What changed in AI security, Feb 9 to Feb 15, 2026
Feb 9 to Feb 15, 2026 (ISO week 2026-W07). Weeks run Monday to Sunday in UTC.
91 records published, +38 on the previous week: 17 vulnerabilities (-4), 0 incidents (no change), 5 research items (-4), 69 news items (+46), 0 policy items (no change).
Critical and high advisories
Vulnerability records rated critical or high, newest first.- Critical
CVE-2026-26190: Milvus authentication bypass through debug and REST API endpoints on port 9091
CVE-2026-26190NVD/CVE Database - High
CVE-2026-26268: Cursor sandbox escape via writing .git configuration
CVE-2026-26268NVD/CVE Database - High
CVE-2026-1669: Keras arbitrary file read in model loading via HDF5 integration
CVE-2026-1669NVD/CVE Database - High
CVE-2026-26029: sf-mcp-server command injection through Salesforce CLI commands
CVE-2026-26029NVD/CVE Database - High
CVE-2026-21523: GitHub Copilot and Visual Studio race condition allowing network code execution
CVE-2026-21523NVD/CVE Database - High
CVE-2026-21516: GitHub Copilot command injection allows remote code execution over a network
CVE-2026-21516NVD/CVE Database - High
CVE-2026-21257: GitHub Copilot and Visual Studio command injection allows privilege elevation
CVE-2026-21257NVD/CVE Database - High
CVE-2026-21256: GitHub Copilot and Visual Studio command injection over network
CVE-2026-21256NVD/CVE Database - Critical
CVE-2026-1868: GitLab has remediated a vulnerability in the Duo Workflow Service component of GitLab AI Gateway affecting all versions…
CVE-2026-1868NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.No vulnerability published in this week is listed as exploited or has an EPSS score of 10% or more.
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| @stripe/agent-toolkit | npm | Model Context Protocol SDK, Vercel AI SDK | 0.9.0 | |
| @n8n/ai-utilities | npm | LangChain | 0.2.0 | |
| bashkit | PyPI | LangChain, Pydantic AI | 0.1.4 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| Coding assistants | 7 | 0.8 | +6.3 |
| Model Context Protocol | 4 | 0.8 | +3.3 |
| AI agents | 8 | 6.0 | +2.0 |
| Adversarial machine learning | 3 | 1.0 | +2.0 |
Research
Peer-reviewed first, then newest.Momentum-Based Zeroth-Order Gradient Method for Distributed Black-Box Optimization
Peer-reviewedIEEE Xplore (Security & AI Journals)Enhancing Adversarial Transferability With Cost-Efficient Landscape Flattening
Peer-reviewedIEEE Xplore (Security & AI Journals)Dual Frequency Branch Framework With Reconstructed Sliding Windows Attention for AI-Generated Image Detection
Peer-reviewedIEEE Xplore (Security & AI Journals)Practical and Flexible Backdoor Attack Against Deep Learning Models via Shell Code Injection
Peer-reviewedIEEE Xplore (Security & AI Journals)AdvScan: Black-Box Adversarial Example Detection at Runtime Through Power Analysis
Peer-reviewedIEEE Xplore (Security & AI Journals)
Policy and regulation
Newest first.No regulatory or policy records were published in this week.
Generated from the AI Sec Watch database at . Every item links to its record.