What changed in AI security, Mar 9 to Mar 15, 2026
Mar 9 to Mar 15, 2026 (ISO week 2026-W11). Weeks run Monday to Sunday in UTC.
170 records published, -30 on the previous week: 18 vulnerabilities (-22), 0 incidents (no change), 18 research items (-4), 134 news items (-4), 0 policy items (no change).
Critical and high advisories
Vulnerability records rated critical or high, newest first.- High
CVE-2026-31944: LibreChat MCP OAuth callback stores tokens for the wrong user
CVE-2026-31944NVD/CVE Database - High
GHSA-gg5m-55jj-8m5g: Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
CVE-2026-32247GitHub Advisory Database - High
GCP-2026-012
Google Cloud Security Bulletins - High
GCP-2026-011
Google Cloud Security Bulletins - High
CVE-2026-31975: Cloud CLI OS command injection via WebSocket shell
CVE-2026-31975NVD/CVE Database - Critical
CVE-2026-31862: Cloud CLI Git API endpoints allow OS command execution via user parameters
CVE-2026-31862NVD/CVE Database - High
CVE-2026-31861: Cloud CLI command injection through the git-config endpoint
CVE-2026-31861NVD/CVE Database - High
CVE-2026-31854: Cursor command execution via indirect prompt injection from visited websites
CVE-2026-31854NVD/CVE Database - High
CVE-2026-30741: OpenClaw Agent Platform remote code execution via request-side prompt injection
CVE-2026-30741NVD/CVE Database - Critical
CVE-2025-68613: n8n Improper Control of Dynamically-Managed Code Resources Vulnerability
CVE-2025-68613CISA Known Exploited Vulnerabilities - High
CVE-2026-31829: Flowise SSRF through HTTP Node in AgentFlow and Chatflow
CVE-2026-31829NVD/CVE Database - Critical
GHSA-xjgw-4wvw-rgm4: MCP Atlassian has an arbitrary file write leading to arbitrary code execution via unconstrained download_path in confluence_download_attachment
CVE-2026-27825GitHub Advisory Database - High
GHSA-7r34-79r5-rcc9: MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers
CVE-2026-27826GitHub Advisory Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.| Advisory | Exploitation | EPSS | Published |
|---|---|---|---|
| CVE-2025-68613: n8n Improper Control of Dynamically-Managed Code Resources Vulnerability CVE-2025-68613CISA Known Exploited Vulnerabilities | Known exploited | 99.0% |
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| nemo-gym | PyPI | Anthropic SDK, Model Context Protocol SDK, OpenAI SDK | 0.2.0 | |
| ddgs | PyPI | Model Context Protocol SDK | 9.11.3 | |
| langchain-plaid | PyPI | LangChain | 0.1.0 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| AI agents | 30 | 12.3 | +17.8 |
| Deepfakes and impersonation | 7 | 0.8 | +6.3 |
| Prompt injection and jailbreaks | 5 | 2.0 | +3.0 |
Research
Peer-reviewed first, then newest. Showing 8 of 18.Unveiling Deepfakes: A Frequency-Aware Triple Branch Network for Deepfake Detection
Peer-reviewedIEEE Xplore (Security & AI Journals)SMInject: Specious Malignant Injection Attacks With Semantically-Enhanced Tokens in Cross-Modal Retrieval
Peer-reviewedIEEE Xplore (Security & AI Journals)Fraud-RLA: A Reinforcement Learning Adversarial Attack Against Credit Card Fraud Detection
Peer-reviewedIEEE Xplore (Security & AI Journals)Robust Reinforcement Learning via Leveraging Historically Optimal Policy With Regulation of Performance
Peer-reviewedIEEE Xplore (Security & AI Journals)Toward Generalizable Deepfake Detection via Forgery-Aware Audio–Visual Adaptation: A Variational Bayesian Approach
Peer-reviewedIEEE Xplore (Security & AI Journals)Adversarial Semantic and Label Perturbation Attack for Pedestrian Attribute Recognition
Peer-reviewedIEEE Xplore (Security & AI Journals)Nappa: NNA-Compatible and Privacy-Preserving DNN Training Framework via Vector Decomposition
Peer-reviewedIEEE Xplore (Security & AI Journals)Comments on “APFed: Anti-Poisoning Attacks in Privacy-Preserving Heterogeneous Federated Learning”
Peer-reviewedIEEE Xplore (Security & AI Journals)
Policy and regulation
Newest first.No regulatory or policy records were published in this week.
Generated from the AI Sec Watch database at . Every item links to its record.