MCP Security in June 2026: ~40% of Remote Servers Still Expose Tools With No Authentication
Adversa AI·medium signal
Fresh June tallies underline that MCP's security debt is structural, not incidental: Censys counted ~12,520 internet-accessible MCP services (most unauthenticated), a separate study found roughly 40% of remote servers expose tools with no auth, VIPER-MCP's sweep of ~40,000 repos produced 67 CVEs, and Microsoft patched a server-hijacking flaw (CVE-2026-26118). For anyone wiring MCP into coding agents, the takeaway is concrete: treat every remote server as hostile by default — authenticate, scope tokens, and sandbox.