Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Gemini MCP Tool 0-day Vulnerability Allows Remote Attackers to Execute Arbitrary Code

Gemini MCP Tool 0-day Vulnerability Allows Remote Attackers to Execute Arbitrary Code

Posted on January 28, 2026January 28, 2026 By CWS

A important zero‑day vulnerability in Gemini MCP Device exposes customers to distant code execution (RCE) assaults with none authentication.

Tracked as ZDI‑26‑021 / ZDI‑CAN‑27783 and assigned CVE‑2026‑0755, the flaw carries a most CVSS v3.1 rating of 9.8, reflecting its ease of exploitation and extreme affect.

In response to a brand new advisory from Development Micro’s Zero Day Initiative (ZDI), the difficulty impacts the open‑supply gemini-mcp-tool, a utility designed to combine Gemini fashions with Mannequin Context Protocol (MCP) companies.

Vulnerability Overview

Each the seller and product are listed as Gemini MCP Device / gemini-mcp-tool within the advisory. On the core of the vulnerability is the improper dealing with of person‑equipped enter within the execAsync methodology.

This operate passes enter straight right into a system name with out satisfactory validation or sanitization.

A distant attacker can exploit this command injection weak point to execute arbitrary code on the underlying system, working with the privileges of the service account.

FieldInformationCVE IDCVE-2026-07550‑Day Namegemini-mcp-tool execAsync Command Injection RCE VulnerabilityCVSS v3.1 Score9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)Affected Productgemini-mcp-toolImpactRemote, unauthenticated arbitrary code execution

As a result of the assault vector is community‑based mostly and requires no prior authentication or person interplay, web‑uncovered or shared environments are at notably excessive threat.

The vulnerability was initially reported to the seller on July 25, 2025, through a 3rd‑social gathering platform.

ZDI adopted up for updates in November 2025 and, after receiving no enough response, knowledgeable the seller on December 14, 2025 of its intention to publish the case as a zero‑day advisory.

The coordinated public disclosure and advisory replace occurred on January 9, 2026.

On the time of publication, no official patch or replace has been documented. Because of this, mitigation choices are restricted.

ZDI recommends strictly proscribing entry to the Gemini MCP Device by making certain it isn’t straight uncovered to the web and limiting interplay to trusted networks and customers.

Directors also needs to monitor methods working gemini-mcp-tool for suspicious course of execution and strange outbound connections that would point out profitable exploitation.

Comply with us on Google Information, LinkedIn, and X for each day cybersecurity updates. Contact us to function your tales.

Cyber Security News Tags:0Day, Arbitrary, Attackers, Code, Execute, Gemini, MCP, Remote, Tool, Vulnerability

Post navigation

Previous Post: Russian ELECTRUM Tied to December 2025 Cyber Attack on Polish Power Grid
Next Post: TP-Link Archer Vulnerability Let Attackers Take Control Over the Router

Related Posts

Threat Actors Leveraging Dynamic DNS Providers to Use for Malicious Purposes Threat Actors Leveraging Dynamic DNS Providers to Use for Malicious Purposes Cyber Security News
Hackers Weaponizing SVG Files to Stealthily Deliver Malicious Payloads Hackers Weaponizing SVG Files to Stealthily Deliver Malicious Payloads Cyber Security News
Critical WatchGuard Flaws Allow System Control on Windows Critical WatchGuard Flaws Allow System Control on Windows Cyber Security News
OpenAI Launches  ChatGPT Go Plan with Unlimited Access to GPT-5 OpenAI Launches $4 ChatGPT Go Plan with Unlimited Access to GPT-5 Cyber Security News
Threat Actors Manipulating LLMs for Automated Vulnerability Exploitation Threat Actors Manipulating LLMs for Automated Vulnerability Exploitation Cyber Security News
What Are The Takeaways from The Scattered Lapsus $Hunters Statement? What Are The Takeaways from The Scattered Lapsus $Hunters Statement? Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Chrome 151 Update Fixes Five Critical Security Flaws
  • SharePoint Exploit Emerges Following PoC Release
  • 737 VPN Extensions Expose Users to Proxy Risks
  • Fake CCleaner Download Spreads GhostDesk Spyware
  • Mindgard Secures $30M to Enhance AI Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Chrome 151 Update Fixes Five Critical Security Flaws
  • SharePoint Exploit Emerges Following PoC Release
  • 737 VPN Extensions Expose Users to Proxy Risks
  • Fake CCleaner Download Spreads GhostDesk Spyware
  • Mindgard Secures $30M to Enhance AI Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark