What changed in AI security, Feb 16 to Feb 22, 2026
Feb 16 to Feb 22, 2026 (ISO week 2026-W08). Weeks run Monday to Sunday in UTC.
162 records published, +71 on the previous week: 37 vulnerabilities (+20), 0 incidents (no change), 8 research items (+3), 116 news items (+47), 1 policy item (+1).
Critical and high advisories
Vulnerability records rated critical or high, newest first.- High
CVE-2026-27487: OpenClaw OS command injection in macOS Claude CLI keychain credential refresh
CVE-2026-27487NVD/CVE Database - High
CVE-2026-27170: OpenSift server-side request forgery through URL ingest
CVE-2026-27170NVD/CVE Database - High
CVE-2026-27169: OpenSift stored XSS through chat tool UI content rendering
CVE-2026-27169NVD/CVE Database - Critical
CVE-2026-2635: MLflow authentication bypass through default credentials in basic_auth.ini
CVE-2026-2635NVD/CVE Database - High
CVE-2026-2492: TensorFlow HDF5 library local privilege escalation through plugin loading
CVE-2026-2492NVD/CVE Database - High
CVE-2026-2033: MLflow Tracking Server directory traversal in artifact handler file paths
CVE-2026-2033NVD/CVE Database - High
GHSA-wh2j-26j7-9728: Google Cloud Vertex AI has a a vulnerability involving predictable bucket naming
CVE-2026-2473GitHub Advisory Database - High
GHSA-qv8j-hgpc-vrq8: Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)
CVE-2026-2472GitHub Advisory Database - High
CVE-2026-26320: OpenClaw macOS client confirmation dialog hides part of deep link message
CVE-2026-26320NVD/CVE Database - High
CVE-2026-26286: SillyTavern server-side request forgery in asset download endpoint
CVE-2026-26286NVD/CVE Database - Critical
GHSA-xjw9-4gw8-4rqx: Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
CVE-2026-26030GitHub Advisory Database - High
GHSA-w235-x559-36mg: OpenClaw: Docker container escape via unvalidated bind mount config injection
CVE-2026-27002GitHub Advisory Database - High
GHSA-2qj5-gwg2-xwc4: OpenClaw: Unsanitized CWD path injection into LLM prompts
CVE-2026-27001GitHub Advisory Database - High
GHSA-x22m-j5qq-j49m: OpenClaw has two SSRF via sendMediaFeishu and markdown image fetching in Feishu extension
GitHub Advisory Database - High
GHSA-4564-pvr2-qq4h: OpenClaw: Prevent shell injection in macOS keychain credential write
GitHub Advisory Database - High
GHSA-8jpq-5h99-ff5r: OpenClaw has a local file disclosure via sendMediaFeishu in Feishu extension
CVE-2026-26321GitHub Advisory Database - High
GHSA-hv93-r4j3-q65f: OpenClaw Hook Session Key Override Enables Targeted Cross-Session Routing
GitHub Advisory Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.No vulnerability published in this week is listed as exploited or has an EPSS score of 10% or more.
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.No tracked package published its first release with an LLM SDK, agent framework or MCP dependency in this week.
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| AI agents | 13 | 7.0 | +6.0 |
| Coding assistants | 6 | 2.5 | +3.5 |
| Prompt injection and jailbreaks | 4 | 0.8 | +3.3 |
Research
Peer-reviewed first, then newest.Model Inversion Attack Against Federated Unlearning
Peer-reviewedIEEE Xplore (Security & AI Journals)Model Hijacking Attack in Federated Learning
Peer-reviewedIEEE Xplore (Security & AI Journals)Adversarial Training for Graph Neural Networks via Graph Subspace Energy Optimization
Peer-reviewedIEEE Xplore (Security & AI Journals)LLMBA: Efficient Behavior Analytics via Large Pretrained Models in Zero Trust Networks
Peer-reviewedIEEE Xplore (Security & AI Journals)SDkA: Synthetic Data Integrated k-Anonymity Model for Data Sharing With Improved Utility
Peer-reviewedIEEE Xplore (Security & AI Journals)Two Technology Wheels of Fortune
Peer-reviewedIEEE Xplore (Security & AI Journals)Practical Insights Into AI System Product Quality Evaluation
Peer-reviewedIEEE Xplore (Security & AI Journals)Prompt-Based Jailbreaking of Leading LLM Chatbots: A Survey of Attacks and Defenses
Peer-reviewedIEEE Xplore (Security & AI Journals)
Policy and regulation
Newest first.Generated from the AI Sec Watch database at . Every item links to its record.