At A Glance
- Nearly 480 new network-exploitable Common Vulnerabilities and Exposures (CVEs) were published September 25 through October 1, 2026.
- 68 cleared our severity bar (Common Vulnerability Scoring System, or CVSS, 8.6+), including 6 rated a perfect 10.0.
- The featured vulnerability is CVE-2026-101065. The documented Docker quickstart for Obot, an open-source AI agent and MCP platform, runs on every network interface with authentication disabled.
- Five of the week’s six 10.0 scores were in router and access-point firmware.
- The common thread this week: security controls that need to be manually turned on in order to work.
Obot is an open-source platform for running AI agents and the Model Context Protocol (MCP) servers those agents use to reach tools and data. Its README documents a one-line Docker quickstart, which is the command most people copy on day one. According to CVE-2026-101065, that command starts the container listening on 0.0.0.0:8080, meaning every network interface on the host, with authentication disabled by default.
Defaults like that one showed up all week. A container deployment tool skipped its webhook check whenever no secret was configured. A Spring Boot starter project shipped with a master login code seeded into its default database. In each case the protection existed in the code but depended on a setting a fresh install doesn’t have. Each of these has a public advisory, and several already have fixed releases. The harder problem is the time between a fix becoming available and every running copy picking it up. The network can reach those copies for that whole stretch.
Vulnerabilities By The Numbers
From September 25 through October 1, 2026, nearly 480 new network-exploitable CVEs were published. 68 cleared our severity bar (CVSS 8.6+), including 6 rated a perfect 10.0. Running tally for the series: [X] critical/high-severity network CVEs tracked across [N] editions.
Four clusters stood out:
- CVE-2026-53988 (10.0, CRITICAL): Dockhand, which manages and redeploys container stacks, exposes git webhook endpoints that let an unauthenticated request trigger arbitrary stack redeployments. The guard that should verify the webhook secret mishandles a null value. As a result, a deployment with no configured secret accepts the request. Fixed in Dockhand 1.0.40.
- Router and access-point firmware (CVE-2026-101000, CVE-2026-101077, CVE-2026-101076, CVE-2026-101072, CVE-2026-102240, all 10.0, CRITICAL): Netcore’s NBR100V2, NR289-GE, and NAP930 devices accounted for five perfect scores. The flaws include missing authentication in a request handler and OS command injection through CGI parameters such as an NTP server field. D-Link DIR-895L (CVE-2026-100740, 9.9) and FAST FAC1200R (CVE-2026-101037, CVE-2026-101038, 9.9) added memory-corruption flaws in network-facing protocol parsers.
- AI agent and inference infrastructure (CVE-2026-103395, 9.8; CVE-2026-102911, 9.9): LightLLM visual_only deployments expose an unauthenticated RPyC service with pickle deserialization enabled, so anyone who can reach that port can hand it objects to deserialize. In pi-llm-wiki, the url argument of an MCP tool allowed OS command injection. The OpenClaw maintainers also shipped fixes for nine 8.8-rated authorization issues. In each one, owner-only controls such as plugin installs, MCP configuration changes, and shell-execution approval were reachable by non-owner channel participants.
- Industrial and building systems (CVE-2025-41753, 9.8; CVE-2026-18782, 9.8): A BACnet implementation treats the name of a dynamically created File Object as a file path, which lets an unauthenticated remote attacker traverse outside the intended directory. In Trex MES, SQL injection can lead to command-line execution. BACnet runs building automation and manufacturing execution systems run factory floors. In both environments, patches usually wait for scheduled downtime.
Every one of these has a published advisory. Each running instance stays reachable from the network until someone updates it. For firmware and factory systems, that update often waits weeks or months.
No Login Required: This Edition’s Most Dangerous Vulnerability
The standout is CVE-2026-101065 (9.8, CRITICAL) in Obot. The Docker quickstart in the README binds the container to 0.0.0.0:8080 with authentication disabled by default. Binding to 0.0.0.0 tells the operating system to accept connections on every interface the host has. That includes localhost, the office LAN, a VPN adapter, and, on a cloud VM, its public IP address. Anyone who can route a packet to port 8080 reaches the platform without a login screen.
An exposed MCP platform carries more weight than most exposed web apps. Its job is to hold the connections between AI agents and the tools those agents act on: source repositories, ticketing systems, databases, cloud APIs. That makes it a broker for credentials and permissions that belong to other systems. Depending on what’s been connected, reaching an unauthenticated Obot instance is a starting point for everything its MCP servers can touch.
The realistic way this gets exposed is through an evaluation. An engineer spins up Obot on a cloud instance or shared dev server to test an agent workflow and runs the documented command. They connect a few real MCP servers to see whether it works, then move on to the next priority while the pilot keeps running. Every step in that sequence follows the documented path.
Two related Obot advisories this week both have fixed releases:
- CVE-2026-101084 (9.6): In versions before v0.21.1, Access Control Rules weren’t enforced on the /mcp-connect endpoint. Any authenticated user who knew a restricted MCP server’s ID could connect to it.
