BLOG
What Shipped This Week: 25 New Connectors, 2 Breaking Changes, and a Gateway Security Pass, September 21, 2026
Biggest connector week yet across Conduit and the vendor-connector fleet: 25 new MCP integrations shipped, plus 2 breaking changes and a gateway-security hardening pass. Conduit is WYRE's MCP (Model Context Protocol) gateway: the layer every one of this week's releases plugs into.
Breaking changes
node-datto-rmm v2.0.0 renames ActivityLogsResponse.activityLogs, and nests QuickJobRequest's componentUid / variables under jobComponent. It also resolves the js-yaml CVE-2026-84375. External contribution: granthartley-brown.
timezest-mcp v3.0.0 lists every tool flatly instead of gating them behind navigate. timezest_navigate and timezest_back are removed (migration note included in the release).
New MCP connectors (25)
- AlertOps — incident/on-call management v1.0.0
- Alloy Navigator — ITSM/asset management v1.0.0
- Bitdefender GravityZone — 10 read-only endpoint-security tools v1.0.0
- Cisco Duo — read-only MFA/identity admin v1.0.0
- Cisco Umbrella — DNS security v1.0.0
- Cork — 23 read-only cyber-insurance tools v1.0.0
- Customer Thermometer — NPS/feedback surveys v1.0.0
- CyberQP — privileged access management v1.0.0
- Dicker Data — distributor integration v1.0.0
- DNSFilter — DNS security v1.0.0
- ESET PROTECT — endpoint security v1.0.0
- Gorelo — read-only PSA v1.0.0
- Island Browser — 4 read-only enterprise-browser security tools v1.0.0
- Keeper Secrets Manager — read-only multitenant bridge over Keeper's MCP server v1.0.0
- MSP360 — backup/DR v1.0.0
- Printix — print management v1.0.0
- PRTG — network monitoring v1.0.0
- RoboShadow — vulnerability/security scanning v1.0.0
- Slide — backup/DR v1.0.0
- Telivy — cyber-insurance scanning v1.0.0
- Teramind — 16 read-only insider-threat/employee-monitoring tools v1.0.0
- Time Doctor — time tracking v1.0.0
- UniFi — network management (Cloud Site Manager API) v1.0.0
- WatchGuard Cloud — network security v1.0.0
- Yeastar P-Series PBX — telephony management v1.0.0
Conduit platform
Conduit v1.90.0 registers CIPP's own first-party MCP server (cipp-official).
Conduit v1.89.0 registers Keeper Secrets Manager as a read-only, admin-tier catalog vendor.
Conduit v1.88.0 adds signed audit-log checkpoints, a trusted Entra tenant for gateway migration, and OAuth device-authorization grant with agent-subjected tokens.
Conduit v1.87.0 adds long-lived agent keys, so a service account can authenticate as itself.
Security
Gateway S2S auth (closes a confused-deputy gap between sibling sidecars) rolled out to axcient-mcp, mailprotector-mcp, and salesforce-mcp.
7 client libraries patched for js-yaml CVE-2026-84375: node-atera, node-crewhu, node-halopsa, node-immybot, node-it-glue, node-ninjaone, node-superops.
node-syncro bumped vitest (CVE-2026-84373) and js-yaml (CVE-2026-84375).