MCP hit ~97M SDK downloads a month, and most public servers carry exploitable risk
Around 41% of software-industry technical leaders report MCP in limited-to-broad production, on SDK downloads near 97 million a month. Independent scans found a majority of public MCP servers carry exploitable risk, and only a small fraction use OAuth by default.
Every widely adopted protocol goes through this. The gap between "this makes integration trivial" and "this needs an authorisation model" is where the incidents live, and MCP is currently in it with unusually large numbers on both sides.
Adoption is not marginal: roughly 97 million SDK downloads a month, and about 41% of technical leaders reporting production use somewhere between limited and broad. That is infrastructure-level penetration in well under two years.
The security picture is the mirror image. Independent scanning found a majority of public MCP servers carrying exploitable risk, with only a small fraction defaulting to OAuth. Tool poisoning is the specific failure mode — an MCP server describing its capabilities to an agent is describing them in text the agent trusts, and text the agent trusts is an injection surface.
The pattern reported by practitioners is consistent enough to be actionable: failures trace back to scaling MCP access before the governance layer could hold it. The organisations getting value treated the gateway, the identity layer and the audit trail as architecture from day one, then scaled — which is exactly what the new crop of agent gateway products is being sold to retrofit.
ITECS — MCP Tool Poisoning: Enterprise AI Agent Security in 2026 → · The Agentics — The Enterprise MCP Guide 2026 → · LangProtect — MCP Security: Enterprise Guide to Securing AI Agents →