Blog

/Research

State of MCP 2026

About 40,000 servers in the official registry, ~0.5B SDK downloads a month, 12,520 exposed services and a stateless spec. The state of MCP in 2026, in data.

·14 min read

Summarize in ChatGPT
State of MCP 2026 cover: monthly official Python and TypeScript SDK downloads rising from 29K in Nov 2024 to a 545M peak in Aug 2026 and 464M in Sep 2026, with tiles for ~0.5B monthly SDK downloads, ~40K servers in the official MCP Registry, 12,520 internet-reachable MCP services (Censys) and 5 spec revisions.
On this page

In November 2024 Anthropic open-sourced the Model Context Protocol, a way for AI assistants to call tools and read data from other systems, with a handful of reference servers for Google Drive, Slack, GitHub and Postgres. Not quite two years later OpenAI, Google, Microsoft and AWS all ship it, the protocol belongs to a Linux Foundation fund, and in July its maintainers rewrote the core in what they call the largest revision of the protocol since launch.

Most MCP coverage is either a launch announcement or an "MCP is dead" take. We wanted the numbers in between: how big the ecosystem really is, where servers run, what they cost in context, how often they get attacked, and who is paying for all of it. So we pulled the public data ourselves (the official registry API, npm and PyPI download counts, directory snapshots), collected the security scans and vendor statements, and checked them. Vendor and security-vendor figures are their own claims and are labelled that way, and every number below links to its source.

Key findings

  1. 1
    The spec has had five revisions, and the 2026-07-28 one made MCP stateless: no handshake, no sessions, and a remote server that is "no different from any other HTTP workload". Roots, Sampling, Logging and Dynamic Client Registration were deprecated with a 12-month runway.
  2. 2
    The official MCP Registry lists about 40,000 servers (40,047 in our count of its public API on 6 Oct 2026), roughly 20 times the "close to two thousand" it had in November 2025. Quantity isn't quality: the top 10 publishers account for 18.7% of entries, and the registry is still in preview.
  3. 3
    The official Python and TypeScript SDKs are downloaded about half a billion times a month by our count (545M at the August 2026 peak, 464M in September), in line with the MCP blog's "close to half-a-billion". Both doubled in a single month, February to March 2026. Downloads are not users.
  4. 4
    Remote is now the default: 62.8% of registry entries offer a hosted endpoint, against 40.9% that ship an installable package.
  5. 5
    Context cost is the live fight. Anthropic measured 55K tokens for five servers' tool definitions, fixes like tool search and code execution cut 85% to 99.9%, and GitHub swapped its own MCP server for the gh CLI for data fetching in its agentic workflows.
  6. 6
    Exposure is growing faster than the fixes ship. Trend Micro's count of unauthenticated servers nearly tripled to 1,467 in nine months, Censys found 12,520 internet-reachable MCP services, 89.4% of them on the March 2025 protocol, and two MCP flaws reached CISA's exploited-vulnerabilities list in 2026.
  7. 7
    Money is flowing to the layer around the protocol: gateways, identity and hosting. Eight disclosed rounds add up to about $211M, Arcade bought Smithery, one of the big public registries, and Snowflake agreed to buy Natoma.
  8. 8
    Nobody publishes how many MCP tool calls actually happen. Downloads, server counts and scans are all proxies.

~40,000

Servers in the official MCP Registry, our count, 6 Oct 2026

40,047 unique names

Source: Registry API

~0.5B

Monthly downloads of the official Python + TypeScript SDKs, Jul–Sep 2026

Our computation

Source: npm and PyPI; MCP blog

12,520

Internet-reachable MCP services, Apr 2026

Vendor scan

Source: Censys

5

Spec revisions; the latest, 2026-07-28, is stateless

Source: MCP blog

The spec went stateless#

MCP has shipped five dated revisions of its specification. The first three were about filling gaps. 2025-03-26 added an OAuth 2.1 authorization framework and replaced the original HTTP+SSE transport with Streamable HTTP. 2025-06-18 made servers OAuth resource servers, required clients to bind tokens to a single server, banned servers from passing a client's token through to upstream APIs, and removed JSON-RPC batching only three months after adding it. 2025-11-25, released on the protocol's first anniversary, added experimental Tasks for long-running work and a new way for clients to register, and stayed backward compatible.

