Why MCP servers are becoming AI's newest attack surface
MCP (Model Context Protocol) became the dominant standard for connecting AI agents to external tools within 12 months of its November 2024 launch, with over 10,000 active public servers by December 2025 and support from all major cloud providers and AI platforms. The rapid adoption of MCP has created a significant security gap, with 40% of analyzed MCP servers found to carry exploitable weaknesses, including tool poisoning, rug pull attacks, and data exfiltration vectors. A new category of "AI f
Analysis
TL;DR
- MCP (Model Context Protocol) became the dominant standard for connecting AI agents to external tools within 12 months of its November 2024 launch, with over 10,000 active public servers by December 2025 and support from all major cloud providers and AI platforms.
- The rapid adoption of MCP has created a significant security gap, with 40% of analyzed MCP servers found to carry exploitable weaknesses, including tool poisoning, rug pull attacks, and data exfiltration vectors.
- A new category of "AI firewalls" is emerging to defend AI models, agents, and their tool connections from prompt injection and data leakage, distinct from traditional AI-powered network firewalls.
- MCP security is only one component of a broader AI security strategy, as agents can interact with external systems through multiple pathways beyond MCP.
- Security vendors including Check Point, Cisco, and TrueFoundry are releasing products to address MCP-specific threats, ranging from network-centric firewalls to infrastructure-layer governance and real-time traffic inspection.
Why It Matters
The explosive growth of MCP as the default connector standard for AI agents means that security infrastructure is struggling to keep pace with adoption, creating a widening vulnerability window that organizations must address. For AI practitioners and security teams, understanding these emerging threats and available defenses is critical to safely deploying agent-based systems that interact with external tools and sensitive data.
Technical Details
- MCP launched as an open standard by Anthropic in November 2024 and achieved widespread adoption by December 2025, with 10,000+ active public servers supported by AWS, Google Cloud, and Azure, and integrated into ChatGPT, Gemini, Microsoft Copilot, Cursor, and VS Code.
- Key attack vectors include tool poisoning (malicious instructions embedded in tool descriptions, schemas, or return values), rug pull attacks (post-approval modification of tool definitions), tool shadowing, and cross-origin escalation attacks, as categorized by OWASP.
- Lakera's analysis of 10,000 MCP servers revealed that 40% contained exploitable weaknesses, with additional risks around data exfiltration through covert insertion of sensitive information into legitimate tool calls and excessive permission grants.
- Emerging security solutions include Check Point's AI Network Firewall (network-centric, integrated with existing firewall infrastructure), Cisco's AI Defense extension (agent-facing guardrails and real-time MCP traffic inspection), and TrueFoundry's AI Gateway (infrastructure-layer governance, access control, and auditing).
Industry Insight
- Organizations deploying AI agents should treat MCP security as a necessary but insufficient layer, evaluating solutions within the broader context of their AI security stack and ensuring integration with existing controls.
- The "AI firewall" market is rapidly evolving with competing approaches—network-centric, infrastructure-layer, and agent-facing—requiring security teams to carefully assess which model aligns with their architecture and threat landscape.
- The 40% vulnerability rate in MCP servers signals that the ecosystem is still immature from a security perspective, and teams should prioritize scanning, monitoring, and least-privilege access policies for any MCP servers they adopt.
Disclaimer: The above content is generated by AI and is for reference only.