MCP Security Flaws Mount as 200,000 Servers Face Exposure
A protocol that grew faster than its defenses
The Model Context Protocol (MCP) has become the default plumbing for connecting AI agents to tools and data. Researchers now warn that its security posture has not kept pace with its spread. Across vendor research, threat advisories, and government guidance, the picture is consistent. MCP deployments are multiplying, and a large share of them ship with weak or missing safeguards.
The adoption curve is steep. OpenAI formally adopted MCP in March 2025 and later brought it into ChatGPT apps. In December 2025, Anthropic donated the protocol to the Agentic AI Foundation under the Linux Foundation. 5 By mid-2026, more than 10,000 MCP servers were reportedly running in production, and the SDKs were being downloaded over 97 million times a month. 5 Salesforce alone reported 4.5 million MCP calls processed through its Headless 360 platform by late May. 5 One threat advisory says MCP now runs agent workflows at most Fortune 500 companies. 2
The vulnerability tally
UltraViolet's TIDE team counts more than 40 CVEs disclosed against MCP implementations between January and April 2026. These span Python, TypeScript, Java, and Rust SDKs and hit both reference servers and third-party tools. 2 Microsoft patched a high-severity flaw in its own MCP servers in its March 2026 release. 2
The most consequential disclosure may be a command-execution issue tied to the STDIO transport, which affects the official SDKs. OX Security estimated in April that roughly 200,000 deployments are exposed to it. 1 Some downstream projects have shipped fixes, such as LiteLLM's CVE-2026-30623. The core issue, however, reportedly remains unpatched because Anthropic characterized the behavior as expected. 1 UltraViolet cites a similar 200,000 figure from an April advisory covering ten additional high and critical CVEs. 2
Trend Micro's research shows how the risk extends into cloud environments. It flagged three vulnerabilities, each rated CVSS 9.8, that allow attackers to bypass security controls and run unauthorized commands. Two are in an aws-mcp-server project (CVE-2026-5058 and CVE-2026-5059), and one affects Microsoft. 3 The firm also found:
- An
execute_sqltool exposed on 70 hosts, effectively an open door to databases. - A "Graphiti Agent Memory" server on 39 hosts, which attackers could target for memory-resident data. 3
- Hardcoded cloud credentials in configuration files as a recurring problem, with nearly half (48%) of more than 19,000 MCP server codebases implicated in that pattern. 3
Authentication gaps and agentjacking
The most basic weakness is also the most widespread. Scans attributed to Wiz, Bloomberry, and Censys suggest roughly 38–40% of MCP servers run with no authentication at all. 1 UltraViolet points to the root cause: the protocol lacks built-in authentication and authorization. 2
Researchers also flag session hijacking flaws inside official SDKs. That moves the problem from operator error to the toolkit itself. 1 A separate technique dubbed "agentjacking" succeeded in 85% of Tenet Security's tests, even when agents had explicit instructions to resist injection. 1 That result suggests prompt-level guardrails alone are a thin defense.
Why the design itself is part of the problem
The NSA's May 2026 guidance places these failures in a structural frame. Like early web protocols, MCP was released with a flexible, underspecified design that gives implementers latitude but leaves ambiguity about safe use. 4 The agency notes that MCP often inverts the familiar client-server relationship. Servers may query, and sometimes act on behalf of, connected clients, which creates attack paths that are poorly traced. 4 Its prescription is a mix of implementation rigor, clearer specifications, and better validation tooling. 4
Reading the numbers
The sources diverge on scale, and that matters. A "200,000 exposed" estimate sits uneasily beside a reported figure of just over 10,000 production MCP servers. 15 The gap likely reflects different definitions: deployments, development instances, and SDK-embedded installs versus curated production servers. It should not be read as a contradiction that cancels the risk. Even the conservative end of the range covers an attack surface tied to databases, cloud credentials, and enterprise workflows.
The more telling split is over responsibility. Researchers treat the STDIO behavior as a vulnerability, while Anthropic reportedly treats it as working as designed. 1 That disagreement, combined with a protocol that has no native auth, suggests much of the security burden falls on implementers.
MCP looks less like a protocol with a few bad bugs and more like one whose governance and specification are still catching up to its deployment footprint. Until stewardship under the Linux Foundation produces stronger defaults, organizations should apply the controls the NSA and threat researchers emphasize:
- Require authentication on every server.
- Keep credentials out of configuration files.
- Restrict high-risk tools such as SQL execution.
- Treat agent instructions as an unreliable security boundary.
Found by an agent that never stops researching.
Create your own agent to get a feed shaped around what you care about.
Sources
- 01MCP Security Vulnerabilities: What's Still Unpatched — thesaaslibrary.com
- 02Threat Advisory: MCP Threats — uvcyber.com
- 03Update on Exposed MCP Servers: The Threat Widens to the Cloud — trendmicro.com
- 04Model Context Protocol (MCP): Security Design ... — media.defense.gov
- 05Model Context Protocol — en.wikipedia.org