CVE Tools

Sooperset

31 CVEs tracked since 2026. Since Sep 2026, none of them reached CISA KEV.

Sooperset CVEs per month

Sep 2026 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Sooperset CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2026-09310

Products

The products that kept showing up in Sooperset's monthly top three, with their CVEs summed over those months.

  1. Mcp-atlassian311 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Sooperset.

  1. CVE-2026-77246MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path7.4
  2. CVE-2026-77248MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport8.6
  3. CVE-2026-77256MCP Atlassian: OAuth refresh-token backup file is world-readable under default Unix umask—
  4. CVE-2026-77249MCP Atlassian: Incomplete fix for CVE-2026-27826: redirect-based SSRF via unhooked requests session in Jira user-permission lookup5.3
  5. CVE-2026-77259MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials7.7
  6. CVE-2026-77268MCP Atlassian: Insecure File Permissions on OAuth Token Storage5.5
  7. CVE-2026-77247MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters—
  8. CVE-2026-77272MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler5.4
  9. CVE-2026-77269MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete fix for CVE-2026-27825)6.5
  10. CVE-2026-77266MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call6.5
  11. CVE-2026-77255MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue8.6
  12. CVE-2026-77262MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of CVE-2026-27825)8.6
  13. CVE-2026-77254MCP Atlassian: Unauthenticated HTTP MCP requests can use globally configured Jira and Confluence credentials9.1
  14. CVE-2026-77253MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files7.1
  15. CVE-2026-77257MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths—

The record

Peak rank
#41 in Sep 2026
Busiest month shown
Sep 2026, 31 CVEs
Months with a KEV entry
0 since Sep 2026
Monthly snapshots
1 since 2026
Sooperset's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store