What changed in AI security, Mar 16 to Mar 22, 2026
Mar 16 to Mar 22, 2026 (ISO week 2026-W12). Weeks run Monday to Sunday in UTC.
157 records published, -13 on the previous week: 33 vulnerabilities (+15), 0 incidents (no change), 25 research items (+7), 97 news items (-37), 2 policy items (+2).
Critical and high advisories
Vulnerability records rated critical or high, newest first.- High
GHSA-ph9w-r52h-28p7: langflow: /profile_pictures/{folder_name}/{file_name} endpoint file reading
CVE-2026-33497GitHub Advisory Database - High
GHSA-7grx-3xcx-2xv5: langflow has Unauthenticated IDOR on Image Downloads
CVE-2026-33484GitHub Advisory Database - High
CVE-2026-33075: FastGPT workflow code execution and secret exfiltration by external contributors
CVE-2026-33075NVD/CVE Database - Critical
CVE-2026-32950: SQLBot SQL injection via uploadExcel endpoint enables remote code execution
CVE-2026-32950NVD/CVE Database - High
CVE-2026-32949: SQLBot server-side request forgery via datasource check endpoint
CVE-2026-32949NVD/CVE Database - Critical
CVE-2026-32622: SQLBot stored prompt injection via Excel upload enables code execution
CVE-2026-32622NVD/CVE Database - High
CVE-2026-26137: Microsoft 365 Copilot Business Chat server-side request forgery over the network
CVE-2026-26137NVD/CVE Database - Critical
GHSA-g2j9-7rj2-gm6c: Langflow has an Arbitrary File Write (RCE) via v2 API
CVE-2026-33309GitHub Advisory Database - High
GHSA-89xv-2j6f-qhc8: Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk
CVE-2026-33252GitHub Advisory Database - High
GHSA-q382-vc8q-7jhj: Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk
GitHub Advisory Database - High
GHSA-mmgp-wc2j-qcv7: Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings File
CVE-2026-33068GitHub Advisory Database - High
CVE-2025-15031: MLflow arbitrary file write during pyfunc extraction via tar archive entries
CVE-2025-15031NVD/CVE Database - Critical
GHSA-gjgx-rvqr-6w6v: Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
CVE-2026-33057GitHub Advisory Database - Critical
GHSA-8qvf-mr4w-9x2c: Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
CVE-2026-33054GitHub Advisory Database - High
GHSA-rf6x-r45m-xv3w: Langflow is Missing Ownership Verification in API Key Deletion (IDOR)
CVE-2026-33053GitHub Advisory Database - Critical
GHSA-vwmf-pq79-vjvx: Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint
CVE-2026-33017GitHub Advisory Database - High
Arbitrary code execution via crafted project files in Kiro IDE
AWS Security Bulletins - High
CVE-2026-4269 - Improper S3 ownership verification in Bedrock AgentCore Starter Toolkit
AWS Security Bulletins - High
CVE-2026-4270 - AWS API MCP File Access Restriction Bypass
AWS Security Bulletins - High
GHSA-hqmj-h5c6-369m: ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack
CVE-2026-28500GitHub Advisory Database - High
GHSA-5h2m-4q8j-pqpj: FastMCP OAuth Proxy token reuse across MCP servers
CVE-2025-69196GitHub Advisory Database - High
CVE-2026-26133: M365 Copilot AI command injection allows information disclosure
CVE-2026-26133NVD/CVE Database - High
CVE-2026-25083: GROWI OpenAI thread and message API endpoints lack authorization checks
CVE-2026-25083NVD/CVE Database - Critical
CVE-2025-15060: claude-hovercraft executeClaudeCode command injection remote code execution
CVE-2025-15060NVD/CVE Database - High
CVE-2025-14287: MLflow command injection through the container parameter in SageMaker CLI
CVE-2025-14287NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.| Advisory | Exploitation | EPSS | Published |
|---|---|---|---|
| GHSA-vwmf-pq79-vjvx: Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint CVE-2026-33017GitHub Advisory Database | Known exploited | 24.8% |
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| promptlayer | PyPI | Claude Agent SDK, OpenAI Agents SDK | 1.1.1 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| Model Context Protocol | 8 | 3.8 | +4.3 |
| Coding assistants | 7 | 4.0 | +3.0 |
| Retrieval-augmented generation | 3 | 0.5 | +2.5 |
| Deepfakes and impersonation | 4 | 2.5 | +1.5 |
| AI agents | 18 | 17.8 | +0.3 |
Research
Peer-reviewed first, then newest. Showing 8 of 25.An efficient hierarchical secret sharing for privacy-preserving distributed gradient descent algorithm
Peer-reviewedElsevier Security JournalsA Dual-Purpose Framework for Backdoor Defense and Backdoor Amplification in Diffusion Models
Peer-reviewedIEEE Xplore (Security & AI Journals)N Truths and a Lie: Consistency-Based Backdoor Defense for Vertical Federated Learning
Peer-reviewedIEEE Xplore (Security & AI Journals)Boosting Active Defense Persistence: A Two-Stage Defense Framework Combining Interruption and Poisoning Against Deepfake
Peer-reviewedIEEE Xplore (Security & AI Journals)FORCE: Byzantine-Resilient Decentralized Federated Learning via Game-Theoretic Contribution Aggregation
Peer-reviewedIEEE Xplore (Security & AI Journals)Alignment of Diffusion Models: Fundamentals, Challenges, and Future
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)Selective Forgetting in Machine Learning and Beyond: A Survey
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)A Systematic Review on Human Roles, Solutions, and Methodological Approaches to Address Bias in AI
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)
Policy and regulation
Newest first.Generated from the AI Sec Watch database at . Every item links to its record.