An AI-Powered Vulnerability Sweep of 19,000 MCP Servers
Researchers scanned over 19,000 open-source MCP server repositories, revealing that AI-generated code is present in at least 20% and is disproportionately linked to exploitable vulnerabilities. Key findings include 4.1% of identified flaws being exploitable, with SQL injection, RCE, and path traversal prevalent, and 42.6% of vulnerable repositories showing signs of AI code generation.
STABLE
What Happened
Researchers scanned over 19,000 open-source MCP server repositories, revealing that AI-generated code is present in at least 20% and is disproportionately linked to exploitable vulnerabilities. Key findings include 4.1% of identified flaws being exploitable, with SQL injection, RCE, and path traversal prevalent, and 42.6% of vulnerable repositories showing signs of AI code generation.
Why This Matters
Publisher reporting describes a security event affecting and. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.
Recommended Action
Confirm whether and is present in your environment and review vendor guidance for this report. Apply available patches or mitigations if your deployment matches the described conditions.
Exposure
Exposure unknown
May 28, 2026 12:30
Exposure reason: This incident does not currently match a technology in My Interests.
Exploitation status: UNKNOWN
Primary entities:
Timeline
-
Incident first seen
May 28, 2026 05:30BugSkan first recorded this incident.
-
An AI-Powered Vulnerability Sweep of 19,000 MCP Servers - www.trendmicro.com
May 28, 2026 05:30trendmicro.com ยท Research
-
Hunt Them All: An AI-Powered Vulnerability Sweep of 19,000 MCP Servers - www.trendmicro.com
May 28, 2026 12:30news.google.com ยท Vulnerability
-
Latest observed development
May 28, 2026 12:30Most recent source or update associated with this incident.
Sources
trendmicro.com ยท May 28, 2026 05:30
Researchers scanned over 19,000 open-source MCP server repositories, revealing that AI-generated code is present in at least 20% and is disproportionately linked to exploitable vulnerabilities. Key findings include 4.1% of identified flaws being exploitable, with SQL injection, RCE, and path traversal prevalent, and 42.6% of vulnerable repositories showing signs of AI code generation.
Open publisher sourcenews.google.com ยท May 28, 2026 12:30
Hunt Them All: An AI-Powered Vulnerability Sweep of 19,000 MCP Servers www.trendmicro.com
Open publisher sourceRelated Incidents
Other BugSkan incidents that share identifiers, products, or vendors with this report.
My Interests Match
Create an account to see which incidents overlap with your interests.