The 2026-07-28 revision is a different kind of release. In the maintainers' words, "MCP is transforming from a bidirectional stateful protocol into a request/response stateless protocol." The initialize handshake and the session header are gone. Every request carries Mcp-Method and Mcp-Name headers, so a gateway or rate limiter can route on headers instead of parsing JSON bodies. Servers that need more input from the user now answer with a "multi round-trip" result instead of holding a stream open, list results carry cache hints, and Roots, Sampling and Logging are deprecated but guaranteed to keep working for at least twelve months. Cloudflare's summary is the shortest: "MCP is now a fully stateless protocol."

Five spec revisions and the road to a stateless protocol

Spec releases and governance milestones, Nov 2024 to Aug 2026

  1. 5 Nov 2024

    First revision, 2024-11-05

    stdio and HTTP+SSE transports.
  2. 25 Nov 2024

    Anthropic open-sources MCP

    With reference servers for Google Drive, Slack, GitHub, Git, Postgres and Puppeteer.
  3. 26 Mar 2025

    Revision 2025-03-26

    OAuth 2.1, Streamable HTTP replaces HTTP+SSE, tool annotations.
  4. 18 Jun 2025

    Revision 2025-06-18

    Servers become OAuth resource servers; token passthrough banned; batching removed.
  5. 8 Sep 2025

    Official registry in preview

    An open catalog and API for public MCP servers.
  6. 25 Nov 2025

    Revision 2025-11-25

    Experimental Tasks, client ID metadata documents, formal governance.
  7. 9 Dec 2025

    MCP joins the Linux Foundation

    Donated to the Agentic AI Foundation, co-founded by Anthropic, Block and OpenAI.
  8. 26 Jan 2026

    MCP Apps, the first official extension

    Interactive UI in ChatGPT, Claude, Goose and VS Code.
  9. 28 Jul 2026

    Revision 2026-07-28: stateless

    No handshake or sessions; extensions framework; DCR, Roots, Sampling and Logging deprecated.
  10. 22 Aug 2026

    New roadmap

    Five priority areas, including progressive tool discovery and agent identity. No date for the next revision.
Three revisions in 2025, then an eight-month gap before the biggest one. The transport working group had pencilled in June 2026; it shipped on 28 July.

Sources: MCP specification changelogs; MCP blog; Anthropic

What each spec revision changed

Headline changes per revision, from the official changelogs, 2024 to 2026

RevisionTransport and coreAuthorizationAddedRemoved or deprecated
2024-11-05stdio, HTTP+SSENone in the specBase protocol—
2025-03-26Streamable HTTPOAuth 2.1 frameworkTool annotations, batching, audioHTTP+SSE replaced
2025-06-18Streamable HTTPServers are OAuth resource servers; RFC 8707 requiredStructured output, elicitation, resource linksBatching removed
2025-11-25Streamable HTTPClient ID metadata documents; incremental consentExperimental Tasks, sampling with tools—
2026-07-28Stateless: no handshake, no sessions; routing headersIssuer validation (RFC 9207)Extensions framework; Tasks as an extensionRoots, Sampling, Logging, HTTP+SSE, Dynamic Client Registration
Authorization changed in every revision after the first. The 2026 release is the first to remove core features on a published deprecation schedule.

Sources: 2025-03-26 changelog; 2025-06-18 changelog; 2025-11-25 changelog; 2026-07-28 changelog

Governance grew up alongside the spec. In December 2025 Anthropic donated MCP to the Agentic AI Foundation, a directed fund under the Linux Foundation co-founded with Block and OpenAI and supported by Google, Microsoft, AWS, Cloudflare and Bloomberg. The foundation reached 247 members in August 2026, with Alibaba, Visa and Wells Fargo joining at the Gold tier. At its first anniversary the project counted 58 maintainers around a core group of nine, and 2,900+ contributors on Discord. The four Tier 1 SDKs (TypeScript, Python, Go and C#) spoke 2026-07-28 on release day; by 6 October the SDK page listed six Tier 1 SDKs, adding Rust and Ruby.

Adoption in numbers#

SDK downloads#

The cleanest public signal of developer activity is how often the official SDKs get installed. We summed daily npm counts for @modelcontextprotocol/sdk and PyPI counts for mcp (from the public ClickHouse PyPI dataset, cross-checked against pypistats) for every month since launch. In November 2024 the two together were downloaded 28,508 times. In August 2026 they were downloaded 545.5 million times, and over July to September they averaged about 509 million a month. That matches the MCP blog's statement in July of "close to half-a-billion downloads a month" across its Tier 1 SDKs, with TypeScript and Python each past a billion in total, and Anthropic's 97M+ a month in December 2025, when our count was 91.8M for November and 100.7M for December.

