Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

OX Security’s 2026 analysis reports that it identified 15,465 published MCP servers, then examined infrastructure associated with 5,095 unique hostnames. It found examples of hostnames resolving outside the United States, links to consumer-grade infrastructure, and domains that no longer resolved. Those observations are reasons to vet each server and limit its access—not proof that every public MCP server is unsafe, compromised, or sending data abroad.

This article summarizes the findings as of October 6, 2026. OX’s accessible report pages do not provide the complete collection and validation protocol, so the results should be read as a snapshot of publicly listed infrastructure, not an independently verified census of all MCP deployments.

What did OX Security analyze?

OX Security says it analyzed 15,465 published MCP servers and narrowed its infrastructure analysis to 5,095 unique hostnames. These are different units: the first figure counts published server records; the second is the denominator for the reported hostname findings. A registry listing, a hostname, and a live deployment are not interchangeable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

OX’s September 24 article says the 15,465 listings came from three public registries: mcp-official-registry, cline-marketplace, and github-mcp-registry. The October 6, 2026 contributed article in The Hacker News describes a scan of five MCP registries. The available descriptions therefore differ on the registry count; without the full methodology, it is not possible to reconcile them. OX’s landing page and article provide the headline figures, but the accessible pages do not expose the full collection and validation protocol. OX Security’s research page and September 24 article are the sources for its reported findings.

#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

The figures describe OX’s observations at the time of its analysis. They do not establish the prevalence of these conditions across all MCP servers, confirm that a particular server is malicious, or show that data was actually exfiltrated. DNS records and hosting can also change after a scan.

What do the infrastructure findings mean?

Some hostnames resolved outside the United States

OX reports that 796 of the 5,095 analyzed hostnames—15.6%—resolved outside the United States. It lists 19 in China and 18 in Russia. These are hostname and DNS/infrastructure observations, not measurements of where a user’s data was stored, processed, or sent. A hostname’s resolution location alone cannot establish the route or destination of a particular request.

For an organization with data-residency or jurisdiction requirements, treat the result as a reason to verify the specific server’s operator, hosting arrangement, and traffic path. Do not infer that all of a server’s users’ data went to the country where a hostname resolved.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A small share appeared to use consumer-grade infrastructure

OX says 0.45% of analyzed hostnames were associated with home networks or consumer tunneling tools. That description does not mean those hostnames were compromised. It does, however, raise operational questions: who controls the endpoint, how stable is it, and is it suitable for a service that can access organizational tools or data?

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

Some hostnames no longer resolved

OX reports that 2.3% of the analyzed hostnames no longer resolved and that six domains were unregistered. Its landing page says some were available for as little as $4 per year; its September article gives a range of $4 to $12 a year. These are OX’s reported prices at the time, not a statement of current availability or a recurring price guarantee.

An expired or unregistered domain creates a conditional takeover exposure: someone could register it, but the risk to an organization depends on whether a client or configuration continues to call that hostname after it becomes available. The scan does not establish that any domain was taken over or that a client kept using it.

Are public MCP servers safe to use?

There is no blanket yes or no in these findings. A public listing does not itself establish that a server is trustworthy or unsafe. Risk depends on the particular operator and deployment, what the connected client is permitted to do, what data it can access, and where requests are routed. OX’s infrastructure snapshot is useful as a warning against treating a registry listing or code repository as a complete security review; it is not a scorecard for individual servers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

As OX Security research team lead Moshe Siman Tov Bustan put it in the October 6 contributed article, “Code review tells you what the developer published, not what the server runs.” A repository may help you inspect published code, but it does not by itself verify the identity of a deployed service or attest that the live runtime matches that code.

Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

Can an MCP server prompt injection get access to files?

OX describes a bounded test in Claude Code using Haiku 3.5. In the reported scenario, a malicious MCP server first requested access to a harmless file. After the user selected “Always-Allow,” the server used prompt injection to obtain access to a sensitive file, including .env, without another confirmation. OX says the same attack did not succeed with Opus 4.6 or 4.7.

This result applies to the specific test setup and permission choice OX describes; it does not show that every MCP server can bypass file permissions or predict how other clients and models behave. OX also reports Anthropic’s explanation that “Always-Allow” behaves as documented and that model-level detection of malicious content is a best-effort heuristic, not a security boundary. That explanation is reported by OX, rather than independently verified here. The test summary is available on OX Security’s research page and in its September article.

The practical lesson is to treat permission prompts as consequential. Granting standing access to a client can make a later request more powerful than the harmless initial action suggests. Limit permissions to what a server needs, and avoid persistent approval when a one-time grant or a narrower workflow will do.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Does MCP authorization prove that a server is trustworthy?

No. The MCP specification update dated July 28, 2026 describes authorization changes including issuer validation and issuer-bound client credentials, and deprecates Dynamic Client Registration in favor of Client ID Metadata Documents. These mechanisms address authorization. They do not constitute marketplace scanning, runtime code attestation, domain-ownership monitoring, or geographic enforcement. See the MCP specification update.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display

Authorization can help establish which clients may access a protected resource under a protocol’s rules. It does not, by itself, tell an organization who operates every listed server, where its infrastructure is located, or whether its running code matches a reviewed repository.

How should organizations review MCP servers?

Use OX’s findings as a prompt to evaluate each connection in context, rather than as a reason to approve or reject every public server as a category. A practical review should cover identity, access, destination, and change monitoring:

  1. Inventory every connection. Record the MCP server name, endpoint and hostname, business owner, users, connected client, and the systems or data it can reach. Include manually configured servers as well as registry-installed ones.
  2. Verify the operator and deployment. Establish who operates the endpoint, how the organization can contact them, where the service is hosted, and how the running service relates to any published repository. Do not treat a repository review as proof of deployed runtime code.
  3. Set an allowlist and review ownership. Permit only approved endpoints and assign an internal owner responsible for reviewing continued use. Remove entries that lack a current business need or accountable owner.
  4. Minimize permissions and data exposure. Give each server only the tools, files, credentials, and data necessary for its task. Prefer narrow, task-specific approvals over broad standing access, and consider whether sensitive files such as .env should be available at all.
  5. Control and monitor outbound connections. Apply egress rules appropriate to the workflow, and monitor for changes in DNS resolution, domain ownership, endpoint, or destination. Reassess a connection when its identity or deployment changes.
  6. Plan revocation and recovery. Make sure you can disable a server connection, revoke its credentials, and remove any client configuration that could continue calling an endpoint whose ownership or resolution has changed.

These are defensive recommendations derived from the scenarios OX reports; the study does not claim to have tested or validated these controls.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.