First Dynamic Security Assessment of Internet-Facing MCP Servers Reveals Widespread Vulnerabilities
A groundbreaking study has performed the first dynamic security check on Model Context Protocol (MCP) servers that are accessible online, uncovering serious weaknesses. Since its debut in November 2024, MCP has rapidly become popular, with over 21,000 servers found online. This investigation combined passive data collection from eleven sources, including crt.sh and Shodan, with active testing using Corvus, which has 34 testing modules focused on ten vulnerability types. In July 2026, researchers monitored four measurement sessions, identifying 640 active MCP servers and evaluating 414 of them. They discovered 68 vulnerabilities, including SQL injection and SSRF aimed at cloud metadata services. Shockingly, 91.8% of the servers reviewed lack OAuth authentication, with 687 tool instances in various setups.
Key facts
- MCP launched in November 2024
- Over 21,000 MCP server instances detectable on the public internet
- First dynamic behavioral security assessment of internet-facing MCP servers
- Passive discovery across 11 data sources
- Active testing using Corvus framework with 34 test modules
- 10 MCP-specific vulnerability classes covered
- Four measurement runs spanning July 2026
- 640 production MCP servers confirmed
- 414 servers dynamically audited
- 68 reportable vulnerabilities found
- 91.8% of audited servers lack OAuth authentication
- 687 tool instances across confi
Entities
Institutions
- arXiv
- HuggingFace
- GitHub
- npm
- Smithery
- PyPI
- Censys
- FOFA
- Shodan
- glama.ai
- pulsemcp.com