MCP Servers Are the New Shadow IT for AI

2026-03-20T08:51:54Z2c9fb17f2451bbccbb4375bef46a8bfbe3e2e4463bf5df869b7ca6935135aff0
AppArmorCISA CVIECVE-2026-3888CrackArmorCyber Essentials PlusLPEMCP serversMicrosoft Patch Tuesday March 2026Qualys TotalAIUbuntu 24.04cloud compromisecompliancecontainer escapecredential misusegeopolitical threatskernel patchinglocal privilege escalationpatch managementshadow ITsnap-confinesupply chain discoverysystemd-tmpfilesvulnerability intelligence

What happened

Qualys published multiple product and threat-research posts in March 2026. Most significant are two local-privilege-escalation (LPE) research findings: CVE-2026-3888 — a snap-confine/systemd-tmpfiles interaction that allows unprivileged local attackers to escalate to root on default Ubuntu Desktop 24.04+ installations — and “CrackArmor,” a set of confused-deputy AppArmor vulnerabilities that enable privilege escalation, container isolation breaks, and kernel bypasses (affecting millions; Qualys recommends immediate kernel patching). Other updates include Qualys TotalAI capabilities to discover

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
qualys_blog
Record identifier
2c9fb17f2451bbccbb4375bef46a8bfbe3e2e4463bf5df869b7ca6935135aff0
Enrichment time
2026-03-20T08:51:54Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.