Research · curated 30 Sep 2026
MCP Server Security Benchmark Report (2026) | OX Research
First reported ox.security
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
MCP server infrastructure underpinning enterprise AI agents lacks native controls over data residency and trust, exposing organizations to supply-chain, domain-takeover, and prompt-injection risks that persist beyond a single granted permission.
OX Security analyzed 15,465 published MCP servers and found widespread governance gaps: 15.6% of hostnames resolved to infrastructure outside the US (including China and Russia), some tied to home/consumer networks, and six unregistered domains available for as little as $4/year that create takeover paths. Testing against Claude Code with Haiku 3.5 showed a single 'Always-Allow' permission let a malicious MCP server use subsequent prompt injection to execute privileged file access without further confirmation, though the attack failed against Opus 4.6 and 4.7.