Monthly downloads of the official MCP SDKs

Python SDK (PyPI mcp) and TypeScript SDK (npm @modelcontextprotocol/sdk), downloads per month, Nov 2024 to Sep 2026

Monthly downloads of the official MCP SDKs
Seriesxy
PythonNov 202414.7K
PythonDec 202483.4K
PythonJan 2025146.1K
PythonFeb 2025317.9K
PythonMar 20251.5M
PythonApr 20253.5M
PythonMay 20258M
PythonJun 202510.8M
PythonJul 202517.9M
PythonAug 202533.3M
PythonSep 202548.4M
PythonOct 202549.5M
PythonNov 202556.7M
PythonDec 202562.2M
PythonJan 202668.9M
PythonFeb 202685.7M
PythonMar 2026170.9M
PythonApr 2026241.9M
PythonMay 2026285.4M
PythonJun 2026281.3M
PythonJul 2026319.3M
PythonAug 2026328.1M (peak)
PythonSep 2026231.7M
TypeScriptNov 202413.8K
TypeScriptDec 2024102.9K
TypeScriptJan 2025176.5K
TypeScriptFeb 2025350.9K
TypeScriptMar 20251.9M
TypeScriptApr 20254.2M
TypeScriptMay 202520.9M
TypeScriptJun 202516.8M
TypeScriptJul 202521.6M
TypeScriptAug 202524.7M
TypeScriptSep 202531.3M
TypeScriptOct 202533.8M
TypeScriptNov 202535M
TypeScriptDec 202538.5M
TypeScriptJan 202650.2M
TypeScriptFeb 202671.7M
TypeScriptMar 2026141.9M
TypeScriptApr 2026140.1M
TypeScriptMay 2026153.2M
TypeScriptJun 2026165.2M
TypeScriptJul 2026198.9M
TypeScriptAug 2026217.3M
TypeScriptSep 2026231.9M
Both lines doubled between February and March 2026. Python's late-August drop is one large automated consumer changing, most likely, not a fall in adoption; by September the two SDKs were level at about 232M each.

Sources: npm downloads API; pypistats; ClickHouse public PyPI dataset; host0 computation, 6 Oct 2026

Two jumps in the series need explaining, and we can only partly explain them. Between February and March 2026 both SDKs doubled in a single month: TypeScript from 71.7M to 141.9M, Python from 85.7M to 170.9M. Then on 25 August Python's daily count fell from around 13M on weekdays to 7–8M and stayed there, so September came in 29% below August. A step that sharp, on one package only, looks like one large automated consumer (a CI system, or an agent product that bundles the SDK) changing how it installs, not thousands of developers leaving. That's the general caveat for this chart: registry downloads count CI runs, transitive installs and bundled copies, not people. Over a year the growth is still large, 7.4× for TypeScript and 4.8× for Python from September 2025 to September 2026.

Surveys agree that awareness ran ahead of use. In Postman's 2025 State of the API report (over 5,700 respondents), 70% of developers were aware of MCP but only 10% used it regularly.

Servers: the registry and the directories#

There are several ways to count MCP servers, and they measure different things. The official MCP Registry, backed by Anthropic, GitHub, PulseMCP and Microsoft, is where publishers register servers under a verified namespace. We paged through its entire public API on 6 October 2026 (401 pages of version=latest, deduplicated by server name) and counted 40,047 servers: 39,565 active and 482 deprecated, from 23,818 distinct namespaces. In November 2025 the maintainers said it had "close to two thousand entries", so that's roughly twentyfold growth in ten months.

That figure needs two qualifiers. First, the registry is still in preview and verifies namespaces, not code. Second, a few publishers account for a lot of it: the 10 largest namespaces hold 18.7% of all entries, and one GitHub account alone has 2,365. The "10,000+ servers" often quoted from December 2025 is a different number again: Anthropic's estimate of active public servers across the ecosystem, made when the registry held about 2,000.

