Threat · curated 8 Aug 2026
CYBER ADVISORY
First reported ca.gov
Coverage timeline
Single-source advisory — first reported, latest, and curated coincide.
Why it matters
CVE-2026-61459 shows how an AI-agent-to-infrastructure bridge (an MCP server) can be weaponized to hijack an entire Kubernetes cluster, making prompt patching to 3.9.0 essential for any environment exposing MCP tooling.
Cal-CSIC issued an advisory for CVE-2026-61459, a critical (CVSS 9.8) argument injection vulnerability in MCP Server Kubernetes, a component that bridges AI assistants and automated tools to Kubernetes clusters. If the MCP server is externally exposed, an attacker can send crafted requests to steal credentials, bypass security checks, inject malicious arguments, and compromise the entire cluster with potential lateral movement across clusters. A fix is available in version 3.9.0.