Infosecurity-Magazine MCP Servers Expose Organizations to Governance Gaps and Security Risks
Article Content
- •15.6% of analyzed MCP servers connect to infrastructure outside the US.
- •2.3% of hostnames are unregistered, posing domain takeover risks.
- •Granting 'always-allow' permissions can lead to unauthorized file access.
Research from Ox Security reveals that Model Context Protocol (MCP) servers are creating significant governance gaps in enterprise cybersecurity as AI deployments increase. The analysis of 15,465 MCP servers found that 15.6% of unique hostnames resolved to infrastructure outside the US, including in China and Russia, posing data residency risks. Additionally, 2.3% of hostnames failed to resolve, with some being unregistered and available for purchase, which could allow for domain takeover. Testing showed that granting an 'always-allow' permission to a malicious MCP server enabled unauthorized access to sensitive files without further user confirmation. The report highlights that MCP lacks a protocol-level mechanism to enforce geographic data processing controls, exposing organizations to vulnerabilities. Previous findings indicated severe flaws in MCP servers, including unchecked input handling and excessive permissions. The situation is compounded by the architectural design decisions in MCP SDKs that may lead to arbitrary command execution vulnerabilities. The urgency of addressing these issues is underscored by the potential for exploitation and the lack of governance in AI workflows.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…