The Model Context Protocol, introduced by Anthropic in 2024, is transitioning to an enterprise-ready version on July 28, 2026, giving companies a 12-month window to prepare. While the new stateless protocol eliminates some vulnerabilities like session hijacking, security firm Akamai warns it introduces new attack surfaces including workflow hijacking risks, potential data leakage through HTTP headers, and denial-of-service vectors from long-running tasks. The shift fundamentally moves security responsibilities from the protocol layer to individual developers and platform operators, requiring in-house teams to carefully implement and secure their MCP servers over the next year.