What is CVE-2026-73296?
CVE-2026-73296 is a vulnerability in Microsoft's UFO open-source automation framework. Before version 3.0.8, mobile MCP servers on TCP ports 8020 and 8021 are exposed without authentication. An attacker with network access can perform unauthorized actions or data collection via these Streamable HTTP MCP services, requiring an immediate update to version 3.0.8.
Azərbaycanca: CVE-2026-73296 Microsoft-un UFO açıq mənbəli avtomatlaşdırma çərçivəsində aşkarlanmış boşluqdur. 3.0.8 versiyasından əvvəl, mobil MCP serverləri heç bir autentifikasiya olmadan TCP port 8020 və 8021-də xidmətləri ifşa edir. Hücum şəbəkədən bu portlara birbaşa qoşularaq icazəsiz hərəkətlər və məlumat toplama əməliyyatları həyata keçirə bilər, dərhal 3.0.8 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306; shared vendor: Microsoft
FAQ2
Which Microsoft product is affected by CVE-2026-73296?
CVE-2026-73296 affects Microsoft's UFO open-source automation framework.
To which version should the UFO framework be updated to mitigate this vulnerability?
An immediate update to version 3.0.8 is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.