Research · curated 29 Sep 2026
Wide Open: 147 Unauthenticated MCP Servers Exposed
First reported pluto.security
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Unauthenticated MCP servers wired into internal company and government systems give any attacker read/write access to highly sensitive data and infrastructure without any exploit, making this a widespread and easily discoverable exposure that defenders must lock down.
Pluto Security's Operation:MCP research found 179 exposed Model Context Protocol (MCP) server deployments on the internet, 147 of which accepted unauthenticated requests, exposing root shells, production credentials, financial data, subscriber lists, and municipal citizen records. The root cause is that MCP's discovery call, tools/list, requires no authentication by design, letting anyone who finds the port enumerate and invoke a server's entire tool catalog.