Fetching from the wire…
Public story · 2026-03-23 · source-backed
The Model Context Protocol has a security problem that's no longer theoretical — it's statistical. Between January and February 2026, researchers filed 30+ CVEs against MCP servers, clients, and infrastructure. One package with nearly 500,000 downloads carried a CVSS 9.6 RCE. A survey of 2,614 MCP implementations found 82% vulnerable to path traversal via file operations, two-thirds have code injection risk, and 38% of 500+ scanned servers completely lack authentication (MCP Security 2026).
The breakdown by attack class: 43% exec/shell injection from unsanitized user input, 20% tooling infrastructure flaws, 13% authentication bypass. The WhatsApp MCP server was documented exfiltrating entire chat histories via tool poisoning — where malicious tool descriptions trick agents into executing operations they can't distinguish from legitimate ones.
This is hitting from multiple directions simultaneously. Qualys TotalAI found over 10,000 active public MCP servers deployed within one year of Anthropic's introduction, with 53% relying on static secrets. Servers evade traditional security tooling by binding to localhost, using random high ports, or embedding in developer tools — classic shadow IT behavior, now with RCE surface.
Meanwhile, Token Security will present MCPwned at RSAC 2026 — an RCE in Microsoft's Azure MCP server that enables full cloud environment compromise (GlobeNewswire). The specific CVE (CVE-2026-23744) in MCPJam Inspector (≤ v1.4.2) binds to 0.0.0.0 with no auth, allowing a single crafted HTTP request to install an arbitrary MCP server and execute code on the host with zero user interaction. The kill chain chains into full Azure tenant compromise via credential harvesting.
What to do right now: Inventory every MCP server in your stack. Enforce authentication on all of them. Audit tool descriptions for injection vectors. If you're running MCPJam Inspector, upgrade to v1.4.3 immediately. Treat every MCP server like an API gateway — because that's what it is, minus decades of hardened security tooling.
Each link below shares sources, entities, or timing with this story.
Token Security's RSAC 2026 presentation documents an RCE chain in Microsoft's Azure MCP server that compromises entire cloud environments. 38% of 500+ public MCP servers have no authentication. Every tool parameter is an untrusted injection surface. Source
Token Security researcher Ariel Simon will present at RSAC 2026 a vulnerability chain starting from SSRF in Microsoft's Azure MCP server (CVE-2026-26118, CVSS 8.8). The managed identity token included in outbound MCP requests is capturable without admin access, then escalatabl...
The agent skills supply chain is under coordinated attack. Snyk's ToxicSkills audit found 36% of ClawHub's 3,984 skills contain prompt injection payloads, 13.4% have critical malware, and submission rates exploded 10x to 500+/day. This week alone: CVE-2026-2256 (CVSS 9.1) is a...
Token Security researcher Ariel Simon will demo a full attack chain at RSAC 2026 — from an RCE flaw in Microsoft's Azure MCP server to credential harvesting and complete Azure tenant compromise. The research extends beyond the patched CVE-2026-26118 by demonstrating post-explo...
Thirty CVEs in sixty days. That's the MCP ecosystem's security track record for 2026 so far, and the severity is climbing. Three disclosures dropped this week that should make anyone running agent infrastructure pause. First, PraisonAI, a popular multi-agent orchestration fram...
Two new attack classes emerged: Anthropic's own official Git MCP server has three CVEs (CVE-2025-68143/44/45) enabling RCE via prompt injection. MCP Watch, a security scanner designed to audit MCP servers, itself contains a command injection (CVE-2025-66401). MCPJam Inspector...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.