Fetching from the wire…
Public story · 2026-03-23 · source-backed
The Model Context Protocol has a security problem that's no longer theoretical — it's statistical. Between January and February 2026, researchers filed 30+ CVEs against MCP servers, clients, and infrastructure. One package with nearly 500,000 downloads carried a CVSS 9.6 RCE. A survey of 2,614 MCP implementations found 82% vulnerable to path traversal via file operations, two-thirds have code injection risk, and 38% of 500+ scanned servers completely lack authentication (MCP Security 2026).
The breakdown by attack class: 43% exec/shell injection from unsanitized user input, 20% tooling infrastructure flaws, 13% authentication bypass. The WhatsApp MCP server was documented exfiltrating entire chat histories via tool poisoning — where malicious tool descriptions trick agents into executing operations they can't distinguish from legitimate ones.
This is hitting from multiple directions simultaneously. Qualys TotalAI found over 10,000 active public MCP servers deployed within one year of Anthropic's introduction, with 53% relying on static secrets. Servers evade traditional security tooling by binding to localhost, using random high ports, or embedding in developer tools — classic shadow IT behavior, now with RCE surface.
Meanwhile, Token Security will present MCPwned at RSAC 2026 — an RCE in Microsoft's Azure MCP server that enables full cloud environment compromise (GlobeNewswire). The specific CVE (CVE-2026-23744) in MCPJam Inspector (≤ v1.4.2) binds to 0.0.0.0 with no auth, allowing a single crafted HTTP request to install an arbitrary MCP server and execute code on the host with zero user interaction. The kill chain chains into full Azure tenant compromise via credential harvesting.
What to do right now: Inventory every MCP server in your stack. Enforce authentication on all of them. Audit tool descriptions for injection vectors. If you're running MCPJam Inspector, upgrade to v1.4.3 immediately. Treat every MCP server like an API gateway — because that's what it is, minus decades of hardened security tooling.
Each link below shares sources, entities, or timing with this story.
Microsoft released Azure / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Microsoft released Azure); both cover Azure MCP, Conference, CVEs, Days; overlapping topics (authentication, azure, chain, cves, have).
Ariel Simon criticizes Azure / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Ariel Simon criticizes Azure); both cover Azure, Azure MCP, CVE, CVSS; overlapping topics (azure, chain, full, server).
Microsoft released Azure / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Microsoft released Azure); both cover Audit, CVE, CVEs, CVSS; overlapping topics (chain, code, cves, have).
Ariel Simon criticizes Azure / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Ariel Simon criticizes Azure); both cover Azure, Azure MCP, CVE, MCPwned; overlapping topics (azure, chain, compromise, full, server).
Microsoft released Azure / Shared entities / Shared topic / What happened next
Linked by a graph relationship (Microsoft released Azure); both cover CVE, CVEs, CVSS, Days; overlapping topics (authentication, azure, cves, injection, security).
Anthropic released MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Anthropic released MCP); both cover Anthropic, CVE, CVEs, HTTP; overlapping topics (cves, injection, server).
Microsoft released Azure / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Microsoft released Azure); both cover Audit, CVE, CVEs, CVSS; overlapping topics (chain, security, server).
Microsoft supports MCP / Shared entities / Shared topic / What happened next
Linked by a graph relationship (Microsoft supports MCP); both cover CVE, CVEs, CVSS, February; overlapping topics (code, cves, security, tool).