Servers listed by MCP directories

Listed servers by directory and date, Dec 2024 to Oct 2026

Servers listed by MCP directories
Seriesxy
Glama9 Mar 20251.4K
Glama3 Jun 20255.4K
Glama10 Sep 20259.1K
Glama2 Nov 202510.8K
Glama28 Jan 202617.3K
Glama4 Apr 202620.9K
Glama1 Jun 202629.9K
Glama8 Jul 202652.5K
Glama6 Oct 202697K
Official registry25 Nov 20252K
Official registry6 Oct 202640K
PulseMCP19 Dec 2024270
PulseMCP19 Feb 20251.1K
PulseMCP4 May 20254.1K
PulseMCP11 Aug 20255.4K
PulseMCP4 Dec 20256.9K
PulseMCP7 Mar 20268.6K
PulseMCP25 Apr 202613.4K
PulseMCP28 Jun 202620.1K
PulseMCP6 Oct 202621.7K
Three directories, three definitions: Glama lists every repository that looks like a server, PulseMCP curates, and the official registry holds what publishers register. Don't add them up. The registry's November 2025 point is the maintainers' “close to two thousand”.

Sources: MCP Registry API; MCP blog (Nov 2025); Glama; PulseMCP; Wayback Machine snapshots

The registry's own timestamps show how recent most of this activity is. For each server we took the month its latest version was published. More than a third of all entries, 14,456, were last published in September 2026 alone.

When registry servers were last published

Official MCP Registry entries by month of their latest version, Sep 2025 to 6 Oct 2026

When registry servers were last published
LabelValue
Sep 2025347
Oct 2025227
Nov 2025142
Dec 2025208
Jan 2026293
Feb 2026903
Mar 20261,535
Apr 20261,672
May 20262,125
Jun 20262,649
Jul 20264,121
Aug 20266,665
Sep 202614,456
Oct 20264,704 (1–6 Oct)
This counts each server once, at its most recent version, so it shows activity rather than first listings. The highlighted September spike is consistent with bulk and automated publishing.

Sources: MCP Registry API; host0 count, 6 Oct 2026

Clients#

On the client side, adoption was close to complete within a year. Cursor added MCP in January 2025. OpenAI adopted it in March, Google in April, and Microsoft and GitHub joined the steering committee in May. By the time the stateless spec shipped, AWS, Cloudflare, Google Cloud and Microsoft Foundry supported it on day one. A few vendors have shared usage: Honeycomb says nearly 20% of its monthly interactive queries are now made by agents, and Cloudflare says its MCP hosting has served billions of tool calls.

Who shipped MCP, and when

Client and platform adoption milestones, Nov 2024 to Jul 2026

  1. 25 Nov 2024

    Claude Desktop

    Launch partners include Block, Apollo, Zed, Replit, Codeium and Sourcegraph.
  2. 30 Jan 2025

    Cursor

    MCP support in version 0.45.
  3. 26 Mar 2025

    OpenAI Agents SDK

    Sam Altman: “people love MCP”.
  4. 9 Apr 2025

    Google Gemini

    Models and SDK to support MCP.
  5. 1 May 2025

    Claude.ai remote servers

    Integrations with 10 launch partners.
  6. 19 May 2025

    Windows 11, GitHub, Microsoft

    Windows embraces MCP; GitHub and Microsoft join the steering committee.
  7. 21 May 2025

    OpenAI Responses API

    Any remote MCP server; OpenAI joins the steering committee.
  8. Jul 2025

    VS Code

    MCP generally available in v1.102.
  9. 9 Sep 2025

    ChatGPT developer mode

    A full MCP client, read and write.
  10. 6 Oct 2025

    ChatGPT Apps SDK

    Built on MCP, pitched at 800M+ ChatGPT users.
  11. 10 Dec 2025

    Google managed servers

    Fully managed remote MCP servers for Google services; 50+ by April 2026.
  12. 28 Jul 2026

    Stateless spec, day one

    AWS, Cloudflare, Google Cloud and Microsoft Foundry support 2026-07-28 at release.
OpenAI, Google and Microsoft all adopted MCP within six months of launch. The second year was about remote servers and distribution, not new clients.

Sources: Anthropic; TechCrunch; OpenAI; VS Code; Google Cloud; MCP blog

Remote is now the majority#

MCP started as a local protocol: a client launched a server as a subprocess and talked to it over stdio. That's no longer where most servers live. In our registry pull, 57.9% of entries list only a remote endpoint, 36.0% list only an installable package, and 4.9% offer both, so 62.8% can be used without installing anything. Excluding the 10 biggest bulk publishers only lowers that to 58.4%. Among packages, npm leads with 10,826, then PyPI with 4,245.

Remote or local: how registry servers are offered

Share of official MCP Registry entries, 40,047 servers, 6 Oct 2026

Remote or local: how registry servers are offered
LabelValue
Remote endpoint only57.9%
Installable package only36.0%
Both4.9%
Neither listed1.2%
Highlighted bars are entries with a hosted endpoint: 62.8% of the registry.

