What changed in AI security, Feb 23 to Mar 1, 2026
Feb 23 to Mar 1, 2026 (ISO week 2026-W09). Weeks run Monday to Sunday in UTC.
193 records published, +31 on the previous week: 22 vulnerabilities (-15), 0 incidents (no change), 9 research items (+1), 162 news items (+46), 0 policy items (-1).
Critical and high advisories
Vulnerability records rated critical or high, newest first.- High
CVE-2026-28416: Gradio server-side request forgery when loading a Space with gr.load()
CVE-2026-28416NVD/CVE Database - High
CVE-2026-28414: Gradio absolute path traversal on Windows with Python 3.13+ file read
CVE-2026-28414NVD/CVE Database - High
GHSA-wvj2-96wp-fq3f: MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity
CVE-2026-27896GitHub Advisory Database - High
CVE-2026-3071: Flair deserialization flaw in LanguageModel enables code execution
CVE-2026-3071NVD/CVE Database - Critical
CVE-2026-27966: Langflow CSV Agent code execution through prompt injection
CVE-2026-27966NVD/CVE Database - High
GHSA-2p9h-rqjw-gm92: n8n Vulnerable to Stored XSS via Various Nodes
CVE-2026-27578GitHub Advisory Database - Critical
GHSA-vpcf-gvg4-6qwr: n8n: Expression Sandbox Escape Leads to RCE
CVE-2026-27577GitHub Advisory Database - Critical
GHSA-jjpj-p2wh-qf23: n8n has a Sandbox Escape in its JavaScript Task Runner
CVE-2026-27495GitHub Advisory Database - Critical
CVE-2026-27597: Enclave JavaScript sandbox escape leading to remote code execution
CVE-2026-27597NVD/CVE Database - High
CVE-2026-27608: Parse Dashboard AI Agent API endpoint lacks authorization checks across apps
CVE-2026-27608NVD/CVE Database - Critical
CVE-2026-27595: Parse Dashboard unauthenticated access to database via AI Agent API endpoint
CVE-2026-27595NVD/CVE Database - High
GHSA-mxhj-88fx-4pcv: Fickling: OBJ opcode call invisibility bypasses all safety checks
GitHub Advisory Database - High
GHSA-299v-8pq9-5gjq: New API has Potential XSS in its MarkdownRenderer component
CVE-2026-25802GitHub Advisory Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.No vulnerability published in this week is listed as exploited or has an EPSS score of 10% or more.
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.No tracked package published its first release with an LLM SDK, agent framework or MCP dependency in this week.
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| Model Context Protocol | 7 | 1.3 | +5.8 |
| Model and package supply chain | 6 | 0.5 | +5.5 |
| AI agents | 14 | 9.5 | +4.5 |
| Robotics and embodied AI | 4 | 0.3 | +3.8 |
| Coding assistants | 4 | 3.3 | +0.8 |
Research
Peer-reviewed first, then newest. Showing 8 of 9.I’ve Got Proof! Dataset-Specific Watermarking for Detecting Excessive Dataset Usage in Text-to-Image Diffusion Model Fine-Tuning
Peer-reviewedIEEE Xplore (Security & AI Journals)Split Learning With Local Epoch Regulation and Time-Aware Detection
Peer-reviewedIEEE Xplore (Security & AI Journals)Cert-SSBD: Certified Backdoor Defense With Sample-Specific Smoothing Noises
Peer-reviewedIEEE Xplore (Security & AI Journals)Risk-Aware Privacy Preservation for LLM Inference
Peer-reviewedIEEE Xplore (Security & AI Journals)A Novel Perspective on Gradient Defense: Layer-Specific Protection Against Privacy Leakage
Peer-reviewedIEEE Xplore (Security & AI Journals)FAOSPA: Frequency-Adaptive Orthogonal Spatiotemporal Perturbation Attack for Exploiting Vulnerabilities in Video Anomaly Detection
Peer-reviewedIEEE Xplore (Security & AI Journals)Secure and Efficient Model Training Framework for Multiuser Semantic Communications via Over-the-Air Mixup
Peer-reviewedIEEE Xplore (Security & AI Journals)PPOM-Attack: A Substitute Model-Free Perturbation Prediction and Optimization Method for Black-Box Adversarial Attack Against Face Recognition
Peer-reviewedIEEE Xplore (Security & AI Journals)
Policy and regulation
Newest first.No regulatory or policy records were published in this week.
Generated from the AI Sec Watch database at . Every item links to its record.