MCP Security: 2 CVEs Your Team Can’t Ignore

The NSA doesn’t usually publish design guidance on a protocol that’s barely 18 months old. It did for MCP, naming eight specific risk categories. Here’s what the two CVEs show, what OWASP already has a name for, and what a real internet scan found.