What changed in AI security, Jan 12 to Jan 18, 2026
Jan 12 to Jan 18, 2026 (ISO week 2026-W03). Weeks run Monday to Sunday in UTC.
22 records published, +11 on the previous week: 11 vulnerabilities (+2), 0 incidents (no change), 10 research items (+8), 1 news item (+1), 0 policy items (no change).
Critical and high advisories
Vulnerability records rated critical or high, newest first.- Critical
CVE-2026-22708: Cursor shell built-ins bypass allowlist approval in Auto-Run Mode
CVE-2026-22708NVD/CVE Database - High
CVE-2026-0532: Google Gemini connector file disclosure via crafted credentials JSON payload
CVE-2026-0532NVD/CVE Database - Critical
CVE-2026-22686: Enclave VM sandbox escape via host Error object prototype chain
CVE-2026-22686NVD/CVE Database - High
CVE-2025-15514: Ollama null pointer dereference in multi-modal image processing via /api/chat
CVE-2025-15514NVD/CVE Database - High
CVE-2024-58340: LangChain ReDoS in MRKLOutputParser.parse() via crafted model output
CVE-2024-58340NVD/CVE Database - High
CVE-2024-58339: LlamaIndex VannaQueryEngine uncontrolled resource consumption in custom_query
CVE-2024-58339NVD/CVE Database - High
CVE-2024-14021: LlamaIndex unsafe deserialization in BGEM3Index.load_from_disk
CVE-2024-14021NVD/CVE Database - Critical
CVE-2026-22252: LibreChat MCP stdio transport accepts arbitrary commands without validation
CVE-2026-22252NVD/CVE Database - High
CVE-2026-22812: OpenCode unauthenticated HTTP server allows arbitrary shell command execution
CVE-2026-22812NVD/CVE Database - High
CVE-2025-14279: MLFlow DNS rebinding through missing Origin header validation in REST server
CVE-2025-14279NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.| Advisory | Exploitation | EPSS | Published |
|---|---|---|---|
| CVE-2026-22812: OpenCode unauthenticated HTTP server allows arbitrary shell command execution CVE-2026-22812NVD/CVE Database | Not listed | 16.5% |
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| mamba-ssm | PyPI | Hugging Face Hub / Transformers | 2.3.0 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| AI agents | 4 | 0.3 | +3.8 |
Research
Peer-reviewed first, then newest. Showing 8 of 10.From Generation to Detection: Multimodal Generative AI and the Threat of Automated Misinformation
Peer-reviewedIEEE Xplore (Security & AI Journals)Practical Continual Forgetting for Pre-Trained Vision Models
Peer-reviewedIEEE Xplore (Security & AI Journals)BlindU: Blind Machine Unlearning Without Revealing Erasing Data
Peer-reviewedIEEE Xplore (Security & AI Journals)Robust Physics-Based Deep MRI Reconstruction via Diffusion Purification
Peer-reviewedIEEE Xplore (Security & AI Journals)SLeak: Multi-Target Privacy Stealing Attack Against Split Learning
Peer-reviewedIEEE Xplore (Security & AI Journals)GHAttack: Generative Adversarial Attacks on Heterogeneous Graph Neural Networks
Peer-reviewedIEEE Xplore (Security & AI Journals)Armor: Shielding Unlearnable Examples Against Data Augmentation
Peer-reviewedIEEE Xplore (Security & AI Journals)Model Lineage Analysis: Determination and Closeness Measurement
Peer-reviewedIEEE Xplore (Security & AI Journals)
Policy and regulation
Newest first.No regulatory or policy records were published in this week.
Generated from the AI Sec Watch database at . Every item links to its record.