On this page5 sections
MCP news: the short answer
The MCP news that matters most in 2026 is the 2026-07-28 specification, which removed sessions and made the protocol stateless. Around it, Arcade.dev bought Smithery, Snowflake bought Natoma, and AWS, Microsoft, HubSpot and Salesforce shipped hosted MCP servers. September was quiet on the protocol side: the MCP blog published nothing new.
Every item below links a primary source: the MCP blog or specification, the vendor's own announcement, a regulatory filing, or the researcher's advisory. For how the protocol fits together, read the Model Context Protocol guide.
The current spec at a glance
| Item | Detail |
|---|---|
| Current revision | 2026-07-28, released 28 July 2026 |
| Previous revision | 2025-11-25 |
| Biggest change | No protocol-level sessions and no initialize handshake. Every request carries its own protocol version and client capabilities |
| New | server/discover, Multi Round-Trip Requests (MRTR), required Mcp-Method and Mcp-Name headers, cache hints (ttlMs, cacheScope), subscriptions/listen |
| Deprecated | Roots, Sampling, Logging, the HTTP+SSE transport, Dynamic Client Registration |
| Moved to an extension | Tasks |
| Deprecation window | At least twelve months before a deprecated feature can be removed |
Source: the 2026-07-28 changelog.
Timeline, newest first
September 2026
- 30 September. Arcade rescans the ecosystem. Arcade's ToolBench now scores more than 90,000 open-source MCP servers and 630,000 tools. It gives an A to 260 of them, or 0.28%. Stateless handling from the new spec shows up on 5.8% of servers. Among servers that ship a destructive or irreversible tool, 14% declare safety annotations. This is a vendor's own benchmark, and the vendor sells tool governance. Arcade
- 28 September. Cisco Investments backs Arcade.dev. The investment extends Arcade's Series A. Arcade is the company that bought Smithery in August. Arcade
The MCP blog's most recent post is still the 22 August roadmap.
August 2026
- 22 August. New MCP roadmap. It names five priority areas: agentic messaging primitives, HTTP-native transport unification and hardening, agent identity and enterprise-ready security, improved primitives, and improved SDK developer experience. One planned piece is progressive discovery, so a server with a hundred tools can offer a small entry point first. MCP blog
- 5 August. Arcade.dev acquires Smithery. Smithery co-founder Anirudh Kamath joins Arcade. Arcade calls Smithery a leading public registry and hosting platform for MCP. The announcement gives no price and still sends developers to smithery.ai to sign up free. Arcade. See also PopMCP vs Smithery.
- 5 August. Azure DevOps Remote MCP Server is generally available. It is hosted by the Azure DevOps service and covers work items, pull requests, repositories and pipelines. Your organization must be backed by a Microsoft Entra tenant. Microsoft
July 2026
- 28 July. Spec 2026-07-28 released. A stateless core, MRTR, header-based routing, cacheable list results and stricter authorization checks. The TypeScript, Python, Go and C# SDKs supported it on release day, and the Rust SDK in beta. A server can now sit behind a plain round-robin load balancer, and code that depends on session IDs has to migrate. MCP blog
- 27 July. The official Ruby SDK reaches 1.0. It is the first stable release of the
mcpgem. It implements the 2025-06-18 and 2025-11-25 revisions. MCP blog - 1 July. DuneSlide: two critical flaws in Cursor. Cato AI Labs published CVE-2026-50548 and CVE-2026-50549, both rated 9.8 by NVD. A prompt injection delivered through an MCP server request or a poisoned web result could write files outside the workspace and escape Cursor's sandbox. Both are fixed in Cursor 3.0. Cato Networks, Cursor advisory
June 2026
- 29 June. Beta SDKs for the release candidate. Python, TypeScript, Go and C#. MCP blog
- 18 June. Enterprise-Managed Authorization is stable. The extension lets a company grant MCP server access through its identity provider, so users skip the per-server consent screen. Okta is the first supported identity provider. Claude and VS Code support it as clients. Asana, Atlassian, Canva, Figma, Granola, Linear and Supabase support it as servers. MCP blog
- 3 June. Snowflake completes its Natoma acquisition. Snowflake announced the deal on 27 May. Its quarterly filing puts the preliminary purchase consideration at $128.3 million and describes Natoma as an enterprise MCP platform for AI agents. Snowflake announcement, 10-Q
May 2026
- 21 May. Release candidate for 2026-07-28. The first public look at stateless MCP. MCP blog
- 6 May. The AWS MCP Server is generally available. It is a managed remote server. Its
call_awstool runs AWS API operations with your existing IAM credentials, and a newrun_scripttool runs a short Python script in a sandbox with no network access. AWS
April 2026
- 29 April. Salesforce Hosted MCP Servers are generally available, for Enterprise Edition orgs and above. Salesforce
- 15 April. OX Security reports a design-level STDIO risk. OX says that passing untrusted input into the configuration that launches a stdio server allows command execution, and lists 10 CVEs in downstream projects. By OX's account, Anthropic called the behavior expected and declined to change the protocol. OX Security
- 15 April. "MCPwn" in nginx-ui, CVE-2026-33032. nginx-ui's
/mcp_messageendpoint skipped authentication, so any network attacker could call its MCP tools and take over Nginx. CVSS 9.8. Pluto Security, which found it, says the fix shipped in v2.3.4 and that the flaw has been exploited in the wild. Pluto Security, nginx-ui advisory - 13 April. HubSpot's remote MCP server is generally available. The release adds write access for contacts, companies, deals, tickets and activities. HubSpot
- 8 April. The maintainer team expands. Den Delimarsky becomes a Lead Maintainer alongside David Soria Parra. Clare Liguori of AWS joins the Core Maintainers. MCP blog
January to March 2026
- 9 March. The 2026 MCP roadmap. Four priority areas: transport evolution and scalability, agent communication, governance maturation and enterprise readiness. MCP blog
- 26 January. MCP Apps, the first official extension. Tools can return interactive UI that renders in the conversation. At launch it was supported in Claude and Goose, in VS Code Insiders, and in ChatGPT from that week. MCP blog
Late 2025
- 11 December 2025. Google announces fully managed remote MCP servers, starting with Google Maps, BigQuery, Compute Engine and Kubernetes Engine. Google Cloud
- 9 December 2025. MCP joins the Agentic AI Foundation. Anthropic donated MCP to the foundation, a directed fund under the Linux Foundation. MCP blog
- 4 December 2025. Workday closes its Pipedream acquisition, announced on 19 November. Pipedream on X, Workday. See also PopMCP vs Pipedream.
- 25 November 2025. Spec 2025-11-25 released. Experimental tasks, URL mode elicitation and Client ID Metadata Documents. MCP blog
- 8 September 2025. The official MCP Registry launches in preview. Its documentation still says preview. MCP blog, registry status
What to do about it
If you build MCP servers
- Plan the move off sessions. The new revision drops
Mcp-Session-Id, theinitializehandshake and the HTTP GET stream. There is no switch-off date: the maintainers say existing clients and servers keep working, and a server may support both eras at once. - Keep deprecated features out of new code. That means Roots, Sampling, Logging and HTTP+SSE. Dynamic Client Registration still works for backwards compatibility, with Client ID Metadata Documents now preferred.
- Put authentication on every MCP endpoint. The nginx-ui flaw was one endpoint that skipped it. MCP security best practices has a checklist.
- Treat tool output as untrusted input. DuneSlide needed no click from the user, only text the model read.
If you use MCP servers
- Ask which revision a provider's endpoint negotiates. The spec's compatibility table says a client that speaks only 2026-07-28 fails against a legacy-only server, and a legacy client fails against a modern-only server.
- Re-read the terms if you rely on Smithery, Pipedream or Natoma. Each has a new owner.
- Check a community server before you connect it. Arcade's 0.28% is one vendor's grading, but the direction matches the advisories above. Remote vs local MCP servers covers what to look for.
