logo

Nearly 2,000 MCP Servers Possess No Security Whatsoever

ID: 8e124e75-4a1e-5d2f-be8e-2a92b187f780

STIX ID: report--8e124e75-4a1e-5d2f-be8e-2a92b187f780

Feed Name: Dark Reading

Threat Score
60/100

Date Published: 2025-07-18

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Researchers discovered roughly 1,862 publicly reachable Model Context Protocol (MCP) servers with little or no authentication; a 119-server sample all returned lists of available tools and connectors, exposing database and service integrations. The exposure could enable attackers to exfiltrate sensitive data, obtain credentials or API keys, execute arbitrary actions via exposed functions, or run denial-of-wallet attacks, though the researchers stopped short of exploiting the servers and no active in-the-wild abuse is reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.