MCP stacks have a 92% exploit probability: How 10 plugins became enterprise security's biggest blind spot

Have you heard about Anthropic’s Model Context Protocol (MCP)? It’s been touted as the fastest-adopted AI integration standard in 2025. But did you know that the same connectivity that made it so popular has also created a dangerous blind spot in enterprise cybersecurity?

A recent study by Pynt sheds light on the growing threat posed by MCP. The analysis reveals that the more MCP plugins are used, the higher the risk of exploitation. In fact, deploying just ten MCP plugins can result in a staggering 92% probability of exploitation. And with three interconnected servers, the risk exceeds 50%. Even a single MCP plugin presents a 9% exploit probability, which increases exponentially with each additional plugin.

Unpacking the Security Paradox of MCPs

Anthropic’s MCP was designed to streamline AI integration, providing a universal interface for AI agents to access a wide range of tools and data sources. The protocol gained rapid adoption, with major players like Google and Microsoft onboard. However, the protocol’s strength in seamless connectivity is also its weakness, as security was not a core design consideration. Authentication and authorization frameworks were only recently introduced, leaving many MCP servers vulnerable to attacks.

According to Merritt Baer, Chief Security Officer at Enkrypt AI, the lack of secure defaults in MCP is a common pitfall in major protocol rollouts. Without proper authentication and least privilege controls, organizations could be dealing with breaches for years to come.

Source: Pynt, Quantifying Risk Exposure Across 281 MCPs Report

Understanding Compositional Risk: Where Security Falters at Scale

Pynt’s analysis of 281 MCP servers highlights the intersection of vulnerabilities that expose sensitive capabilities and accept untrusted inputs. When these risks converge, attackers gain direct pathways to execute commands and extract data, often without detection. These vulnerabilities are not theoretical but real threats lurking within everyday MCP configurations.

Idan Dardikman, CTO at Koi Security, warns about the dangers of compromised MCP servers, emphasizing the need for heightened vigilance and thorough audits to mitigate risks.

Source: Pynt, Quantifying Risk Exposure Across 281 MCPs Report

Real-World Exploits Highlight MCP’s Vulnerabilities

Security research teams have identified several real-world exploits targeting MCP, including critical vulnerabilities like CVE-2025-6514 and the Postmark MCP Backdoor. These exploits demonstrate the urgent need for robust security measures to protect against malicious attacks.

Additional vulnerabilities include prompt injection attacks, tool poisoning, authentication weaknesses, and supply chain attacks through compromised npm packages. Organizations utilizing MCP must remain vigilant and proactive in addressing these vulnerabilities.

Addressing the Authentication Gap in MCP

Authentication and authorization were initially optional in MCP, leading to widespread vulnerabilities. Organizations are urged to implement OAuth 2.1 and enforce access controls to mitigate risks. Gartner’s research underscores the importance of securing MCP gateways to prevent vulnerabilities and ensure centralized monitoring.

Developing a Comprehensive MCP Defense Strategy

To enhance security around MCP, organizations should focus on implementing layered security measures, semantic layers, and knowledge graphs. These steps help reduce the threat surface and strengthen defenses against potential attacks. Regular audits, threat modeling, and red-teaming are essential practices to maintain a secure MCP environment.

Key Recommendations for Security Leaders

Security leaders are advised to take proactive measures to secure their MCP infrastructure, including enforcing OAuth 2.1, implementing layered security architectures, conducting regular audits, limiting plugin usage, and investing in AI-specific security measures. By following these recommendations, organizations can mitigate the risks associated with MCP integration and safeguard their AI ecosystems.

Leave a Reply

Your email address will not be published. Required fields are marked *