Businesswire Permit.io Launches MCP Gateway to Address Security Gaps in AI Agent Operations
Article Content
- •Permit.io launches MCP Gateway to enhance security for AI agents in enterprises.
- •OWASP ranks Shadow MCP Servers as a top-10 risk due to lack of authorization.
- •The MCP protocol has 97 million monthly SDK downloads, indicating rapid adoption.
Permit.io has launched the Permit MCP Gateway to address significant security gaps in the Management Control Protocol (MCP) used by AI agents in enterprise environments. These agents currently operate without fine-grained authorization, delegation tracking, or audit trails, leading to vulnerabilities. OWASP identifies Shadow MCP Servers as a top-10 risk, with incidents like Asana's data leak and a critical flaw in the mcp-remote npm package exposing unpatched systems to remote code execution. The MCP protocol has seen rapid adoption, with 97 million monthly SDK downloads, and is supported by major tech companies. The new gateway provides real-time authorization, tracks delegation chains, and ensures agents do not exceed granted permissions. It is available in both hosted SaaS and on-premises configurations. The launch comes amid growing concerns over the autonomous actions of AI agents without proper oversight.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Asana in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…