What changed in AI security, Jan 19 to Jan 25, 2026
Jan 19 to Jan 25, 2026 (ISO week 2026-W04). Weeks run Monday to Sunday in UTC.
30 records published, +8 on the previous week: 22 vulnerabilities (+11), 0 incidents (no change), 4 research items (-6), 4 news items (+3), 0 policy items (no change).
Critical and high advisories
Vulnerability records rated critical or high, newest first.- Critical
CVE-2025-13374: Kalrav AI Agent WordPress plugin arbitrary file upload via kalrav_upload_file
CVE-2025-13374NVD/CVE Database - Critical
CVE-2026-24399: ChatterMate client-side injection through iframe javascript URI in chat input
CVE-2026-24399NVD/CVE Database - High
CVE-2026-0772: Langflow disk cache deserialization of untrusted data leading to code execution
CVE-2026-0772NVD/CVE Database - Critical
CVE-2026-0771: Langflow PythonFunction code injection allowing remote code execution
CVE-2026-0771NVD/CVE Database - Critical
CVE-2026-0770: Langflow remote code execution through exec_globals in the validate endpoint
CVE-2026-0770NVD/CVE Database - Critical
CVE-2026-0769: Langflow eval_custom_component_code eval injection enables remote code execution
CVE-2026-0769NVD/CVE Database - Critical
CVE-2026-0768: Langflow code injection in validate endpoint allows remote code execution
CVE-2026-0768NVD/CVE Database - High
CVE-2025-15063: Ollama MCP Server execAsync command injection leading to remote code execution
CVE-2025-15063NVD/CVE Database - High
CVE-2026-0757: MCP Manager for Claude Desktop command injection sandbox escape
CVE-2026-0757NVD/CVE Database - High
CVE-2026-0755: gemini-mcp-tool command injection in execAsync allows remote code execution
CVE-2026-0755NVD/CVE Database - Critical
CVE-2026-24307: M365 Copilot improper input validation allows information disclosure
CVE-2026-24307NVD/CVE Database - High
CVE-2026-21521: Copilot information disclosure via improper neutralization of escape sequences
CVE-2026-21521NVD/CVE Database - High
CVE-2026-21520: Copilot Studio exposure of sensitive information to unauthorized actor
CVE-2026-21520NVD/CVE Database - High
CVE-2025-65098: Typebot client-side script execution exposes stored credentials
CVE-2025-65098NVD/CVE Database - High
CVE-2026-22807: vLLM arbitrary code execution through Hugging Face auto_map model loading
CVE-2026-22807NVD/CVE Database - High
CVE-2026-21852: Claude Code project-load flow leaks API keys before trust prompt
CVE-2026-21852NVD/CVE Database - High
CVE-2025-66960: Ollama denial of service through GGUF v1 string length parsing
CVE-2025-66960NVD/CVE Database - High
CVE-2025-66959: ollama denial of service via GGUF decoder
CVE-2025-66959NVD/CVE Database - High
CVE-2025-33233: NVIDIA Merlin Transformers4Rec code injection vulnerability
CVE-2025-33233NVD/CVE Database - High
CVE-2026-23842: ChatterBot denial of service through concurrent get_response() calls
CVE-2026-23842NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.| Advisory | Exploitation | EPSS | Published |
|---|---|---|---|
| CVE-2026-0770: Langflow remote code execution through exec_globals in the validate endpoint CVE-2026-0770NVD/CVE Database | Known exploited | 63.0% | |
| CVE-2026-0769: Langflow eval_custom_component_code eval injection enables remote code execution CVE-2026-0769NVD/CVE Database | Not listed | 41.7% | |
| CVE-2026-21852: Claude Code project-load flow leaks API keys before trust prompt CVE-2026-21852NVD/CVE Database | Not listed | 27.9% | |
| CVE-2026-0768: Langflow code injection in validate endpoint allows remote code execution CVE-2026-0768NVD/CVE Database | Not listed | 23.2% |
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| Inference infrastructure | 4 | 0.5 | +3.5 |
| Coding assistants | 3 | 0.3 | +2.8 |
| AI agents | 3 | 1.3 | +1.8 |
Research
Peer-reviewed first, then newest.A Survey of Progress in LLM Alignment From the Perspective of Reward Design
Peer-reviewedIEEE Xplore (Security & AI Journals)Generative Artificial Intelligence for Knowledge-Driven Industries: Leveraging Collective Intelligence to Address Discourse Patterns and Sectoral Diffusion
Peer-reviewedAIS eLibrary (Journal of AIS, CAIS, etc.)Generative Artificial Intelligence in Information Systems Education: Benefits, Challenges and Recommendations
Peer-reviewedAIS eLibrary (Journal of AIS, CAIS, etc.)Words Become SQL: Securing AI Assistants That Talk to Databases
Peer-reviewedIEEE Xplore (Security & AI Journals)
Policy and regulation
Newest first.No regulatory or policy records were published in this week.
Generated from the AI Sec Watch database at . Every item links to its record.