VYPR
advisoryPublished Sep 28, 2026· 1 source

Model Context Protocol Servers Expose Organizations to Significant Governance and Security Risks, Researchers Warn

Ox Security research reveals widespread governance gaps in Model Context Protocol (MCP) servers, potentially undermining cybersecurity efforts as AI deployments accelerate.

Researchers at Ox Security have sounded the alarm over significant governance and security gaps present in a vast number of Model Context Protocol (MCP) servers, a critical component for connecting AI applications to external data and tools. The findings, detailed in the report "15,465 MCP Servers, 0 Governance," highlight that as AI adoption rapidly increases, these protocols are inadvertently creating "silent enterprise governance gaps" that could severely undermine existing cybersecurity strategies.

MCP servers are designed to streamline the integration of AI models with various APIs and databases, eliminating the need for custom coding. However, Ox Security's analysis of over 15,000 MCP servers across public registries indicates that this convenience comes at a steep price. The research suggests that MCP may be introducing cloud security risks that organizations typically mitigate through measures like data residency controls, zero trust architectures, granular identity and access management (IAM) policies, and supply chain audits.

The report's analysis of 5,095 unique hostnames revealed that nearly 16% resolved outside the United States, in countries including Russia and China. This geographic dispersion is particularly concerning because, as Ox Security points out, "MCP has no protocol-level concept of geographic region." This means that even if an enterprise enforces strict data residency controls on its own cloud infrastructure, its AI agents could still connect to MCP servers located outside those mandated boundaries, creating a significant compliance and security loophole.

Further compounding the risks, over 2% of the analyzed hostnames no longer resolve. Some of these are currently unregistered and available for purchase, presenting a clear opportunity for threat actors to impersonate legitimate servers. This could lead to sophisticated phishing attacks, data exfiltration, or the redirection of AI agent traffic to malicious infrastructure, all while appearing to originate from a trusted source.

The research also flagged a critical issue related to permission handling. When testing Anthropic's Claude Code with Haiku 3.5, researchers found that granting a single "always-allow" permission to an MCP server enabled subsequent malicious activity without requiring further human approval. In one scenario, a malicious MCP server first requested access to a harmless file, which was approved with an "always-allow" setting. It then successfully requested a sensitive file, such as a .env file containing credentials, without any additional prompts, demonstrating a dangerous lack of granular control once initial permissions are granted.

Anthropic's response indicated that this behavior is documented and that model-level detection of malicious content is a best-effort heuristic, not a security boundary. This highlights a fundamental challenge in securing AI supply chains: the reliance on best-effort security measures rather than hard-coded, robust security controls.

This is not the first time MCP servers have been flagged for security concerns. A June 2025 report by Backslash Security identified hundreds of MCP servers exposed to local networks via a vulnerability dubbed "NeighborJack," with around 70 exhibiting severe flaws like unchecked input handling and excessive permissions. In April 2026, Ox Security itself reported a "critical, systemic" vulnerability in MCP that could allow arbitrary command execution, potentially exposing hundreds of thousands of instances.

The proliferation of these governance gaps and vulnerabilities in MCP servers poses a substantial threat to organizations integrating AI into their operations. As AI agents become more autonomous and interconnected, the security of the protocols they rely on, like MCP, becomes paramount. The findings underscore the urgent need for standardized security protocols, robust permission management, and greater transparency in the AI supply chain to prevent widespread exploitation.

Synthesized by Vypr AI