Fetching from the wire…
Top 5 · 2026-02-22 · source-backed
Bitdefender published the most alarming MCP security metric to date: 53% of open-source MCP server implementations rely on insecure static credentials while only 8.5% use OAuth. The report identifies five risk categories: opt-in (not default) security, supply chain poisoning, over-permissioned tokens/confused deputy, injection attacks, and absent audit logging. Two specific CVEs cited: CVE-2025-6514 (CVSS 9.6 RCE in mcp-remote) and CVE-2025-32711 ("EchoLeak" silent data exfiltration via Microsoft 365 Copilot). Builder takeaway: Audit your MCP servers TODAY. Replace static credentials with OAuth. Bitdefender
Each link below shares sources, entities, or timing with this story.
MCP uses OAuth / Shared entities / Shared topic / What happened next / Tension
Linked by a graph relationship (MCP uses OAuth); both cover Audit, CVE, CVEs, CVSS; overlapping topics (chain, security, server).
MCP uses OAuth / Shared entities / Shared topic / What happened next
Linked by a graph relationship (MCP uses OAuth); both cover Audit, CVE, CVEs, CVSS; overlapping topics (attack, audit, chain).
MCP uses OAuth / Shared entities / Same source / Shared topic / What happened next
Linked by a graph relationship (MCP uses OAuth); both cover Bitdefender, Builder, MCP, OAuth; cite the same source (Bitdefender).
MCP uses OAuth / Shared entities / Shared topic / What happened next
Linked by a graph relationship (MCP uses OAuth); both cover Audit, CVE, CVEs, CVSS; overlapping topics (chain, server).
Linked by a graph relationship (MCP uses OAuth); both cover Copilot, CVEs, MCP, OAuth; overlapping topics (audit, category, server).
MCP uses OAuth / Shared entities / Same source / Shared topic
Linked by a graph relationship (MCP uses OAuth); both cover Bitdefender, CVEs, MCP, OAuth; cite the same source (Bitdefender).
Microsoft released Azure / Shared entities / Shared topic / What happened next
Linked by a graph relationship (Microsoft released Azure); both cover Audit, CVE, CVEs, Replace; overlapping topics (attack, chain, credential, security).
Cursor uses MCP / Shared entities / Shared topic / What happened next
Linked by a graph relationship (Cursor uses MCP); both cover Builder, CVE, CVEs, RCE; overlapping topics (attack, builder, chain, copilot).