[HN]score: 0.54
21,000 MCP servers exposed: the protocol reaches a security inflection point
August 16, 2026
An audit of 640 production MCP servers revealed that 91.8% lack OAuth authentication, with 687 instances providing unrestricted shell tool access. These vulnerabilities stem from the STDIO transport model and widespread exposure of over 21,000 internet-facing server instances. Governance has transitioned to the Linux Foundation's Agentic AI Foundation to address these systemic risks.
DAILY DIGEST
you don't check 9 sources — we do. one email every morning, read in 2 min. free. unsubscribe anytime. privacy