mcpSecurity.cloud
MSR-2026-08 · PUBLIC RESEARCH
Scanner research · 2026 coverage report

MCP Security Scanner Coverage: What We Tested and Proved

A transparent measurement of our catalog and verification pipeline: what our scanner tested, where it reproduced findings, and how much of the catalog still lacks current-version evidence.

Dataset: MCP Security public catalogUpdated: Sep 8, 2026Scope: our scanner and observation workers
71,565implementations in our catalog71,584 source records normalized
8,402current versions tested by our scanner11.7% of our catalog
508tested current versions with proven findings6.0% of our tested cohort
5,032linked remote MCPs4,445 observed by our worker
01 / EXECUTIVE FINDINGS

Our scanner has tested 11.7% of the current versions represented in our catalog.

Our catalog currently resolves 71,565 canonical MCP implementations from 71,584 active source records. Our scanner has completed publicly eligible tests for 8,402 selected current versions—11.7% of our catalog.

11.7%

of our catalog has a current-version test

63,163 catalog implementations still lack a publicly eligible current-version result from our scanner.

6.0%

of our tested cohort has findings

Our scanner reproduced one or more findings in 508 of the 8,402 current versions it tested.

7,894

tested without a proven finding

Our retained test profile did not prove a finding for these exact versions. This is not certification of the server or every deployment configuration.

4,445

observed by our remote worker

Our remote observation records endpoint and transport evidence; it does not substitute for authenticated application-layer testing.

What we can concludeOur scanner has reproduced risk in a material subset of the exact current versions it tested. We cannot use this non-random tested cohort to claim the same rate for MCP implementations outside our coverage.
02 / SCANNER COVERAGE

Our results must be reported with the catalog and tested-cohort denominators.

A raw finding count is not an MCP-wide prevalence estimate. Our tested cohort is shaped by what our pipeline can discover, acquire, launch, isolate, and publish.

In our catalog
71,565
Tested current versions
8,402
Tested with findings
508

Coverage is calculated against canonical implementations in our catalog, not all MCP implementations that may exist. One implementation may appear in multiple source listings or distribution channels.

03 / OUR CURRENT FINDINGS

Our scanner proved findings in 508 selected current versions.

That is 6.0% of the current versions our scanner tested—not 6.0% of MCP as a whole. Findings are attached to exact package versions and should not be generalized to untested releases.

Interpretation ruleOn this report, “with findings” means our scanner reproduced and retained at least one finding for the selected exact version. It does not mean every deployment exposes the same path.
04 / FINDING TAXONOMY

Types of vulnerabilities our scanner proved.

Percentages use 75 retained proven technique observations for selected current versions. One affected implementation can contribute multiple observations.

TECHNIQUE · ENGINE SEVERITYPROVEN OBSERVATIONS · SHARE · AFFECTED CURRENT VERSIONS
01Server-side request forgeryhigh
46records61.3%4versions
02Command injectioncritical
21records28.0%2versions
03Path traversalhigh
8records10.7%2versions

This is a distribution of proven observations produced by our current test profile, not a prevalence estimate for all MCP vulnerabilities. “Affected current versions” is deduplicated within each technique. Severity is our engine’s technique classification, not a CVSS score. Techniques our scanner does not test cannot appear here.

04 / REMOTE EXPOSURE

Remote discovery is ahead of deep application-layer verification.

The catalog links 5,032 remote endpoints and has observed 4,445 of them (88.3%). Observation records transport reachability and endpoint state; authentication boundaries may limit further inspection.

1,601

initialized successfully

The endpoint completed the supported initialization flow during its latest observation.

1,439

authentication required

The endpoint was reachable but correctly demanded credentials before protected interaction.

2,860

unhealthy observations

The latest observation reached a terminal unhealthy state; this is operational evidence, not automatically a security finding.

1,135

blocked observations

Policy or safety controls prevented deeper observation. Blocked is not equivalent to safe or vulnerable.

05 / EVIDENCE INDEX

Highest-adoption affected implementations in the current public cohort.

Rows link to canonical profiles and exact-version evidence. Ordering follows the catalog’s adoption ranking; it is not a severity ranking.

No current public finding records match the report filter. The report does not substitute historical or restricted evidence.
06 / CATALOG PATHS

Continue from aggregate research to implementation-level evidence.

Use these crawlable catalog paths to compare retained identity, distribution, and exact-version evidence without treating category membership as a safety claim.

Database MCP servers

Browse PostgreSQL, MySQL, MongoDB, and other explicitly identified database integrations.

Individual profile pages remain authoritative for selected version, package, publisher, tool, and verification details.

06 / METHODOLOGY

Identity first. Exact version second. Runtime evidence third.

  1. Normalize identities. Active source listings are resolved to canonical implementations using retained package, repository, publisher, and namespace evidence.
  2. Select the current artifact. The report chooses the latest eligible package version using deterministic channel and release ordering.
  3. Verify in isolation. Successful public runs link an exact artifact to retained proof results. Inconclusive, failed, and not-tested outcomes are not silently counted as clean.
  4. Separate observations. Remote endpoint health and initialization are reported independently from package runtime findings.
  5. Respect publication controls. Draft, embargoed, restricted, and otherwise non-public evidence is excluded from public findings.
07 / LIMITATIONS

What our scanner data cannot establish.

Do not read 6.0% as MCP-wide vulnerability prevalence.Our tested cohort is not a random sample. Results reflect artifacts our pipeline could discover, acquire, launch, test, retain, and publish.
  • A result without proven findings applies only to the exact version and behaviors our scanner tested.
  • Implementations outside our catalog are absent from every denominator in this report.
  • Remote endpoints requiring credentials may expose capabilities our public observation cannot measure.
  • New releases can invalidate our previous current-version conclusion.
  • Finding counts are not severity-weighted in this overview.

Reproducible profile and version pages are the authoritative public evidence surfaces. This report describes our continuously regenerated scanner and catalog records.

Let’s talk about MCP security.

Share your details and our security team will contact you.