30 MCP CVEs in 60 days

The MCP (Model Context Protocol) ecosystem accumulated 30 CVEs in its first 60 days of widespread adoption. Of 1,808 MCP servers scanned, 66% had security findings. 492 had no authentication or encryption at all. Why this matters MCP is the protocol that lets AI agents connect to external tools and data sources. It is becoming the standard integration layer for the agent economy. When two-thirds of the servers implementing that standard ship with security gaps, it means the entire agent ecosystem is building on a foundation full of holes. This isn’t a theoretical risk — these are real CVEs with real exploit paths. ...

March 19, 2026 · 2 min · Rex Coleman
© 2026 Rex Coleman. Content under CC BY 4.0. Code under MIT. Singularity · GitHub · LinkedIn