Sources: MCP Registry API; host0 count, 6 Oct 2026

The long tail on GitHub looks different. Glama, which indexes open-source repositories broadly, tags 41% of its 96,973 servers as remote, about the same share as in June 2025 (42%). The likely reading: individual developers still write local servers, while companies publishing to the official registry ship hosted endpoints. The stateless spec pushes further in that direction. The maintainers' August roadmap says a remote MCP server is now "no different from any other HTTP workload", which means it can run on ordinary serverless hosting behind ordinary load balancers.

The context-cost fight#

Every MCP tool a client loads comes with a name, a description and a JSON schema, and all of it goes into the model's context before the user has typed anything. With one or two servers that's fine. With a realistic set it isn't. Anthropic measured a five-server setup (GitHub, Slack, Sentry, Grafana and Splunk) at 58 tools and about 55K tokens, and says it has seen tool definitions reach 134K tokens internally. The GitHub MCP server on its own used 64.6K tokens for its 101 default tools, before its maintainers cut the default set to 52 tools and 30.3K.

What MCP tool definitions cost in context

Tokens used by a server's tool definitions, as measured by each source, Oct to Nov 2025

What MCP tool definitions cost in context
LabelValue
GitHub MCP, old default (101 tools)64.6K (GitHub)
GitHub MCP, default toolsets (52 tools)30.3K (GitHub)
GitHub MCP (35 tools)~26K (Anthropic)
Slack MCP (11 tools)~21K (Anthropic)
Chrome DevTools MCP (26 tools)18K (Mario Zechner)
Playwright MCP (21 tools)13.7K (Mario Zechner)
Sentry MCP (5 tools)~3K (Anthropic)
Grafana MCP (5 tools)~3K (Anthropic)
Splunk MCP (2 tools)~2K (Anthropic)
A single large server can take tens of thousands of tokens before the conversation starts. Counts depend on the server version and toolset each source measured.

Sources: Anthropic; github-mcp-server #1182; Mario Zechner

The fixes come in two families. One loads tools lazily: Anthropic's Tool Search Tool cut token use by 85% and raised accuracy on MCP evaluations (Opus 4 from 49% to 74%), and Claude Code now switches it on automatically when tool descriptions would take more than 10% of the context. The other lets the model write code against tools instead of calling them one at a time. Anthropic's code-execution example went from 150,000 tokens to 2,000, and Cloudflare put its entire API behind two tools in about 1,000 tokens, where one tool per endpoint would have taken 1.17 million.

How much the context fixes save

Reduction in tokens, before vs after, as reported by each vendor, Oct 2025 to Feb 2026

How much the context fixes save
LabelValue
Code Mode, whole Cloudflare API99.9% (1.17M → ~1,000 tokens)
Code execution with MCP (Anthropic example)98.7% (150,000 → 2,000 tokens)
Tool Search Tool (Anthropic)85%
GitHub MCP default toolsets53% (64.6K → 30.3K tokens)
Each bar is a vendor's own before-and-after on its own workload, so they aren't directly comparable. The direction is consistent: most of the cost is avoidable.

Sources: Cloudflare; Anthropic (code execution); Anthropic (tool search); GitHub

The cost also fed a wider argument about whether agents need MCP at all. When Anthropic launched Agent Skills, folders of instructions and scripts loaded only when needed, Simon Willison called them "maybe a bigger deal than MCP", noting that GitHub's MCP server alone "famously consumes tens of thousands of tokens of context". Mario Zechner's essay "What if you don't need MCP at all?" argued that an agent with bash and a code interpreter can skip it. GitHub itself made the practical version of that call: in its own agentic workflows it replaced GitHub MCP calls for data fetching, such as pull-request diffs and file contents, with the gh CLI, because a CLI call is a plain HTTP request while every MCP tool call is also a round trip through the model.

The argument hasn't ended in either direction. In late September 2026 Pi, Zechner's own coding agent, added MCP support in its 1.0 release, with its new owner Earendil writing that "the MCP of today is not the MCP of yesteryear". One reading of these moves is a division of labour: skills and CLIs for an agent working on its own machine, MCP for authenticated access to someone else's service.

Security: exposure grows faster than fixes#

MCP's security problems fall into two groups. Some are ordinary bugs in servers and tools: missing authentication, command injection, path traversal. Others come from the model itself. Invariant Labs described tool poisoning in April 2025, hidden instructions in a tool's description that the model reads and the user never sees. Simon Willison's "lethal trifecta" names the dangerous combination: an agent with access to private data, exposure to untrusted content and a way to send data out. In an academic benchmark, MCPTox, the best tool-poisoning attack succeeded 72.8% of the time across 20 agents, and no model refused more than 3% of attacks.

