AI Technology

143,000 Vulnerabilities, One Weekend of Scanning: The MCP Security Wake-Up Call

MCP security illustration of AI agents connecting to vulnerable server nodes
MCP security got a hard number this week: vulnerabilities in 73% of scanned servers.

MCP security has a number attached to it now, and it is not a reassuring one. In the two months leading up to August 4, 2026, security firm Enkrypt AI scanned more than 268,000 individual tools across 25,000 live Model Context Protocol servers, the connectors that let AI agents call external functions and data sources, and found more than 143,000 vulnerabilities affecting 73 percent of the servers scanned. That figure became public the same day data science platform Anaconda announced it was acquiring Enkrypt AI outright, folding the startup’s red-teaming and runtime guardrail technology directly into its enterprise AI platform.

The timing was not incidental. It is the clearest quantified evidence yet for a warning security researchers have been repeating for the better part of a year: enterprises are wiring AI agents into their infrastructure faster than anyone is checking whether the connections those agents rely on are actually secure.

What the MCP Security Numbers Actually Measure

Anaconda’s own announcement of the acquisition frames the scale of the problem plainly: every model an AI agent runs on, every tool it calls, and every MCP server it touches introduces a potential attack vector, and unlike a conventional software vulnerability, there is no single patch for an exposure that was never fully understood in the first place. Model Context Protocol, the open standard that lets AI agents discover and call external tools, has become the default plumbing connecting agentic AI systems to databases, internal APIs, and third-party services since its release in late 2024.

The 25,000 servers Enkrypt AI scanned represent a meaningful slice of that rapidly expanding ecosystem, and a 73 percent vulnerability rate across servers already in live production use, not test environments, is the detail that turns an abstract security concern into a concrete, current exposure.

David DeSanto, Anaconda’s CEO, put the underlying problem directly: “Enterprises are running AI-native applications and services that already contain exploitable vulnerabilities and weaknesses, leaving them exposed to unknown risks they cannot easily address,” he said. Sahil Agarwal, Enkrypt AI’s co-founder and CEO, framed the fix as a matter of sequencing rather than bolt-on security: trust cannot be added to an agent after it ships, in his words, it has to be built into a trusted foundation from the start.

How This Fits the Pattern of Recent MCP Security Incidents

The Enkrypt AI findings do not exist in isolation. LiveAIWire’s coverage of the agentic AI attack that breached Hugging Face’s production infrastructure in July documented an autonomous AI agent exploiting a code-execution vulnerability in a dataset processing pipeline to escalate access and move laterally across internal systems over a single weekend, generating more than 17,000 individually logged malicious actions before it was contained. That incident was not itself an MCP-specific breach, but it demonstrated exactly the failure mode Enkrypt AI’s scan quantifies at scale: the connective tissue linking AI agents to real infrastructure is being deployed faster than the security review it requires.

That same Hugging Face incident is part of why Nvidia assembled a 40-plus-member coalition to build shared open-source AI defence tooling in late July. LiveAIWire’s reporting on the Nvidia-led Open Secure AI Alliance found the coalition explicitly framed around the same gap: agents are gaining autonomy faster than the tools needed to audit, test, and govern them are maturing, and closed, single-vendor security platforms cannot keep pace with an attack surface expanding this quickly on their own. The Anaconda-Enkrypt deal is, in effect, a second and separate answer to the same problem the Nvidia alliance was built to address, arriving from a different part of the AI infrastructure stack.

Why Attackers Have an Edge Enterprises Do Not

The MCP security gap also connects to a wider imbalance LiveAIWire has tracked in state-sponsored AI-enabled cyber operations. Our coverage of AI espionage and the GTG-1002 campaign, in which an AI agent reportedly executed the large majority of a state-sponsored intrusion autonomously, found that offensive AI operations benefit disproportionately from full autonomy in a way defensive AI struggles to match, because an attacker operating with no usage policy or safety guardrail can move through an unaudited MCP server or tool connection in ways a defensively deployed agent, built to respect guardrails and human oversight, cannot exploit back.

Enkrypt AI’s scan results give that structural asymmetry a concrete number: nearly three-quarters of the connective infrastructure enterprises have already deployed contains vulnerabilities a sufficiently motivated attacker could plausibly find first.

What an MCP Vulnerability Actually Looks Like

The abstraction of a 143,000-vulnerability count is easy to skim past without registering what it means in practice. Anaconda’s announcement lays out concrete failure scenarios rather than leaving the risk theoretical: a manipulated image or document can redirect an agent’s tool calls without anyone noticing, a spoofed voice input can trigger an approval that was never meant to be given, and a single bad instruction fed into an unaudited tool chain can cascade into a wire transfer, a further attack on another company’s systems, or a decision nobody can later account for in an audit trail.

None of these require a sophisticated nation-state actor. They require an MCP server whose tool permissions were never properly scoped, connected to an agent that trusts whatever that server tells it.

That is the specific gap between MCP security as a compliance checkbox and MCP security as an operational discipline. A server can pass a cursory review, be technically reachable, and still hand an agent far broader tool access than the task in front of it actually requires, the same over-permissioning problem that has caused breaches in conventional cloud infrastructure for years, now reproduced at the speed and scale agentic AI operates at.

What This Means for You

If your organisation has deployed any AI agent that calls external tools, whether through MCP specifically or an equivalent agent-to-tool protocol, the practical takeaway from these numbers is not to wait for a vendor’s reassurance before checking your own exposure. Enkrypt AI’s own recommended baseline, pre-deployment red-teaming across established attack categories before an agent goes live and runtime guardrails that operate inside an organisation’s own environment rather than depending entirely on a hosted provider’s safety layer, reflects what security teams that have already been burned by this gap have converged on independently.

The compliance dimension adds urgency for regulated industries specifically. Enkrypt AI’s tooling is built to translate frameworks including the NIST AI Risk Management Framework and the EU AI Act, whose high-risk AI provisions took effect August 2, into automated, enforceable controls rather than a manual audit exercise conducted after the fact. For a board or compliance team currently unable to answer a straightforward question, whether the AI agents already running in production have been checked for exactly this category of exposure, that gap is no longer a theoretical governance concern. It is now a quantified one, and the number attached to it is not small.

The Acquisition Itself Is Part of the Story

Anaconda’s purchase of Enkrypt AI is its third acquisition in as many months, following deals for Outerbounds and the coding agent Kilo Code, and the pattern reveals a company building a single governed pipeline spanning AI development, orchestration, and now runtime security. Whether that consolidation genuinely closes the gap Enkrypt AI’s own numbers describe, or simply moves the unaudited risk from a fragmented vendor landscape into a single larger one, is the question enterprise security teams evaluating the platform will need to answer for themselves.

What the underlying scan data makes clear regardless of which vendor ultimately addresses it is that the gap exists today, at a scale too large to treat as a rounding error in anyone’s AI rollout plan.

About the Author

Stuart Kerr is Technology Correspondent at LiveAIWire, covering artificial intelligence, cybersecurity, and the social impact of emerging technology. He publishes daily at LiveAIWire.com.