Vulnerability  ·  2026-08-14

Microsoft UFO agentic automation framework exposes unauthenticated MCP services on mobile automation ports

VulnerabilityHigh impactGlobal
Microsoft's UFO open-source framework for intelligent automation across devices exposes create_mobile_data_collection_server and create_mobile_action_server functions (ufo/client/mcp/http_servers/mobile_mcp_server.py) that stand up Streamable HTTP MCP services on TCP ports 8020/8021 without authentication (CVE-2026-73296, CVSS 9.4, Critical), prior to version 3.0.8.
UFO is an MCP-based agentic automation framework from Microsoft; unauthenticated MCP servers bound to network-reachable ports allow any network-adjacent attacker to invoke device-automation tool calls (including mobile action execution) without credentials, a direct agent-tool-execution compromise path.
Attacker connects directly to unauthenticated MCP service on TCP port 8020/8021 and invokes mobile data-collection or mobile-action tool calls without any credential check
Microsoft UFO < 3.0.8
Upgrade to UFO 3.0.8 or later
NVD - CVE-2026-73296GitHub commit fix
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →