Research · curated 29 Sep 2026

Wide Open: 147 Unauthenticated MCP Servers Exposed

Coverage timeline

24 Sep 2026pluto.security

Single-source research — first reported, latest, and curated coincide.

Why it matters

Unauthenticated MCP servers wired into internal company and government systems give any attacker read/write access to highly sensitive data and infrastructure without any exploit, making this a widespread and easily discoverable exposure that defenders must lock down.

Pluto Security's Operation:MCP research found 179 exposed Model Context Protocol (MCP) server deployments on the internet, 147 of which accepted unauthenticated requests, exposing root shells, production credentials, financial data, subscriber lists, and municipal citizen records. The root cause is that MCP's discovery call, tools/list, requires no authentication by design, letting anyone who finds the port enumerate and invoke a server's entire tool catalog.