Exposed servers#

Several security vendors have scanned the internet for MCP servers. Their methods differ, so the counts aren't a trend line. The one like-for-like pair is Trend Micro's: 492 servers with no client authentication and no encryption in July 2025, and 1,467 in April 2026 using the same method. The largest scan is Censys's. As of 28 April 2026 it found 12,520 internet-accessible MCP services on 8,758 IP addresses in 56 countries; 11,379 listed at least one tool to its probe, and 687 fell into its "system control" category, which covers command execution and remote system interaction.

Internet-exposed MCP servers, by scan

Servers or services each vendor reported, by method and date, Jul 2025 to Apr 2026

Internet-exposed MCP servers, by scan
LabelValue
Trend Micro, Jul 2025492 (no auth, no encryption)
Knostic, Jul 20251,862 (all 119 sampled lacked auth)
Bitsight, Dec 2025~1,000 (no authorization)
Trend Micro, Apr 20261,467 (same method as 2025)
Censys, Apr 202612,520 (internet-accessible services)
Only the highlighted bars use the same method: Trend Micro's count nearly tripled in nine months. Censys counted every reachable MCP service, not only unauthenticated ones.

Sources: Trend Micro 2025; Knostic; Bitsight; Trend Micro 2026; Censys

The Censys data also shows how slowly the spec's security work reaches deployed servers. 89.4% of the services it saw spoke protocol version 2025-03-26. Only 1.0% were on 2025-06-18, the revision that made servers OAuth resource servers and banned token passthrough, and 0.7% on 2025-11-25. The scan predates 2026-07-28, so the newest hardening (issuer validation, client registration bound to its issuer) has no deployment data yet.

Protocol versions spoken by internet-facing MCP services

Share of 12,520 services Censys observed, as of 28 Apr 2026

Protocol versions spoken by internet-facing MCP services
LabelValue
2025-03-2689.4%
2024-11-058.3%
2025-06-181.0%
2025-11-250.7%
Empty0.5%
Other0.1%
Nine in ten exposed services were a full revision behind. The authorization changes in 2025-06-18 and later had reached under 2% of them.

Source: Censys, MCP servers on the internet

Incidents and exploitation#

The incident record runs from research demos in 2025 to criminal exploitation in 2026. In 2025 the notable cases were proofs of concept and bugs found by researchers: a GitHub MCP prompt injection that leaked private repositories, a cross-tenant leak in Asana's MCP server that a spokesperson said affected about 1,000 customers, remote code execution in mcp-remote (CVSS 9.6) and the MCP Inspector (CVSS 9.4), and postmark-mcp, the first malicious MCP server found in the wild, which published 15 clean versions before quietly BCC'ing every email.

In 2026 attackers caught up. A missing-authentication bug on nginx-ui's MCP endpoint (CVSS 9.8) was exploited in the wild within two weeks of its advisory, according to Recorded Future as cited by Rapid7. Pluto Security says a flaw in mcp-atlassian went from patch to a criminal proof of concept in 20 days. And two MCP-related bugs, both in the LiteLLM gateway, were added to CISA's Known Exploited Vulnerabilities catalog: CVE-2026-42271, where MCP "test connection" endpoints ran a command supplied in the request, on 8 June, and CVE-2026-59822, an authentication bypass to MCP tools, on 2 September. Even the official Python SDK had a high-severity advisory in September that let a malicious server choose where a client's OAuth credentials went, the kind of gap the July spec's issuer validation is meant to close.

MCP security incidents, research to exploitation

Selected disclosures, incidents and responses, Apr 2025 to Sep 2026

  1. 1 Apr 2025

    Tool poisoning named

    Invariant Labs describes hidden instructions in tool descriptions, rug pulls and shadowing.
  2. 26 May 2025

    GitHub MCP prompt injection

    A malicious public issue makes an agent leak private repository data.
  3. 18 Jun 2025

    Asana cross-tenant leak

    About 1,000 customers affected, per a spokesperson; the server was offline for 12 days.
  4. 9 Jul 2025

    mcp-remote RCE

    CVE-2025-6514, CVSS 9.6: a malicious server could run commands on the client.
  5. 25 Sep 2025

