What changed in AI security, May 4 to May 10, 2026
May 4 to May 10, 2026 (ISO week 2026-W19). Weeks run Monday to Sunday in UTC.
188 records published, +8 on the previous week: 50 vulnerabilities (+19), 0 incidents (no change), 16 research items (-2), 120 news items (-11), 2 policy items (+2).
Critical and high advisories
Vulnerability records rated critical or high, newest first. Showing 25 of 33.- High
CVE-2026-41705: Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via…
CVE-2026-41705NVD/CVE Database - High
CVE-2026-44286: FastGPT is an AI Agent building platform. Prior to version 4.14.17, an unauthenticated Server-Side Request Forgery…
CVE-2026-44286NVD/CVE Database - High
CVE-2026-42345: FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in…
CVE-2026-42345NVD/CVE Database - High
CVE-2026-42339: New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. In versions…
CVE-2026-42339NVD/CVE Database - Critical
CVE-2026-42302: FastGPT is an AI Agent building platform. From version 4.14.10 to before version 4.14.13, the agent-sandbox component…
CVE-2026-42302NVD/CVE Database - High
GHSA-pjwx-r37v-7724: LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists
CVE-2026-44843GitHub Advisory Database - High
GHSA-4vg5-rp28-gvjf: Open WebUI has Improper Authorization Control
CVE-2026-44567GitHub Advisory Database - Critical
GHSA-5c57-rqjx-35g2: Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerability
CVE-2026-44211GitHub Advisory Database - High
GHSA-gphh-9q3h-jgpp: banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
CVE-2026-44209GitHub Advisory Database - High
GHSA-8g7g-hmwm-6rv2: n8n-mcp affected by path traversal, redirect-following SSRF, and telemetry payload exposure
GitHub Advisory Database - High
GHSA-cmrh-wvq6-wm9r: n8n-mcp webhook and API client paths has an authenticated SSRF
CVE-2026-44694GitHub Advisory Database - High
CVE-2026-41487: Langfuse is an open source large language model engineering platform. From version 3.68.0 to before version 3.167.0…
CVE-2026-41487NVD/CVE Database - Critical
CVE-2026-42271: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before…
CVE-2026-42271NVD/CVE Database - High
CVE-2026-42261: PromptHub is an all-in-one AI toolbox for prompt, skill, and agent management. From version 0.4.9 to before version…
CVE-2026-42261NVD/CVE Database - Critical
CVE-2026-42208: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before…
CVE-2026-42208NVD/CVE Database - Critical
CVE-2026-42203: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.80.5 to before…
CVE-2026-42203NVD/CVE Database - High
CVE-2026-35435: Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges…
CVE-2026-35435NVD/CVE Database - High
CVE-2026-33111: Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge)…
CVE-2026-33111NVD/CVE Database - High
CVE-2026-32207: Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows…
CVE-2026-32207NVD/CVE Database - High
CVE-2026-26164: Improper neutralization of special elements in output used by a downstream component ('injection') in M365 Copilot…
CVE-2026-26164NVD/CVE Database - High
CVE-2026-26129: Improper neutralization of special elements in M365 Copilot allows an unauthorized attacker to disclose information…
CVE-2026-26129NVD/CVE Database - High
GHSA-98h9-4798-4q5v: Diffusers has a `trust_remote_code` bypass via `custom_pipeline` and local custom components
CVE-2026-44513Hugging Face Security Advisories - High
GHSA-j7w6-vpvq-j3gm: Duplicate Advisory: Diffusers has a `trust_remote_code` bypass via `custom_pipeline` and local custom components
Hugging Face Security Advisories - Critical
GHSA-9h64-2846-7x7f: Axonflow fixed bugs by implementing multi-tenant isolation and access-control hardening
GitHub Advisory Database - High
GHSA-mgx6-5cf9-rr43: Keras vulnerable to DoS via Malicious .keras Model (HDF5 Shape Bomb Causes Petabyte Allocation in KerasFileEditor)
CVE-2026-0897GitHub Advisory Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.| Advisory | Exploitation | EPSS | Published |
|---|---|---|---|
| CVE-2026-42271: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before… CVE-2026-42271NVD/CVE Database | Known exploited | 92.6% | |
| CVE-2026-42208: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before… CVE-2026-42208NVD/CVE Database | Known exploited | 5.8% |
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| teich | PyPI | Hugging Face Hub / Transformers | 0.1.1a1 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| AI agents | 23 | 12.8 | +10.3 |
| Inference infrastructure | 6 | 2.3 | +3.8 |
| Coding assistants | 6 | 3.3 | +2.8 |
Research
Peer-reviewed first, then newest. Showing 8 of 16.Adaptive active-defense hardening of ML-based NIDS against RL-driven adversaries: A comparative analysis with static defenses
Peer-reviewedElsevier Security JournalsSBOMs into Agentic AIBOMs: Schema Extensions, Agentic Orchestration and Reproducibility Evaluation
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)QAEAS: A quantum adaptive ensemble attack system against robust deep neural networks
Peer-reviewedElsevier Security JournalsFacial image encryption algorithm based on feature recognition and chaotic scrambling
Peer-reviewedElsevier Security JournalsDeep video inpainting and video inpainting detection: A comprehensive survey from deep learning perspective
Peer-reviewedElsevier Security JournalsInterpretable Semantic Medical Image Segmentation With Style and Confidence
Peer-reviewedIEEE Xplore (Security & AI Journals)An Integrated Speech Tampering Detection Framework With Deep Neural Networks
Peer-reviewedIEEE Xplore (Security & AI Journals)Automatic Red Teaming LLM-Based Agents With Model Context Protocol Tools
Peer-reviewedIEEE Xplore (Security & AI Journals)
Policy and regulation
Newest first.Generated from the AI Sec Watch database at . Every item links to its record.