Tuesday , July 28 2026
MCP Servers

Thousands of MCP Servers Exposed to File Access and Injection Attacks

Thousands of Model Context Protocol (MCP) servers have serious security flaws like file access issues, command injection, server-side request forgery (SSRF), and SQL injection. This raises big worries about the safety of AI supply chain security.

A big study of 9,695 MCP servers from well-known sites like GitHub, Glama, Lobehub, and PulseMCP shows that trusted signs like popularity, activity, and verification badges do not always show real security quality, putting organizations at risk as use grows.

Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

CISA has put the Fortinet FortiOS vulnerability CVE-2025-68686 in its list of known exploited flaws after ongoing attacks. The flaw...
Read More
Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

OpenAI's CEO Sam Altman says that AI has reached a big milestone. The technology can now make itself better, leading...
Read More
Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

Shinyhunters claimed and set deadline to publish E&Y data

ShinyHunters has publicly claimed responsibility for the Ernst & Young (EY) data breach. The group posted a message on their...
Read More
Shinyhunters claimed and set deadline to publish E&Y data

Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Nvidia and over 30 tech firms started a group on Monday to create open-source AI tools for protecting against cyber...
Read More
Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Google Search Results Reportedly Show Claude AI Shared Chats

Claude's share links from Anthropic showed up in public search results. This raised new privacy worries for users who shared...
Read More
Google Search Results Reportedly Show Claude AI Shared Chats

“PentesterFlow” AI Automation Tool for Penetration Testers and Bug Hunters

PentesterFlow is a new open-source AI tool for command lines. It is made for penetration testers and bug bounty hunters....
Read More
“PentesterFlow” AI Automation Tool for Penetration Testers and Bug Hunters

Jailbreak works against AI Models GPT-5.6, Claude Opus 5, and Fable, Claims Researcher

A famous AI red team expert claimed developing a universal jailbreak that can work against top large language models, like...
Read More
Jailbreak works against AI Models GPT-5.6, Claude Opus 5, and Fable, Claims Researcher

Researchers found security flaws in every script generated by ChatGPT, Copilot, and Gemini

A new study from Beacom College shows that all automation scripts produced by top AI models like ChatGPT, Microsoft Copilot,...
Read More
Researchers found security flaws in every script generated by ChatGPT, Copilot, and Gemini

Australian Energy Giant Origin confirms unauthorized access and disclosure of customer data

Origin Energy Limited, a major energy provider in Australia, has said there was a cybersecurity issue with unauthorized access to...
Read More
Australian Energy Giant Origin confirms unauthorized access and disclosure of customer data

Anthropic Unveils Claude Security Plugin for Code Flaw Scanning

Anthropic launched the Claude Security plugin in beta. This tool uses AI to find serious security flaws in Claude Code....
Read More
Anthropic Unveils Claude Security Plugin for Code Flaw Scanning

Thousands of MCP Servers Found Vulnerable

The study found 5,832 servers with security flaws. Out of those, 2,259 were confirmed to have serious flaws that could be exploited beyond just login issues.

4,982 different security problems were listed. This includes 880 cases of unwanted file access, 476 command injection errors, 422 SSRF issues, 211 SQL injection problems, and 490 denial-of-service flaws.

Additional findings showed 155 cases of cross-site scripting, authorization bypass, and 185 prompt injection cases seen as harmful actions. Importantly, 2,054 servers did not have authentication methods, and while these were not reported alone, they greatly increase the risk of other weaknesses when added together.

MCP servers connect AI agents to important resources like files, databases, APIs, and cloud systems. This helps them run code and automate work. But this special access also increases the risk of attacks.

The top combinations of security issues (Source: Trend AI Security)

The study showed that there is no strong link between how popular a server is and its security. Servers that are very popular (with over 50 GitHub stars) can be the most risky because many people use them, which raises the danger of one flaw affecting many users.

These servers often show SSRF, prompt injection, and file access problems linked to rich features. Mid-tier servers (10–49 stars) are the most common and have the most types of weaknesses. On the other hand, low-popularity and no-star repositories, which are often experimental or used privately, still have serious issues like command execution flaws, even though they are less visible.

Repository activity, measured by commit history, did not show better security. Projects with over 100 commits were just as vulnerable as less active ones. This means that more development can lead to more security risks without making defenses better.

Verification tools in MCP directories, like code checks and ownership tests, did not lower risk much. Verified servers had almost the same average number of problems as unverified servers.

The Trend AI Security study shows real risks in different areas. In MCP servers that focus on cryptocurrency and DeFi, researchers found problems with server-side template injection that allow remote code execution and issues with prompt injection that can change how AI agents behave.

MCP servers in businesses had problems with SQL injection and unverified Active Directory queries. This could let attackers gather information or gain more power using simple language questions handled by AI.

The study highlights a larger problem in the industry: there is no steady way to check inputs or safe development methods in the MCP system. Most security gaps were seen as mistakes made by developers, not as deliberate attacks. Still, prompt injection is a new danger in places using LLMs.

Security experts say that organizations need to stop trusting third-party MCP servers and instead use a zero-trust method.

This involves checking code, making sure users are verified and have limited access, validating all inputs, and inspecting traffic in real-time to find unusual behavior. As MCP supports the growth of AI-driven automation, the results show that security needs to improve with functionality to stop widespread abuse of connected AI systems.

Check Also

Nvidia

Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Nvidia and over 30 tech firms started a group on Monday to create open-source AI …