Why MCP Servers Are Becoming AI's Newest Attack Surface
40% of MCP servers carry exploitable weaknesses—security tools haven't kept pace with the protocol's 12-month rise to dominance.
- 01MCP became the default connector between AI agents and external tools faster than almost any infrastructure standard in recent memory, now embedded across every major coding assistant and LLM platform.
- 02That velocity created an attack surface security teams aren't equipped to defend.
- 03OWASP documents novel threat classes—tool poisoning, rug pull attacks, cross-origin escalation—while a review of 10,000 servers found 40% exploitable.
- 04Vendors are rushing AI-native firewalls to market, but MCP security alone won't cover every agent interaction pathway.
40% of MCP servers carry exploitable weaknesses—security tools haven't kept pace with the protocol's 12-month rise to dominance.
MCP became the default connector between AI agents and external tools faster than almost any infrastructure standard in recent memory, now embedded across every major coding assistant and LLM platform. That velocity created an attack surface security teams aren't equipped to defend. OWASP documents novel threat classes—tool poisoning, rug pull attacks, cross-origin escalation—while a review of 10,000 servers found 40% exploitable. Vendors are rushing AI-native firewalls to market, but MCP security alone won't cover every agent interaction pathway.
Watch: whether emerging 'AI firewall' vendors expand MCP coverage into full agent-interaction monitoring, or remain narrowly scoped as attackers probe adjacent vectors.
As AI adoption gathers pace, so does the evolution of the infrastructure that supports it. New standards and connectors keep appearing, and the ones that catch on spread through the ecosystem within months rather than years. That speed strengthens what AI can do, but makes it very difficult for security teams to maintain sufficient protections. MCP servers are a prime example. MCP became the preferred standard for connecting AI agents to outside tools and data within 12 months of publication, and by December 2025 were being used by every major coding assistant and most leading LLMs. As a protocol, MCP has grown faster than most infrastructure standards, a rarity in the high-competition LLM space. This adoption curve validated MCP as Anthropic’s protocol of choice for agent-tool connections, but security solutions aren’t keeping up. A number of cybersecurity vendors are building products to close that gap. Many of them describe what they’re building as an “AI firewall,” but that term is doing double duty right now. One meaning is an older, AI-powered firewall that defends a network against conventional threats like malware and intrusion. The other, newer meaning, and the one we’ll focus on here, is a firewall built specifically to defend AI itself: its models, agents, and the tools they connect to, from threats like prompt injection and data leakage. Check Point’s AI Network Firewall, released in July 2026, belongs to this second category. Nowhere is the need for AI firewalls more visible right now than with MCP servers, the connectors that let AI agents reach outside tools and data, and the fastest-growing piece of AI infrastructure that this type of firewall now has to contend with. How MCP became AI’s default connector standard in about a year The growth of MCP servers has been astonishing. Anthropic launched MCP as an open standard in November 2024. In December 2025, Anthropic announced that more than 10,000 active public MCP servers were now running, with deployment support from AWS, Google Cloud, Azure, and other providers. All the leading AI platforms and coding assistants, including ChatGPT, Gemini, Microsoft Copilot, Cursor and Visual Studio Code, now use MCP. This rapid growth is largely due to the real need for a standardised connection between AI systems and external tools and data. The key advantage of an MCP server is that it allows AI agents, assistants, and coding tools to use a single interface to connect securely with multiple tools and data sources, instead of needing a custom connector. But MCP brought a whole new attack surface along with these advantages, at a speed that vastly outpaces any supporting security network. Existing AI defenses aren’t built for situations where AI agents dynamically access tools and sensitive systems, and as we’ll see, research findings show just how big that gap actually is. What actually goes wrong when an MCP server has a weakness OWASP, the Open Worldwide Application Security Project, has specified a number of serious threats that can affect MCP servers . Tool poisoning is a chief concern, taking prompt injection up a level by embedding malicious instructions in tool descriptions, schemas, or tool return values and using them to manipulate agent behaviour. Rug pull attacks are unique to the emerging AI ecosystem. Here, an attacker changes a tool’s definition after a human has already approved it, exploiting the trust that approval created. Tool shadowing and cross-origin escalation attacks work similarly, with an attacker using a malicious server’s tool description to manipulate how an agent uses tools belonging to another, trusted server. These vulnerabilities are not rare, either. An analysis conducted by Lakera, the AI security company Check Point acquired in 2025, reviewed 10,000 MCP servers and found that 40% carried exploitable weaknesses . Other threats are familiar but made more sinister. Attackers use MCP servers for data exfiltration by covertly inserting sensitive information into otherwise legitimate tool calls like searches and emails. Or they exploit the server’s broader permissions by granting it more access than the task really needs, creating a larger exposure. Why MCP security is not the same as agent security While MCP security is vital, it’s not the whole picture. Connecting through MCP servers is just one of many ways that AI agents can reach the tools and data they need. Securing them goes a long way towards preventing tool poisoning, unauthorised access, and data breaches, but it’s not enough on its own. Agents can still interact with other systems without using MCP at all. This makes MCP security just one thread in a broadly woven AI security tapestry. When you consider vendors for an MCP server security solution, you need to look at them within the greater context. It’s important to evaluate how effectively they secure MCP-specific interactions and risks, but you’ll still need additional controls to protect your AI ecosystem, so check how well the solution integrates with the rest of your security stack. Who is building for this gap right now The good news is that security teams have options. A number of companies offer security solutions that include MCP servers and bear in mind their role in AI infrastructure. TrueFoundry’s AI Gateway provides infrastructure-layer governance, access control, and auditing for interactions between MCP tools and agents. Cisco has extended its AI Defense product to include agent-facing guardrails, MCP scanning, and real-time inspection of MCP traffic, designed to detect and block unsafe behavior. Check Point’s AI Network Firewall takes a different approach. Its offering is network-centric, stitching AI security into its customers’ existing firewall infrastructure. The firewall addresses employee, AI application, and AI agent interactions with MCP as well as other connections between AI systems and external data and tools. It discovers MCP servers, inspects MCP traffic, and enforces policies around agent access. Security tends to lag whenever infrastructure scales this fast, and MCP is following the same pattern. We’re currently seeing vendors and organisations trying out different solutions to an emerging problem, whether that’s an AI-aware network-level firewall, infrastructure-level governance, or dedicated AI guardrails. Which approach wins out matters far less than whether security teams close that gap before an MCP-specific attack forces the issue. The post Why MCP servers are becoming AI’s newest attack surface appeared first on AI News .
Don't miss tomorrow's
The Daily Pulse in your inbox each morning — sourced and linked.
CFO peer benchmarks
Margins, FCF conversion, ROIC, and the working-capital cycle (DSO/DPO/DIO/CCC), percentile-ranked against sector peers.
Executive Briefing Studio
Assemble a company-specific, persona-framed executive deck from the site's own intelligence.
Ask KokoAI about AI
Cited answers across news, vendors & capabilities.