What changed in AI security, Jan 5 to Jan 11, 2026
Jan 5 to Jan 11, 2026 (ISO week 2026-W02). Weeks run Monday to Sunday in UTC.
11 records published, -12 on the previous week: 9 vulnerabilities (+5), 0 incidents (no change), 2 research items (-15), 0 news items (-2), 0 policy items (no change).
Critical and high advisories
Vulnerability records rated critical or high, newest first.- Critical
CVE-2025-69222: LibreChat SSRF via Actions feature in default configuration
CVE-2025-69222NVD/CVE Database - High
CVE-2025-69220: LibreChat improper access control on agent file context uploads
CVE-2025-69220NVD/CVE Database - High
CVE-2025-66786: OpenAirInterface CN5G AMF denial of service via malicious JSON requests
CVE-2025-66786NVD/CVE Database - High
CVE-2026-0621: Anthropic MCP TypeScript SDK ReDoS in UriTemplate array pattern matching
CVE-2026-0621NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.No vulnerability published in this week is listed as exploited or has an EPSS score of 10% or more.
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| toolbox-adk | PyPI | Google Agent Development Kit | 0.5.5 | |
| azure-ai-projects | PyPI | OpenAI SDK | 2.0.0b3 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.No topic had at least 3 records in this week and more than its mean over the 4 previous weeks.
Research
Peer-reviewed first, then newest.Policy and regulation
Newest first.No regulatory or policy records were published in this week.
Generated from the AI Sec Watch database at . Every item links to its record.