Skip to content
MCP Servers Expose Organizations to Governance Gaps and Security Risks

MCP Servers Expose Organizations to Governance Gaps and Security Risks

First seen 28 Sep 2026, 11:03 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 11:04 UTC
  • •15.6% of analyzed MCP servers connect to infrastructure outside the US.
  • •2.3% of hostnames are unregistered, posing domain takeover risks.
  • •Granting 'always-allow' permissions can lead to unauthorized file access.

Research from Ox Security reveals that Model Context Protocol (MCP) servers are creating significant governance gaps in enterprise cybersecurity as AI deployments increase. The analysis of 15,465 MCP servers found that 15.6% of unique hostnames resolved to infrastructure outside the US, including in China and Russia, posing data residency risks. Additionally, 2.3% of hostnames failed to resolve, with some being unregistered and available for purchase, which could allow for domain takeover. Testing showed that granting an 'always-allow' permission to a malicious MCP server enabled unauthorized access to sensitive files without further user confirmation. The report highlights that MCP lacks a protocol-level mechanism to enforce geographic data processing controls, exposing organizations to vulnerabilities. Previous findings indicated severe flaws in MCP servers, including unchecked input handling and excessive permissions. The situation is compounded by the architectural design decisions in MCP SDKs that may lead to arbitrary command execution vulnerabilities. The urgency of addressing these issues is underscored by the potential for exploitation and the lack of governance in AI workflows.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-24
Ox Security report published
Ox Security released a report analyzing 15,465 MCP servers, highlighting governance gaps and security risks.
Ox.Security
2026-09-28
Infosecurity Magazine coverage
Infosecurity Magazine reported on Ox Security's findings, emphasizing the risks posed by MCP servers.
Infosecurity-Magazine

More articles in this cluster (2)