Open standards cut integration cost. They also create shared attack surfaces. MCP’s rapid adoption means a flaw or misfeature can scale across tools that look unrelated on a vendor slide. Background on the 2026 revision: MCP connectivity update.
What OX Security reported (as covered by VentureBeat)
- Thousands of servers on public IPs with STDIO transport active.
- An estimate of a much larger vulnerable population.
- High-severity CVEs across multiple agent and workflow products.
- Anthropic’s reported stance: default execution behavior as design, not a simple bug.
That disagreement helps buyers. Separate “is the protocol broken?” from “is the default deployment model safe for our threat model?”
Tool poisoning as untrusted input
Tool poisoning (Invariant Labs, widely cited in 2026 enterprise security pieces) can live in natural-language tool descriptions. An agent that trusts tool metadata can call dangerous functions. Defense is not only patching servers. Treat tool catalogs as untrusted input. Tie this to the agent-security checklist.
A 90-day remediation sequence
- Inventory every agent and MCP server with a named owner.
- Revoke shared API keys.
- Enable read-only monitoring of tool calls.
- Scan registered MCP endpoints with available scanners.
- Stage write tools behind approvals and retest with adversarial prompts.



