
CVE-2026-27825: Critical Unauthenticated RCE and SSRF in mcp-atlassian
On 24 February 2026, sooperset, the mcp-atlassian project maintainer, released fixes for a critical vulnerability in mcp-atlassian, tracked as CVE-2026-27825. The flaw arises from missing directory confinement








