x64dbg MCP plugin shipped an unauthenticated debugger on every network interface (CVE-2026-107824)
x64dbg-MCP Server before 1.1 exposed every debugger tool over HTTP, unauthenticated, on all interfaces. CVE-2026-107824 scores 9.3; no exploitation.
· 6 min