build1 publisherOne report Pennyforge Studio found that 40 of 186 servers in one MCP registry slice completed an anonymous tool call. Most failures were credential gates or schemas that understate required inputs, so a registry listing says little about whether an agent's call will succeed.
Reality
- Evidence55
- Adoption10
- Hype gap+15
- Incentives40
- Confidence50
Cisco says CVE-2026-76460 is under active exploitation. It scores 10.0, needs no credentials, and puts an unauthenticated attacker past the web management interface of an Identity Services Engine appliance.
Reality
- Evidence45
- Adoption30
- Hype gap−10
- Incentives50
- Confidence48
build1 publisherOne report Three commits in one evening shipped free guest games, minted a permit so those games could read question banks behind auth, then removed all of it. The permit module is good code, and writing it produced the case against the feature.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap−10
- Incentives25
- Confidence62
build1 publisherOne report The only public count of internet-exposed MCP servers is fourteen months old, so a new open-source scanner fingerprints them by protocol handshake and reports which ones answer a caller holding no credentials.
Reality
- Evidence46
- Adoption20
- Hype gap+15
- Incentives55
- Confidence47
build1 publisherOne report A measured run published on dev.to shows three If-None-Match requests returning 304 with empty bodies each took one off the 60/hour bucket. The discount is documented only for authorized calls.
Reality
- Evidence66
- Adoption
- Insufficient
- Hype gap−12
- Incentives30
- Confidence55