What changed in AI security, Apr 20 to Apr 26, 2026
Apr 20 to Apr 26, 2026 (ISO week 2026-W17). Weeks run Monday to Sunday in UTC.
169 records published, -8 on the previous week: 52 vulnerabilities (+13), 0 incidents (no change), 6 research items (-17), 111 news items (-3), 0 policy items (-1).
Critical and high advisories
Vulnerability records rated critical or high, newest first. Showing 25 of 37.- High
CVE-2026-7061: A weakness has been identified in Toowiredd chatgpt-mcp-server up to 0.1.0. Affected by this issue is some unknown…
CVE-2026-7061NVD/CVE Database - High
GHSA-v4p8-mg3p-g94g: LiteLLM: Authenticated command execution via MCP stdio test endpoints
GitHub Advisory Database - Critical
GHSA-wpqr-6v78-jr5g: Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses
GitHub Advisory Database - High
GHSA-rp7v-4384-hfrp: k8sGPT has Prompt Injection through its k8sGPT-Operator
GitHub Advisory Database - High
GHSA-q5hj-mxqh-vv77: Claude Code: Trust Dialog Bypass via Git Worktree Spoofing Allows Arbitrary Code Execution
CVE-2026-40068GitHub Advisory Database - Critical
GHSA-r75f-5x8p-qvmc: LiteLLM has SQL Injection in Proxy API key verification
GitHub Advisory Database - High
GHSA-mw35-8rx3-xf9r: Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization
CVE-2026-41486Hugging Face Security Advisories - High
GHSA-xqmj-j6mv-4862: LiteLLM: Server-Side Template Injection in /prompts/test endpoint
GitHub Advisory Database - Critical
CVE-2026-41274: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the…
CVE-2026-41274NVD/CVE Database - Critical
CVE-2026-33102: Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate…
CVE-2026-33102NVD/CVE Database - Critical
GHSA-c2jg-5cp7-6wc7: Pipecat: Remote Code Execution by Pickle Deserialization Through LivekitFrameSerializer
CVE-2025-62373GitHub Advisory Database - High
CVE-2026-41279: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the…
CVE-2026-41279NVD/CVE Database - High
CVE-2026-41278: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GET…
CVE-2026-41278NVD/CVE Database - High
CVE-2026-41277: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass…
CVE-2026-41277NVD/CVE Database - Critical
CVE-2026-41276: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this…
CVE-2026-41276NVD/CVE Database - High
CVE-2026-41273: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise…
CVE-2026-41273NVD/CVE Database - High
CVE-2026-41272: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the core…
CVE-2026-41272NVD/CVE Database - High
CVE-2026-41271: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side…
CVE-2026-41271NVD/CVE Database - High
CVE-2026-41270: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side…
CVE-2026-41270NVD/CVE Database - High
CVE-2026-41269: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow…
CVE-2026-41269NVD/CVE Database - Critical
CVE-2026-41268: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is…
CVE-2026-41268NVD/CVE Database - High
CVE-2026-41267: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper…
CVE-2026-41267NVD/CVE Database - High
CVE-2026-41266: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0…
CVE-2026-41266NVD/CVE Database - Critical
CVE-2026-41265: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific…
CVE-2026-41265NVD/CVE Database - Critical
CVE-2026-41138: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, there is a…
CVE-2026-41138NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.| Advisory | Exploitation | EPSS | Published |
|---|---|---|---|
| CVE-2026-39987: Marimo Remote Code Execution Vulnerability CVE-2026-39987CISA Known Exploited Vulnerabilities | Known exploited | 37.9% |
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| scao | PyPI | Hugging Face Hub / Transformers | 0.1.0 | |
| jupyter-ai-tools | PyPI | Model Context Protocol SDK | 0.5.0 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| Coding assistants | 7 | 2.0 | +5.0 |
| Prompt injection and jailbreaks | 7 | 3.5 | +3.5 |
| AI agents | 17 | 15.0 | +2.0 |
| Model Context Protocol | 5 | 4.5 | +0.5 |
Research
Peer-reviewed first, then newest.Benchmarking the effectiveness of multi-agent LLMs in collaborative privacy threat modeling with <span class="small-caps">LINDDUN GO</span>
Peer-reviewedElsevier Security JournalsR-FLoRA: Residual-Statistic-Gated Low-Rank Adaptation for Single-Image Face Morphing Attack Detection
Peer-reviewedIEEE Xplore (Security & AI Journals)Fingerprint-based watermarking for protecting and tracing black-box NLP models
Peer-reviewedElsevier Security JournalsForgettable Federated Linear Learning With Certified Data Unlearning
Peer-reviewedIEEE Xplore (Security & AI Journals)AI-Enhanced Cybersecurity in Edge Computing: Threats, Solutions, and Future Directions
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)Optimizing stealthiness in universal adversarial perturbations via class-selective and perceptual similarity metrics
Peer-reviewedElsevier Security Journals
Policy and regulation
Newest first.No regulatory or policy records were published in this week.
Generated from the AI Sec Watch database at . Every item links to its record.