Measurement study: 40% of live MCP servers have zero authentication

Glittering_Royal6799 · reddit · 2026-09-22

A measurement study of nearly 8,000 live remote MCP servers found 40.55% expose tools with no authentication at all, and every server that did use OAuth had at least one security flaw. Over 300 CVEs have been filed against MCP infrastructure. The core issue: every MCP server now quietly acts as an identity issuer deciding what agents can access, but most were never built to do that safely.

Original post →

More from coding & agent

coding & agent channel →