thehackernews.com 6 Oct 2026, 11:02 UTC

Thousands of MCP Servers Have No Governance, OX Security Warns

OX Security has published findings on the MCP (Model Context Protocol) ecosystem, revealing a dangerous gap between a standard for AI model and tool integration and the governance applied by downstream marketplaces and servers. The researchers examined what people actually install and found a marketplace landscape with little to no guardrails or code review, meaning enterprises cannot safely rely on public MCP servers without additional verification.

A key point is that the trust users place in repositories does not reflect what runs on the server itself, which may execute backend code different from what is publicly visible.

The report analysed 15,465 publicly indexed MCP servers across five MCP registries, deduplicating to 5,095 unique hostnames. Notable findings include: 15.6% of hostnames resolve to infrastructure outside the United States (including 19 in China and 18 in Russia); 0.45% route traffic through consumer tunnelling services (predominantly ngrok-free), indicating servers run from personal machines or home networks; and 2.3% have dangling domains, with six on expired domains that new owners could register.

The authors stress that data residency, Zero Trust boundaries, IAM granularity, and supply-chain audits are often bypassed by MCP connections, expanding the enterprise attack surface. They advocate for added vetting, code signing, and origin verification by marketplaces, while noting that governance remains a responsibility for the enterprise. The full report, “15,465 MCP Servers, 0 Governance,” is available for download.

View full article

Article by CyberSIXT