A combined static-and-dynamic taint framework, VIPER-MCP, swept ~40,000 MCP server repos and surfaced 106 zero-day vulnerabilities yielding 67 CVEs, per Adversa AI's June 2026 roundup. In parallel the NSA's AI Security Center released CSI U/OO/6030316-26 ("Model Context Protocol: Security Design Considerations"), covering MCP's inverted client-server pattern, unverified task propagation between servers, and arbitrary-code-execution exposure. Together they mark MCP security shifting from ad-hoc disclosures to an official defensive baseline builders can audit against.