⟨ INCOMING TRANSMISSION ⟩ 200,000 MCP instances exposed by April 2026 security disclosure (OX Security) · 97M monthly MCP SDK downloads, up from ~2M at launch (Anthropic, Mar 2026) · RSAC 2026: $392M raised in agentic security in one week · EU AI Act fully applicable August 2026 · Microsoft (Apr 2026): MCP tool execution needs a control plane · sources: sentnelops.com/research/mcp-landscape · ⟨ INCOMING TRANSMISSION ⟩ 200,000 MCP instances exposed by April 2026 security disclosure (OX Security) · 97M monthly MCP SDK downloads, up from ~2M at launch (Anthropic, Mar 2026) · RSAC 2026: $392M raised in agentic security in one week · EU AI Act fully applicable August 2026 · Microsoft (Apr 2026): MCP tool execution needs a control plane · sources: sentnelops.com/research/mcp-landscape ·

[ TRANSMISSION // BLOG ]

We measured the MCP ecosystem.

Today we're releasing the MCP Security Index 2026: a rubric-based survey of the 50 most widely used public MCP servers — reference, vendor, and community — with the full dataset public under CC BY 4.0.

Blog/September 7, 2026·Rupam Biswal

The numbers: 48% of the surveyed servers have no per-call authorization of any kind. 92% have no hook where a policy decision could even be inserted. 58% document no audit logging. And 30% expose destructive tools — delete, execute, spend — with zero per-call authorization. Across the population we recorded 55 documented CVEs, advisories, and security write-ups, each cited in the dataset.

The full analysis, the four patterns in the data, and the method are in the summary: The MCP Security Index 2026. The dataset — CSV, JSON, rubric, per-server evidence — is at github.com/sentnelops/mcp-security-index. If you maintain one of the fifty servers and we got something wrong, corrections are welcome and attributed.

SentnelOps is an AI agent runtime governance platform — an MCP firewall giving every agent an identity, runtime policy on every tool call, and an audit-ready evidence trail. Start with the knowledge layer or log your first call in 10 minutes.

← All posts · RSS