    First malicious MCP server

    postmark-mcp adds a hidden BCC after 15 clean versions.
  6. 30 Mar 2026

    nginx-ui “MCPwn”

    Missing auth on the MCP endpoint, CVSS 9.8; exploited in the wild by mid-April.
  7. 15 Apr 2026

    OX Security on stdio

    OX says the stdio transport runs any command it's given and counts 10 CVEs; per OX, Anthropic called it by design.
  8. 20 May 2026

    NSA guidance on MCP

    Tool and model output should never be implicitly trusted.
  9. 8 Jun 2026

    First MCP bug on CISA's KEV list

    LiteLLM CVE-2026-42271: a command from the request body, run via stdio.
  10. 28 Jul 2026

    Spec hardens authorization

    Issuer validation required; Dynamic Client Registration deprecated.
  11. 2 Sep 2026

    Second KEV entry

    LiteLLM CVE-2026-59822: unauthenticated access to MCP tools.
  12. 16 Sep 2026

    Patch to criminal exploit in 20 days

    Pluto Security's account of mcp-atlassian “MCPwnfluence”.
In 2025 the record was mostly research and responsible disclosure, plus one malicious package. In 2026 it includes confirmed exploitation and two entries on the US government's exploited-vulnerabilities list.

Sources: Invariant Labs; BleepingComputer; JFrog; Postmark; Rapid7; OX Security; NSA; NVD; Pluto Security

The response has come from every direction at once: the spec (token binding in 2025, issuer validation in 2026), platforms (Windows runs MCP servers under a separate agent account behind an OS proxy), and governments, with joint Five Eyes guidance on agentic AI in May 2026 and an NSA information sheet specific to MCP. The registry itself verifies who published a server and can denylist entries, but it doesn't scan code.

Distribution and money#

MCP became a distribution channel when the chat apps opened up to it. Claude added remote servers in May 2025; OpenAI built its Apps SDK on MCP in October 2025, pitching it as a way to reach over 800 million ChatGPT users, and opened app submissions in December. In January 2026 the two efforts met in MCP Apps, the first official extension, which lets a tool return interactive UI that ChatGPT, Claude, Goose and VS Code render in the conversation. Google now offers more than 50 managed MCP servers for its own services.

The money has gone to the infrastructure around the protocol, not the protocol itself. Gateways, which sit between agents and servers to enforce auth and policy, are the most common type of MCP security product, according to TechCrunch. The eight rounds below add up to about $211M, by our arithmetic over the announced amounts. In 2026 the first acquisitions followed: Snowflake agreed to buy Natoma for its MCP governance platform, and Arcade, seven weeks after raising a $60M Series A, bought Smithery, one of the largest public MCP registries, on 5 August.

Funding and acquisitions in MCP infrastructure

Disclosed rounds and deals, amounts as announced, Jul 2025 to Aug 2026

CompanyAmountDateDealWhat it does
Composio$25MJul 2025Series A (Lightspeed)Tool and integration layer
Alpic$6MSep 2025Pre-seed (Partech)MCP hosting
Obot AI$35MSep 2025Seed (Mayfield, Nexus)MCP gateway
Keycard$38MOct 2025Seed + Series A (a16z, boldstart, Acrew)Agent identity and access
Runlayer$11MNov 2025Seed (Khosla, Felicis)MCP security
Manufact$6.3MFeb 2026Seed (Peak XV)MCP SDK and cloud
Natoma → SnowflakeUndisclosedMay 2026AcquisitionMCP governance
Arcade$60MJun 2026Series A (SYN Ventures)Agent tool runtime
Runlayer$30MJun 2026Series A (Felicis, Khosla)MCP security
Smithery → ArcadeUndisclosedAug 2026AcquisitionMCP registry and hosting
Security and gateways took the largest share. Disclosed rounds total about $211M; both acquisitions were undisclosed.

Sources: SiliconANGLE (Composio); Alpic; Obot; GlobeNewswire (Keycard); TechCrunch (Runlayer); SiliconANGLE (Manufact); CIO (Natoma); BusinessWire (Arcade); Runlayer; Arcade (Smithery)

MCP also isn't the only agent protocol under the Linux Foundation. Google's Agent2Agent protocol moved there in June 2025, absorbed IBM's ACP, and had 150+ supporting organizations by April 2026. The foundation frames the two as complementary: A2A for agents talking to each other, MCP for agents reaching tools and data.

What this means if you build with AI#

MCP is now infrastructure: nearly every assistant speaks it, and anything you expose through it can be reached by an agent you didn't write. The data points to a short list of habits.

