What changed in AI security, May 11 to May 17, 2026
May 11 to May 17, 2026 (ISO week 2026-W20). Weeks run Monday to Sunday in UTC.
230 records published, +42 on the previous week: 92 vulnerabilities (+42), 1 incident (+1), 15 research items (-1), 118 news items (-2), 4 policy items (+2).
Critical and high advisories
Vulnerability records rated critical or high, newest first. Showing 25 of 76.- High
CVE-2026-8756: A vulnerability has been found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c. The impacted…
CVE-2026-8756NVD/CVE Database - High
CVE-2026-45401: Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the…
CVE-2026-45401NVD/CVE Database - High
CVE-2026-44556: Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the…
CVE-2026-44556NVD/CVE Database - High
GHSA-rpj4-7x2v-wjrf: Budibase: SSRF in AI Extract File Automation Step via Missing IP Blacklist Validation
CVE-2026-45548GitHub Advisory Database - High
CVE-2026-45539: Microsoft APM is an open-source, community-driven dependency manager for AI agents. From 0.5.4 to 0.12.4, two primitive…
CVE-2026-45539NVD/CVE Database - High
CVE-2026-44641: Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.8.12, Microsoft APM…
CVE-2026-44641NVD/CVE Database - High
GHSA-3363-2ph6-35wh: Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator
CVE-2026-44716GitHub Advisory Database - High
CVE-2026-2652: A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes…
CVE-2026-2652NVD/CVE Database - High
GHSA-5v57-8rxj-3p2r: python-utcp: Full Process Environment Exposed to CLI Subprocess - Secrets Leakage via Command Injection
CVE-2026-45370GitHub Advisory Database - Critical
GHSA-72w5-pf8h-xfp4: DeepSeek TUI: task_create Insecure Defaults Enable RCE via Prompt Injection in Project Files
CVE-2026-45374GitHub Advisory Database - Critical
GHSA-wx44-2q6h-j6p8: DeepSeek TUI: run_tests Tool Enables RCE via Malicious Repository Without Approval
CVE-2026-45311GitHub Advisory Database - High
GHSA-96ff-gc8g-wpvg: DeepSeek TUI has SSRF via HTTP Redirect Bypass in fetch_url Tool
CVE-2026-45310GitHub Advisory Database - High
GHSA-h3ww-q6xx-w7x3: Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts
CVE-2026-45675GitHub Advisory Database - High
GHSA-26g9-27vm-x3q8: Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion
CVE-2026-45671GitHub Advisory Database - High
GHSA-r472-mw7m-967f: Open WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints
CVE-2026-45402GitHub Advisory Database - High
GHSA-4g37-7p2c-38r9: Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base Access Controls
CVE-2026-45398GitHub Advisory Database - High
CVE-2026-8597: Missing integrity verification in the Triton inference handler in Amazon SageMaker Python SDK v2 before v2.257.2 and v3…
CVE-2026-8597NVD/CVE Database - High
Issue with Amazon SageMaker Python SDK - Model artifact integrity verification issues (CVE-2026-8596 &: CVE-2026-8597)
AWS Security Bulletins - High
GHSA-wxrr-jp8m-qq7f: FlowiseAI: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover
GitHub Advisory Database - High
GHSA-mq53-pc65-wjc4: FlowiseAI: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover
GitHub Advisory Database - High
GHSA-7j65-65cr-6644: FlowiseAI: DatasetRow create+update mass-assignment allows cross-workspace row takeover
GitHub Advisory Database - High
GHSA-5h9v-837x-m97r: FlowiseAI: Dataset create+update mass-assignment allows cross-workspace dataset takeover
GitHub Advisory Database - High
GHSA-728h-4mwj-f2p4: FlowiseAI: CustomTemplate create+update mass-assignment allows cross-workspace template takeover
GitHub Advisory Database - High
GHSA-78pr-c5x5-jggc: FlowiseAI: Assistant create+update mass-assignment allows cross-workspace assistant takeover
GitHub Advisory Database - High
GHSA-hmg2-jjjx-jcp2: FlowiseAI: Vector Store No Permission Checks
GitHub Advisory Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.No vulnerability published in this week is listed as exploited or has an EPSS score of 10% or more.
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| fasta2a | PyPI | Pydantic AI | 0.6.1 | |
| milvus-lite | PyPI | FAISS | 3.0 | |
| fastmcp-slim | PyPI | Anthropic SDK, Google Gemini SDK, Model Context Protocol SDK, OpenAI SDK | 3.3.0b1 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| AI agents | 25 | 15.8 | +9.3 |
| Model and package supply chain | 8 | 1.3 | +6.8 |
| Deepfakes and impersonation | 6 | 2.0 | +4.0 |
| Retrieval-augmented generation | 4 | 0.5 | +3.5 |
| Adversarial machine learning | 5 | 2.0 | +3.0 |
Research
Peer-reviewed first, then newest. Showing 8 of 15.The Double-Edged Sword of GenAI Feedback: How Generative AI Influences Employee Motivation and Perceived Devaluation
Peer-reviewedAIS eLibrary (Journal of AIS, CAIS, etc.)Generative AI and the Tertiary Sector: Current Issues, Key Opportunities and Risks for Institutions and Policymakers
Peer-reviewedAIS eLibrary (Journal of AIS, CAIS, etc.)A Panel Report on the Implications of Artificial Intelligence for Academic Knowledge Work
Peer-reviewedAIS eLibrary (Journal of AIS, CAIS, etc.)Towards Robust and Secure Embodied AI: A Survey on Vulnerabilities and Attacks
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)PVLM: Parsing-Aware Vision-Language Model With Dynamic Contrastive Learning for Zero-Shot Deepfake Attribution
Peer-reviewedIEEE Xplore (Security & AI Journals)Benchmarking Deepfake Attacks on Deep Face Recognition Systems
Peer-reviewedIEEE Xplore (Security & AI Journals)A Study of the Removability of Speaker-Adversarial Perturbations
Peer-reviewedIEEE Xplore (Security & AI Journals)Beyond Stop Signs: Why Evasion Attacks Matter Even More
Peer-reviewedIEEE Xplore (Security & AI Journals)
Policy and regulation
Newest first.Thinking carefully before adopting agentic AI
UK NCSCThe EU AI Act’s transparency rules: A practical guide to Article 50
EU AI Act Updates10 questions to ask when using AI models to find vulnerabilities
UK NCSCOpenAI to give EU access to new cyber model but Anthropic still holding out on Mythos
CNBC Technology
Generated from the AI Sec Watch database at . Every item links to its record.