Analysis · curated 5 Jul 2026
The New MCP Specification: What Security Teams Must Prepare For
First reported akamai.com
Coverage timeline
Why it matters
The MCP specification overhaul reshapes the agentic-AI attack surface, so security teams must understand how new capabilities like stateless design and rich UI apps can be abused before enterprise MCP deployments go live.
Akamai researchers analyze the upcoming MCP 2026-07-28 specification, which shifts the Model Context Protocol to an enterprise-grade, stateless architecture with application-managed state, rich interactive UI apps, and long-running async tasks. While the update eliminates historical risks like protocol-level session hijacking, unsolicited server prompts, and weak authentication, it pushes responsibility for security boundaries onto developers and opens new abuse avenues including unauthorized customer data access, phishing through trusted AI interfaces, control bypass, and service disruption via background processing.