  1. Build new servers on 2026-07-28, and keep older clients working. The stateless core means any HTTP host works, with no sticky sessions. But 89.4% of the servers Censys saw were still on the March 2025 version, so expect clients that lag too.
  2. Put authentication in front of every remote server. Trend Micro's count of servers with no client auth nearly tripled in nine months. Never bind a local server to every network interface, and treat a test or "preview" endpoint like a production one: that's how LiteLLM ended up on CISA's list.
  3. Measure what your tools cost in context. A single server can take 30K–65K tokens. Ship a small default toolset, and prefer clients with tool search or code execution.
  4. Treat tool output as untrusted input. Don't give one agent private data, untrusted content and a way to send data out at the same time, which is the lethal trifecta. In one demo, a support ticket was enough to make an agent with service-role access leak a Supabase secrets table.
  5. Pin the servers you install, and patch fast. postmark-mcp turned malicious on its sixteenth version, and one MCP flaw went from patch to criminal exploit in 20 days. If you use mcp-remote or the Python SDK, check you're past the fixed versions (0.1.16 and 1.30.0).
  6. Pick MCP or a CLI by the job. For data fetching inside your own pipelines, a CLI call skips a model round trip, which is why GitHub switched. For letting other people's agents reach your service with their own sign-in, MCP is the standard every client speaks.
  7. Don't read a registry listing as a quality signal. The official registry verifies namespaces, not code, and 18.7% of its entries come from ten publishers. Check who publishes a server before you connect it.

host0 is a cloud for small software: agents deploy apps through a skill and a REST API, and host0's own MCP server is deliberately control-only (list, rename, share and delete apps, no deploy). The context-cost and security data above is a large part of why we split it that way.

Methodology#

This post draws on four research passes we ran on 6 October 2026, one per angle: the spec and its governance, adoption, security, and the market and its debates. Each was limited to primary sources: the specification and its changelogs, the official MCP blog, company announcements, security-vendor reports, NVD entries and academic papers. We used aggregator and "statistics" sites only as leads. Before publishing, we re-opened every single-source page the post leans on for a headline number and confirmed the quoted sentence was still there.

Several numbers are our own computations from public data:

  • Registry size and shape: we paged through the official registry's public API (/v0/servers?limit=100&version=latest, 401 pages) on 6 October 2026 and deduplicated by server name. Two pulls a few hours apart gave 40,041 and 40,047; we use the later one. Remote and local shares come from each entry's remotes and packages fields.
  • SDK downloads: monthly sums of daily npm counts for @modelcontextprotocol/sdk and PyPI counts for mcp from the public ClickHouse PyPI dataset, cross-checked against pypistats.
  • Directory growth: Wayback Machine snapshots of PulseMCP and Glama, read from the counts in their page titles.

We dropped claims that didn't hold up: a widely repeated "78% of enterprise AI teams use MCP in production" (no traceable source), several aggregator totals for servers and downloads, a "first MCP flaw on CISA's list" headline that named the wrong CVE, and paraphrases of Censys's data as "unauthenticated" servers. We also left out a third-party registry pull from May 2026 in favour of our own.

Limitations:

  • Downloads are not users. They include CI runs, transitive installs and bundled copies, and one large consumer can move the total by tens of millions a month.
  • Server counts are listings. Neither the registry nor any directory measures whether a server is used, maintained or safe.
  • Security scans use different methods. Only Trend Micro's two scans are directly comparable. Vendor counts are the vendor's claim.
  • Vendor figures are self-reported. Funding amounts are as announced; the $211M total is our sum, not a market size.
  • Everything has a date. The registry is in preview and may reset, and the Censys scan predates the July spec.

Open questions#

The public data has clear holes:

  1. How many tool calls happen. No client vendor publishes MCP call volumes; the only figure we found is Cloudflare's "billions of tool calls" for its own hosting.
  2. How much of the registry is real. What share of the 40,047 entries are maintained, distinct servers rather than bulk or automated listings?
  3. What moved the download curves. Why did both SDKs double in March 2026, and what dropped Python by about 40% overnight on 25 August?
  4. Whether the 2026 hardening has shipped. How many clients and internet-facing servers have adopted 2026-07-28's authorization changes?
  5. How many MCP vulnerabilities there are. No maintained, current count of MCP CVEs exists.
  6. How big the app directories are. Neither ChatGPT's app directory nor Claude's connector directory has published a count since Anthropic's "over 75" in December 2025.
ResearchMCP