21,000 MCP servers exposed: the protocol reaches a security inflection point
Wpnx330
11 points
1 comment
August 16, 2026
Related Discussions
Found 5 related stories in 91.4ms across 8,687 title embeddings via pgvector HNSW
- The State of MCP Security [pdf] mavzer · 26 pts · July 12, 2026 · 68% similar
- New MCP Roadmap pentagrama · 192 pts · August 22, 2026 · 60% similar
- Show HN: Only 1 of 4,356 reachable MCP servers is ready for the 2026-07-28 spec roee_tsur · 21 pts · July 12, 2026 · 59% similar
- 24,650 internet-accessible BMCs leak password-derived hashes before login ilreb · 20 pts · July 28, 2026 · 54% similar
- Ask HN: Who is using MCP in production? sukit · 39 pts · September 03, 2026 · 54% similar
Discussion Highlights (1 comments)
Wpnx330
21,000 exposed servers with 92% lacking OAuth. The OWASP MCP Top 10 is a good start.... but it's reactive. It doesn't address the fundamental issue. There's no standard way to verify what an MCP server actually does before you connect to it. Not without studying the github repo, if one is even available. We need lockfiles, audit commands, and signed provenance, just like we got with npm.