Sooperset
31 CVEs tracked since 2026. Since Sep 2026, none of them reached CISA KEV.
Sooperset CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2026-09 | 31 | 0 |
Products
The products that kept showing up in Sooperset's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Sooperset.
- CVE-2026-77246MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path7.4
- CVE-2026-77248MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport8.6
- CVE-2026-77256MCP Atlassian: OAuth refresh-token backup file is world-readable under default Unix umask—
- CVE-2026-77249MCP Atlassian: Incomplete fix for CVE-2026-27826: redirect-based SSRF via unhooked requests session in Jira user-permission lookup5.3
- CVE-2026-77259MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials7.7
- CVE-2026-77268MCP Atlassian: Insecure File Permissions on OAuth Token Storage5.5
- CVE-2026-77247MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters—
- CVE-2026-77272MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler5.4
- CVE-2026-77269MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete fix for CVE-2026-27825)6.5
- CVE-2026-77266MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call6.5
- CVE-2026-77255MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue8.6
- CVE-2026-77262MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of CVE-2026-27825)8.6
- CVE-2026-77254MCP Atlassian: Unauthenticated HTTP MCP requests can use globally configured Jira and Confluence credentials9.1
- CVE-2026-77253MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files7.1
- CVE-2026-77257MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths—
The record
- Peak rank
- #41 in Sep 2026
- Busiest month shown
- Sep 2026, 31 CVEs
- Months with a KEV entry
- 0 since Sep 2026
- Monthly snapshots
- 1 since 2026