- CVE-2026-101062 (8.8): In versions through v0.22.1 with authentication turned on, OAuth dynamic client registration accepted unauthenticated requests with no restriction on redirect URIs. That opens the door to registering a client that sends authorization codes to a destination an attacker controls.
Read together, the three advisories trace each layer an operator adds. First, authentication is off by default. Next, authentication is on, but one endpoint skips its authorization check. Last, authentication is on, but a registration endpoint is left open. Each fix closes one gap inside the application.
The contrast with the rest of the week is useful. The Netcore and FAST flaws above are code defects in how input gets parsed. Obot’s quickstart code behaves exactly as written, and its exposure comes from where it listens. Dockhand’s null-secret guard is the closest relative this week. Obot only enforces login when the OBOT_SERVER_ENABLE_AUTHENTICATION environment variable is set, and Dockhand only checks webhooks when a secret is configured, so an install that skips either step serves requests from anyone who can reach it.
How Identity-First Reachability Closes This Gap
Identity-First Reachabilityโข moves the decision about who can connect out of each application’s settings and into the network itself. With NetFoundry, a service like Obot is published as a service on the NetFoundry overlay network. The host makes only outbound connections to the NetFoundry fabric, and its inbound firewall can deny everything. Only identities with a policy granting access to that specific service can open a connection to it, so every connection requires a verified identity and an explicit policy decision first.
Here’s how that applies to this week’s three Obot advisories:
- CVE-2026-101065 (the 0.0.0.0 bind): The bind address stops mattering, because no inbound path to port 8080 exists for an unenrolled device to use.
- CVE-2026-101084 (the restricted-server bypass): If each restricted MCP server is published as its own NetFoundry service, access is enforced by identity policy. Knowing a server ID grants nothing on its own.
- CVE-2026-101062 (open client registration): The OAuth registration endpoint is reachable only by identities already authorized to reach Obot, which takes anonymous client registration off the table.
You should still apply every one of these fixes. Identity-First Reachability shrinks the exposure window around them. An unpatched instance that no unauthorized identity can reach gives an attacker nowhere to send a request.
Don’t Be the Next Reachability Watch Headline
Nearly 480 CVEs in one week is more than any team can patch on schedule, and this week shows why patching alone leaves a gap. A documented quickstart, a webhook guard waiting on a secret, and a login code seeded into a default database were each reachable from the network the day they shipped.
The CVEs that matter most are the ones that move onto CISA’s Known Exploited Vulnerabilities (KEV) catalog, which lists flaws confirmed exploited in the wild. That move can happen faster than a maintenance window opens. NetFoundry, the company behind the open-source OpenZiti project, builds connectivity that keeps AI agents, MCP servers, and the systems they touch unreachable until a verified identity with an explicit policy asks to connect.
See how NetFoundry Vulnerability Cloaking makes unpatched systems unreachable before a CVE ever becomes a KEV. See How It Works โ
Frequently Asked Questions
What is MCP, and why are MCP platforms a high-value target?
Model Context Protocol (MCP) is an open standard that lets AI agents connect to external tools and data. An MCP platform manages many of those connections at once, which gives it access to every system behind them. At NetFoundry, we treat MCP servers and platforms as privileged services, reachable only by verified identities with an explicit policy, because an exposed MCP platform hands its connections to whoever reaches it.
What does it mean when a service binds to 0.0.0.0?
Binding a service to 0.0.0.0 tells it to accept connections on every network interface its host has, and on a cloud server that includes the public IP address. NetFoundry removes that exposure by letting the host close inbound access entirely, so the service only accepts connections that arrive through an identity-verified, policy-approved path.
What’s the difference between a CVE and a KEV?
A CVE (Common Vulnerabilities and Exposures) entry is a public record of a disclosed security flaw. A KEV is a flaw listed in the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities catalog, which means attackers have been confirmed using it. At NetFoundry, we track both because most CVEs never get exploited, and the ones that do often reach the KEV list before many organizations have patched them.
Why does NetFoundry use a CVSS 8.6+ floor?
The Common Vulnerability Scoring System (CVSS) rates security flaws from 0 to 10, and hundreds of network-exploitable CVEs are published every week, most of which are never exploited in practice. NetFoundry tracks flaws scoring 8.6 or higher to isolate the ones that combine high severity with network exploitability. For those flaws, reaching the service is the main thing an attacker needs.
How does Identity-First Reachability prevent this class of attack?
Identity-First Reachability is a security model in which every connection requires a verified identity and an explicit access policy before a service becomes reachable on the network. NetFoundry applies it so that a vulnerable or misconfigured service, such as an AI platform left with authentication off, can’t be reached by anyone without that identity and policy, whether or not a patch has been applied. Think of a building with no street entrance: visitors come in only through a checked door, so an unlocked office inside isn’t exposed to passersby.
