Infosecurity Magazine iconInfosecurity MagazineSep 28, 2026 ~5 min source read

Researchers Say MCP Deployments Are Creating Major Enterprise Governance Gaps

Ox Security analyzed thousands of Model Context Protocol servers and found geographic exposure, stale hostnames, and permission flows that bypass enterprise controls.

Share this story

Send the public story page.

Useful takeaways from this story.

Ox Security report titled "15,465 MCP Servers, 0 Governance" analyzed three public registries and found wide geographic and operational exposure across MCP infrastructure.

A tested permission flow with Claude Code (Haiku 3.5) showed an "always-allow" grant allowed subsequent access to sensitive files, including.env, without further user prompts.

Previous research flagged additional MCP risks: a 2025 NeighborJack local-network exposure and an April 2026 Ox Security report describing a systemic SDK design issue affecting many open-source projects.

# What Ox Security found Ox Security published a report called "15,465 MCP Servers, 0 Governance" after analyzing three public MCP registries: mcp-official-registry, cline-marketplace and github-mcp-registry. The report inspects MCP deployments and shows how MCP (Model Context Protocol) servers can escape common enterprise controls and introduce new cloud and supply-chain risks.

# Concrete data points Ox Security analyzed 15,465 MCP servers and identified 5,095 unique hostnames. Nearly 16% of those hostnames resolved to locations outside the United States, including Russia and China. The report notes MCP has no protocol-level concept of geographic region, which lets AI agents connect to servers outside organizational residency controls.

# Permission and behavior risks demonstrated

# Related MCP vulnerabilities and prior reports The Ox Security report is part of a sequence of research that has highlighted MCP-related risks:

  • June 2025: Backslash Security analyzed about 7,000 MCP servers and reported a local-network vulnerability dubbed "NeighborJack," which exposed hundreds of servers to anyone on the same LAN. Around 70 servers had severe flaws like unchecked input handling or excessive permissions.
  • April 2026: Ox Security released a report claiming a "critical, systemic" vulnerability tied to MCP SDK design across languages. That report estimated impacts touching roughly 200 open-source projects, 150 million downloads, 7,000+ publicly accessible servers and up to 200,000 vulnerable instances. Ox Security described the problem as an architectural design decision in Anthropic's official MCP SDKs. Anthropic called the behavior "expected" and left remediation to the open-source supply chain.

# Implications for enterprise governance The report shows multiple ways MCP servers can sit outside common enterprise controls: geographic residency rules, zero-trust boundaries, granular IAM policies and supply-chain audits. Stale hostnames and permissive client-side behaviors can create impersonation and data-exfiltration vectors that bypass existing cloud governance tooling.

# Practical follow-ups for security teams The article details findings rather than prescriptive steps, but the concrete issues security teams should prioritize based on the report are: inventorying any internal use of MCP endpoints, auditing where AI agents connect (including external hostnames and geographic resolution), reviewing permission models like "always-allow," and tracking third-party MCP components in the software supply chain.

# Bottom line Ox Security's analysis presents measurable governance gaps tied to deployed MCP servers: cross-border exposure, stale hostnames available for re-registration, and permission flows that can allow sensitive data access without repeated human authorization. Prior research has documented local-network and SDK-level risks, creating a pattern of deployment, configuration and design issues across MCP ecosystems.

More context around this story.

MCP Debate: Token Tax, Context Bloat, and What Devs Can Do
Dev iconDevSep 22, 2026

MCP Debate: Token Tax, Context Bloat, and What Devs Can Do

TL;DR: A post on maharship.com argues MCP was designed for 2024-era models and now causes context bloat and a token tax, sparking a ~165-point Hacker News thread with 100+ comments and pushback on X. If you run agents today, the debate is a prompt to audit what your tools actually cost in context and dollars before you

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app