    <news:news>
      <news:publication>
        <news:name>MCP News</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-05</news:publication_date>
      <news:title>Five MCP-related IBM Langflow OSS CVEs published to NVD, including an authentication bypass in the MCP composer endpoint</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://mcp-news.com/news/mcp-inspector-2-1-0-sep-2243-header-mirroring</loc>
    <news:news>
      <news:publication>
        <news:name>MCP News</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-05</news:publication_date>
      <news:title>MCP Inspector 2.1.0 mirrors SEP-2243 x-mcp-header arguments to Mcp-Param-* on tools/call</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://mcp-news.com/news/mongodb-mcp-server-2-0-0-removes-session-state</loc>
    <news:news>
      <news:publication>
        <news:name>MCP News</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-04</news:publication_date>
      <news:title>MongoDB&apos;s mongodb-mcp-server 2.0.0 removes session state and requires explicit connection ids</news:title>
    </news:news>
  </url>
</urlset>