AI Business

MCP Servers Emerge as Critical Security Vulnerability in AI Infrastructure

Model Context Protocol servers have become the standard for connecting AI agents to external tools in just over a year, but security defenses have failed to keep pace with their rapid adoption.

·4 min read
Why MCP servers are becoming AI’s newest attack surface
Why MCP servers are becoming AI’s newest attack surface

The velocity of AI infrastructure development has created a persistent challenge for security teams. As new standards and protocols gain traction, they proliferate across the ecosystem in months—a timeline that accelerates capability but outpaces defensive measures. MCP servers exemplify this dynamic. Anthropic published MCP as an open standard in November 2024, and by December 2025, the protocol had become the dominant choice for linking AI agents to external systems. The ecosystem now hosts more than 10,000 active public MCP servers, with backing from AWS, Google Cloud, Azure, and deployment across ChatGPT, Gemini, Microsoft Copilot, Cursor, and Visual Studio Code. Yet security solutions designed to protect these connectors remain underdeveloped.

How MCP became AI's default connector standard in about a year

The expansion of MCP has been remarkable. Anthropic's decision to release MCP as an open standard addressed a genuine market need: AI systems required a unified interface for securely connecting to multiple external tools and data sources without requiring custom connectors for each integration. This standardization removed friction from AI development and deployment. All major AI platforms and coding assistants now rely on MCP, validating it as the protocol of choice for agent-tool connections across the industry.

However, this rapid adoption introduced an expansive new attack surface that security infrastructure was not prepared to defend. Current AI security tools were not designed for scenarios in which AI agents dynamically access external tools and sensitive systems. Research demonstrates the magnitude of this gap.

What actually goes wrong when an MCP server has a weakness

The Open Worldwide Application Security Project has identified multiple critical threats targeting MCP servers. Tool poisoning represents a significant risk, extending prompt injection attacks by embedding malicious instructions within tool descriptions, schemas, or return values to alter agent behavior.

  • Rug pull attacks, specific to AI infrastructure, involve an attacker modifying a tool's definition after human approval, leveraging the trust that approval established
  • Tool shadowing and cross-origin escalation attacks allow an attacker to manipulate how an agent uses tools from a trusted server by exploiting a malicious server's tool description
  • Data exfiltration occurs when attackers covertly insert sensitive information into legitimate tool calls such as searches or emails
  • Excessive permissions create larger exposure when a server is granted more access than the task requires

These vulnerabilities are widespread. Lakera, the AI security firm acquired by Check Point in 2025, analyzed 10,000 MCP servers and discovered that 40% contained exploitable weaknesses.

Why MCP security is not the same as agent security

MCP server security is necessary but insufficient for comprehensive AI protection. Agents can access tools and data through multiple pathways beyond MCP connections. Securing MCP servers prevents tool poisoning, unauthorized access, and certain data breaches, yet agents remain capable of interacting with other systems without using MCP at all.

MCP security therefore represents one component of a larger AI security strategy. Organizations evaluating MCP server security solutions should assess them within their broader security context. Vendors should demonstrate effectiveness in securing MCP-specific interactions and risks, but additional controls remain necessary to protect the entire AI ecosystem. Integration with existing security infrastructure matters significantly.

Who is building for this gap right now

Security teams now have multiple options for addressing MCP vulnerabilities. Several vendors have developed solutions that account for MCP servers' role in AI infrastructure.

  • TrueFoundry's AI Gateway delivers governance, access control, and auditing at the infrastructure layer for interactions between MCP tools and agents
  • Cisco extended its AI Defense product to include agent-facing guardrails, MCP scanning, and real-time inspection of MCP traffic to detect and block unsafe behavior
  • Check Point's AI Network Firewall, released in July 2026, takes a network-centric approach by integrating AI security into existing firewall infrastructure, discovering MCP servers, inspecting traffic, and enforcing access policies

Security consistently lags when infrastructure scales rapidly, and MCP follows this established pattern. Organizations and vendors are currently testing different approaches—network-level firewalls with AI awareness, infrastructure-layer governance, or dedicated AI guardrails. The specific approach matters less than whether security teams close the gap before an MCP-specific attack forces action.