Where PopMCP stands
PopMCP's endpoint is built on the official TypeScript SDK and negotiates MCP revisions up to 2025-11-25. It does not implement 2026-07-28. It uses Streamable HTTP only, with no SSE transport.
Frequently asked questions
What is the latest MCP spec version?
2026-07-28, released on 28 July 2026. It removed protocol-level sessions and the initialize handshake, and added server/discover, Multi Round-Trip Requests and required routing headers.
Is MCP still owned by Anthropic?
No. Anthropic created MCP and donated it in December 2025 to the Agentic AI Foundation, a directed fund under the Linux Foundation. The maintainer structure stayed in place.
Who bought Smithery?
Arcade.dev. It announced the acquisition on 5 August 2026. Smithery's site is still running, and Arcade's announcement points developers there to sign up free.
Who owns Pipedream now?
Workday. It announced the deal on 19 November 2025, and Pipedream said it closed on 4 December 2025.
Will old MCP servers stop working?
Not on any set date. Deprecated features stay in the spec for at least twelve months, and servers can support old and new clients together. The risk is a mismatch: a client that speaks only the new revision cannot use a server that speaks only an old one.
What changed for MCP authorization in 2026?
Clients must validate the issuer returned by the authorization server, and credentials are bound to the server that issued them. Dynamic Client Registration is deprecated in favor of Client ID Metadata Documents. MCP OAuth explained covers the flow.
Where can I follow MCP news?
The official blog at blog.modelcontextprotocol.io and the specification changelog are the primary sources. Vendor changelogs cover their own servers.
Sources
34 references, checked 5 October 2026
- MCP specification 2026-07-28, changelogmodelcontextprotocol.io
- MCP specification 2026-07-28, versioning and compatibilitymodelcontextprotocol.io
- MCP feature lifecycle and deprecation policymodelcontextprotocol.io
- The 2026-07-28 Specification (MCP blog)blog.modelcontextprotocol.io
- The New MCP Roadmap (22 August 2026)blog.modelcontextprotocol.io
- Arcade, ToolBench rescan (30 September 2026)arcade.dev
- Arcade, Cisco Investments (28 September 2026)arcade.dev
- Arcade, Smithery Is Now Part of Arcade.dev (5 August 2026)arcade.dev
- Azure DevOps Remote MCP Server GAdevblogs.microsoft.com
- Ruby SDK 1.0blog.modelcontextprotocol.io
- Cato Networks, DuneSlide (1 July 2026)catonetworks.com
- Cursor advisory, CVE-2026-50548github.com
- Cursor advisory, CVE-2026-50549github.com
- Beta SDKs for the release candidateblog.modelcontextprotocol.io
- Enterprise-Managed Authorizationblog.modelcontextprotocol.io
- Snowflake, intent to acquire Natoma (27 May 2026)snowflake.com
- Snowflake Form 10-Q for the quarter ended 31 July 2026sec.gov
- 2026-07-28 release candidateblog.modelcontextprotocol.io
- AWS MCP Server GAaws.amazon.com
- Salesforce Hosted MCP Servers GAdeveloper.salesforce.com
- OX Security advisory (15 April 2026)ox.security
- Pluto Security, MCPwn (15 April 2026)pluto.security
- nginx-ui security advisory, CVE-2026-33032github.com
- HubSpot remote MCP server GAdevelopers.hubspot.com
- Expanding the MCP Maintainer Teamblog.modelcontextprotocol.io
- The 2026 MCP Roadmap (9 March 2026)blog.modelcontextprotocol.io
- MCP Apps launchblog.modelcontextprotocol.io
- Google, MCP support for Google servicescloud.google.com
- MCP joins the Agentic AI Foundationblog.modelcontextprotocol.io
- Pipedream on X, acquisition closed (4 December 2025)x.com
- Workday announcement (19 November 2025)newsroom.workday.com
- One Year of MCP, the 2025-11-25 releaseblog.modelcontextprotocol.io
- Introducing the MCP Registryblog.modelcontextprotocol.io
- MCP Registry statusmodelcontextprotocol.io