Skip to content
AI-Powered Vulnerability Sweep Reveals 15,000 Flaws in MCP Servers

AI-Powered Vulnerability Sweep Reveals 15,000 Flaws in MCP Servers

First seen 28 May 2026, 15:18 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 29, 2026 at 14:59 UTC
  • Over 15,000 vulnerabilities identified in 19,000 MCP servers.
  • 8.3% of analyzed repositories showed AI bot activity, indicating AI's role in code development.
  • The research utilized advanced AI tools to assess and refine vulnerability findings.

A recent Trendmicro report identified over 15,000 vulnerabilities across 19,000 open-source MCP servers, with a significant portion potentially influenced by AI-generated code. The research utilized a Gemini-powered AI agent to analyze repository metadata and source code traits. Initial scans flagged 17,558 vulnerabilities, later refined to 15,000 after removing false positives. A manual review of 438 selected vulnerabilities confirmed their status. The analysis highlighted a growing trend in AI bot activity on GitHub, with 8.3% of MCP repositories showing such activity. This situation raises concerns about the security and reliability of AI-assisted code development, as the presence of vulnerabilities could impact a wide range of applications relying on these servers.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 104d ago How this analysis works

Timeline

2025-01-01
Rapid growth of MCP servers observed
Over 19,000 open-source MCP server repositories were identified in a few months, raising concerns about security.
Trendmicro
2025-10-01
GitHub AI bot operations surge
AI bot operations on GitHub increased from 175,996 to over 1 million events, indicating a rise in AI-assisted coding.
Trendmicro
2026-05-28
Vulnerability analysis published
Trendmicro published findings of a vulnerability sweep revealing over 15,000 flaws in MCP servers.
Trendmicro

More articles in this cluster (3)