Researchers Say MCP Deployments Are Creating Major Enterprise Governance Gaps
Ox Security analyzed thousands of Model Context Protocol servers and found geographic exposure, stale hostnames, and permission flows that bypass enterprise controls.
Ox Security analyzed thousands of Model Context Protocol servers and found geographic exposure, stale hostnames, and permission flows that bypass enterprise controls.
Ox Security report titled "15,465 MCP Servers, 0 Governance" analyzed three public registries and found wide geographic and operational exposure across MCP infrastructure.
A tested permission flow with Claude Code (Haiku 3.5) showed an "always-allow" grant allowed subsequent access to sensitive files, including.env, without further user prompts.
Previous research flagged additional MCP risks: a 2025 NeighborJack local-network exposure and an April 2026 Ox Security report describing a systemic SDK design issue affecting many open-source projects.
# What Ox Security found Ox Security published a report called "15,465 MCP Servers, 0 Governance" after analyzing three public MCP registries: mcp-official-registry, cline-marketplace and github-mcp-registry. The report inspects MCP deployments and shows how MCP (Model Context Protocol) servers can escape common enterprise controls and introduce new cloud and supply-chain risks.
# Concrete data points Ox Security analyzed 15,465 MCP servers and identified 5,095 unique hostnames. Nearly 16% of those hostnames resolved to locations outside the United States, including Russia and China. The report notes MCP has no protocol-level concept of geographic region, which lets AI agents connect to servers outside organizational residency controls.
# Permission and behavior risks demonstrated
# Related MCP vulnerabilities and prior reports The Ox Security report is part of a sequence of research that has highlighted MCP-related risks:
# Implications for enterprise governance The report shows multiple ways MCP servers can sit outside common enterprise controls: geographic residency rules, zero-trust boundaries, granular IAM policies and supply-chain audits. Stale hostnames and permissive client-side behaviors can create impersonation and data-exfiltration vectors that bypass existing cloud governance tooling.
# Practical follow-ups for security teams The article details findings rather than prescriptive steps, but the concrete issues security teams should prioritize based on the report are: inventorying any internal use of MCP endpoints, auditing where AI agents connect (including external hostnames and geographic resolution), reviewing permission models like "always-allow," and tracking third-party MCP components in the software supply chain.
# Bottom line Ox Security's analysis presents measurable governance gaps tied to deployed MCP servers: cross-border exposure, stale hostnames available for re-registration, and permission flows that can allow sensitive data access without repeated human authorization. Prior research has documented local-network and SDK-level risks, creating a pattern of deployment, configuration and design issues across MCP ecosystems.

Effective regulations, better governance can address budget discrepancy
ShareGate study claims to reveal a governance ‘crisis’ as AI usage grows
Enterprise software increasingly requires users to wear many hats. The security engineer who manages access controls one day handles incident response the next. The operations team that automates routine deployments must also handle one-off infrastructure exceptions. These occasional, cognitively complex tasks fall int

TL;DR: A post on maharship.com argues MCP was designed for 2024-era models and now causes context bloat and a token tax, sparking a ~165-point Hacker News thread with 100+ comments and pushback on X. If you run agents today, the debate is a prompt to audit what your tools actually cost in context and dollars before you
The EU Court of Auditors has criticized EU shortcomings in responding to major cyber incidents

Misconfigurations remain widespread in the manufacturing sector, including internet-accessible remote-access software, a new report found.
Loading more related stories...
Open the app view to save this story, compare related coverage, and continue from the same source.