Fetching from the wire…
Public story · 2026-08-11 · high
Zero Day Initiative scanned 19,000 servers and put 600 to 1,650 as exploitable, with 42% of vulnerable repos tracing to code AI coding tools wrote.
Why now: Forkast published the tally days before the MCP Dev Summit in Seoul opens on Aug. 13, putting these numbers in front of the people who set the protocol's next security defaults.
A review of the MCP ecosystem counts more than 40 disclosed CVEs across roughly 15,930 active public servers spanning four registries, per Forkast. Zero Day Initiative ran its own scan of 19,000 servers and extrapolates that 600 to 1,650 are exploitable, per Forkast's tally. Among the vulnerable implementations, 26% carry SQL injection flaws and 22.5% allow remote code execution.
The number that should worry builders is 42%: that's the share of vulnerable MCP repos that trace back to code written by AI coding tools, per Forkast's analysis. The same tools writing the servers are writing the holes into them.
The Langflow chain, CVE-2026-33017 paired with CVE-2026-55255, shows how fast that gap gets used. Attackers weaponized it within 20 hours of disclosure, pulling LLM provider keys and cloud credentials straight out of live deployments.
This isn't a one-off patch cycle anymore. At 40+ CVEs and thousands of exploitable servers, MCP security reads as a standing line item, the same way web app security became one after a decade of SQL injection breaches. Forkast published the tally days before the MCP Dev Summit in Seoul opens on Aug. 13, and a related audit circulating in the same coverage found most production MCP servers still run without OAuth. Anyone shipping an MCP server built with an AI coding tool should give it the same security review as anything else headed to production, not a lighter one because a model wrote it.
Each link below shares sources, entities, or timing with this story.
Same source domain / Semantically similar
Reported by the same outlet (forkast.news); covers closely related ground (similarity 0.75).
Same source
Cite the same source (Forkast).
Semantically similar
Covers closely related ground (similarity 0.83).
Covers closely related ground (similarity 0.78).
Covers closely related ground (similarity 0.77).
Covers closely related ground (similarity 0.77).
Covers closely related ground (similarity 0.77).
Covers closely related ground (similarity 0.77).