MCP Servers Are the New Shadow IT for AI
2026-03-20T08:51:54Z•2c9fb17f2451bbccbb4375bef46a8bfbe3e2e4463bf5df869b7ca6935135aff0
AppArmorCISA CVIECVE-2026-3888CrackArmorCyber Essentials PlusLPEMCP serversMicrosoft Patch Tuesday March 2026Qualys TotalAIUbuntu 24.04cloud compromisecompliancecontainer escapecredential misusegeopolitical threatskernel patchinglocal privilege escalationpatch managementshadow ITsnap-confinesupply chain discoverysystemd-tmpfilesvulnerability intelligence
What happened
Qualys published multiple product and threat-research posts in March 2026. Most significant are two local-privilege-escalation (LPE) research findings: CVE-2026-3888 — a snap-confine/systemd-tmpfiles interaction that allows unprivileged local attackers to escalate to root on default Ubuntu Desktop 24.04+ installations — and “CrackArmor,” a set of confused-deputy AppArmor vulnerabilities that enable privilege escalation, container isolation breaks, and kernel bypasses (affecting millions; Qualys recommends immediate kernel patching). Other updates include Qualys TotalAI capabilities to discover
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- qualys_blog
- Record identifier
- 2c9fb17f2451bbccbb4375bef46a8bfbe3e2e4463bf5df869b7ca6935135aff0
- Enrichment time
- 2026-03-20T08:51:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.