Measurement study: 40% of live MCP servers have zero authentication
Glittering_Royal6799 · reddit · 2026-09-22
A measurement study of nearly 8,000 live remote MCP servers found 40.55% expose tools with no authentication at all, and every server that did use OAuth had at least one security flaw. Over 300 CVEs have been filed against MCP infrastructure. The core issue: every MCP server now quietly acts as an identity issuer deciding what agents can access, but most were never built to do that safely.
More from coding & agent
- The Modern AI Stack: 100+ Tools Powering What's Underneath ChatGPT — Aiden_Tech_Ai · 2026-09-22
- OpenAI, Anthropic, and Cognition to launch personal agent platforms within a month — cephaloform · 2026-09-22
- Open-source SemIf: a 4B model on a 3090 beats Jev in Sentdex's toy test — Sentdex · 2026-09-22
- A 4B model beats Jev in hybrid agent setup that runs 13x faster at 56% cost — Sentdex · 2026-09-22
- Jev ships 7-page guide; dynamic context rated 10/10 for coding agents — ramagetime · 2026-09-22
- Spring AI model router sample: auto-tier prompts across four OpenAI models — therealdanvega · 2026-09-22