MCP Python SDK maintainers rated a flaw that let a connected server choose where OAuth secrets were sent High, at 7.5. For its two machine-to-machine providers, upgrading changes nothing until the client names the issuer it expects.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+15
- Incentives30
- Confidence50
AWS published CVE-2026-87911, a CVSS 9.6 command injection in its own postgres-mcp-server, where one COPY ... TO PROGRAM line runs a shell on the host. The read-only promise lives in a regex filter that lets the COPY keyword through.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+25
- Incentives40
- Confidence50
MCP Python SDK releases 1.30.0 and 2.2.0 leave a credential-theft bug open for two OAuth providers unless their constructors pass an issuer. For unattended MCP clients the fix is a one-argument code change, and each team has to find and make it in its own source.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence50
Model Context Protocol's reference Postgres MCP server guards writes with a read-only transaction. One COMMIT; DROP TABLE query drops the table anyway. Only database permissions sit where the agent's SQL cannot reach.
Reality
- Evidence64
- Adoption
- Insufficient
- Hype gap+5
- Incentives70
- Confidence66
LiteLLM's MCP test endpoints let any valid proxy key run arbitrary commands on the gateway, rated CVSS 8.8. CISA added the flaw to its Known Exploited Vulnerabilities catalog on June 8, 2026, confirming exploitation in the wild.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
Imperva found Microsoft's DebugMCP 1.1.4 let a malicious webpage run code on a developer's machine through an unauthenticated port 3001 listener. The fix reached 1.2.0 with no advisory, so finding exposed machines means checking installed extension versions.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence60
MCP servers that skip audience binding accept tokens minted for other servers, says a dev.to OAuth 2.1 guide that puts it in the 80% most guides skip. The check depends on RFC 9728 metadata the server publishes and a resource parameter the client sends.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+25
- Incentives60
- Confidence35
A GET asks a site for a page and a POST tells it to act, so the change Akamai measured over 30 days puts verified AI bots on the request type behind store logins, carts and checkouts. Akamai did not break those requests down by action; retailers have that in their own logs.
Reality
- Evidence36
- Adoption42
- Hype gap+28
- Incentives80
- Confidence40
Hush Security searched public GitHub for the configuration filenames coding agents write, classified how each credential slot gets its value, and found a hardcoded literal in 12% of them, most of which match no vendor token format.
Reality
- Evidence45
- Adoption38
- Hype gap+12
- Incentives78
- Confidence58
A dev.to post argues MCP's attack surface follows from point-to-point model-to-server links and belongs behind an inline gateway. The tool-poisoning path it documents runs through description text that a gateway may forward unchanged.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+35
- Incentives75
- Confidence45
In MCP's Sampling flow the server composes the prompt and the client runs the completion on its own model. The includeContext default is "none", and the two wider values only work if the client declares a capability.
Reality
- Evidence50
- Adoption30
- Hype gap+8
- Incentives15
- Confidence55
Island scanned 475,865 tools across 33,563 MCP server builds in July 2026 and found manipulation signals in 3.3% of them. Its researcher says a scan can confirm the capability is there without seeing what will actually run.
Reality
- Evidence45
- Adoption30
- Hype gap+30
- Incentives70
- Confidence50
The poisoned field is inputSchema, which the framework parses and executes against while the model's safety training never evaluates it, so the only gate that holds is a hash recomputed at every call.
Reality
- Evidence32
- Adoption35
- Hype gap+30
- Incentives38
- Confidence45
An SC World commentary argues the AI security debate is stuck on model behavior while agent connectors get wired with API keys that never rotate and model loading still executes unsigned code.
Reality
- Evidence58
- Adoption34
- Hype gap+14
- Incentives34
- Confidence53
The MCP layer inherits its trust at install time and never re-checks it, so a lapsed domain behind a still-listed registry entry belongs to whoever registers it next. Air Security says it registered one, and agents came.
Publishers:air.security
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+32
- Incentives84
- Confidence34
A researcher found the SSRF guard sitting on the credential-submission side of an MCP auth SDK while the .well-known discovery fetch ran unchecked from the public entry point, which is the wrong end of the flow to protect.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+28
- Incentives55
- Confidence42
Agent tool calls look like ordinary HTTPS, so Cloudflare's new controls match on protocol headers rather than on destinations. They only see traffic you already decrypt, which is where the adoption cost sits.
Reality
- Evidence45
- Adoption12
- Hype gap+22
- Incentives85
- Confidence55
A census scored 19 widely deployed servers on three disclosure questions drawn from the MCP spec, and the most common answer in every column was undocumented. That is the position agent teams are reviewing from.
Publishers:digitalapplied.com
Reality
- Evidence62
- Adoption28
- Hype gap−10
- Incentives35
- Confidence55
Ninety days of Wiz honeypot telemetry shows tooling written for LiteLLM's internals, including a config test endpoint that spawns whatever command it is handed and a miner whose output comes home inside the MCP protocol.
Reality
- Evidence62
- Adoption66
- Hype gap+12
- Incentives72
- Confidence55
A PingFederate write-up wires RFC 8693 token exchange to a SPIRE JWT-SVID so neither the user's token nor the workload's proof can stand in for the other. The lifetimes tell you where the risk sits.
Reality
- Evidence44
- Adoption10
- Hype gap−5
- Incentives42
- Confidence55
Earlier coverage
- MCP is four trust boundaries, and credentials only close one of them
Build · August 23, 2026 · 1 publisher
- Google names the default posture for agent security, and boards will borrow the words
Leadership · August 22, 2026 · 1 publisher
- Exposed MCP servers are now a scanned entry point, and N4D's agent calls the tools itself
Science · August 21, 2026 · 1 publisher
- OX Security says MCP command execution is a design choice, so server owners own the risk
Science · August 19, 2026 · 1 publisher
- Human-in-the-loop is being retired, and the assurance burden shifts to machine identity
Leadership · August 18, 2026 · 1 publisher
- The credential store nobody inventoried: MCP servers now hold the keys to everything they touch
Security · August 18, 2026 · 1 publisher
- Microsoft ships an MIT-licensed agent kernel: policy rings, Ed25519 identity, kill switch
Build · August 17, 2026 · 1 publisher