# GSA Hosts MCP Security Hackathon

A report on federal Model Context Protocol (MCP) services describes five unpatched government MCP servers and potential risks including weak authentication, exploitable servers, and unsafe protocol behavior. The article notes that there is no dedicated FedRAMP baseline or finalized federal security profile for MCP; it reports no confirmed breach of a federal MCP server, and the platform-level findings have not been independently replicated. GSA’s Government MCP Server and AI Agent Hackathon runs from September through November 2026, giving agencies and contractors a current venue to demonstrate security controls.

- The report points to a security gap for agencies piloting or publishing MCP services; it does not establish that a federal breach occurred or that the reported findings have been independently verified.
- Contractors participating in GSA’s hackathon can demonstrate independent authentication, tool-level authorization, and middleware safeguards—the controls identified in the signal.
- Procurement teams evaluating MCP or AI-agent capabilities can use these controls as concrete security considerations when assessing proposed solutions.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity, Artificial Intelligence
**Published:** October 07, 2026

### Government Entities
- General Services Administration (GSA)

### Sources
- [Federal MCP Security Exposure — Five Unpatched MCP Servers in Government | infrastructure | CryptoRank.io](https://cryptorank.io/news/feed/260bd-federal-mcp-security-exposure-five-unpatched-mcp-servers-in-government) - CryptoRank