What changed in AI security, May 18 to May 24, 2026
May 18 to May 24, 2026 (ISO week 2026-W21). Weeks run Monday to Sunday in UTC.
183 records published, -47 on the previous week: 45 vulnerabilities (-47), 0 incidents (-1), 19 research items (+4), 119 news items (+1), 0 policy items (-4).
Critical and high advisories
Vulnerability records rated critical or high, newest first. Showing 25 of 28.- High
CVE-2026-9255 - Tool Execution Without Authorization via Piped Stdin in Kiro CLI
AWS Security Bulletins - High
GHSA-j3vx-cx2r-pvg8: Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret
CVE-2026-46701GitHub Advisory Database - Critical
GHSA-f396-4rp4-7v2j: Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host
CVE-2026-46703GitHub Advisory Database - Critical
GHSA-g6ww-w5j2-r7x3: BoxLite: Permission Bypass Allows Modification of Read-Only Files
CVE-2026-46695GitHub Advisory Database - High
CVE-2026-47102: LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint…
CVE-2026-47102NVD/CVE Database - High
CVE-2026-47101: LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role…
CVE-2026-47101NVD/CVE Database - High
GHSA-cr22-wjx7-2w6m: MCP Server Kubernetes: Tool Access Control Bypass via Presentation-Layer Filtering Without Execution-Layer Enforcement
CVE-2026-46519GitHub Advisory Database - High
GHSA-7hh5-prp2-mfh5: Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK ModelBuilder/Serve path
CVE-2026-8596GitHub Advisory Database - High
GHSA-m549-qq94-fvhg: LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization
CVE-2026-46432Hugging Face Security Advisories - High
GHSA-7wx4-6vff-v64p: Diffusers: TOCTOU Trust Remote Code Bypass
CVE-2026-45804Hugging Face Security Advisories - High
CVE-2026-24214: NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an integer…
CVE-2026-24214NVD/CVE Database - High
CVE-2026-24213: NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an…
CVE-2026-24213NVD/CVE Database - High
CVE-2026-24210: NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an integer overflow. A successful…
CVE-2026-24210NVD/CVE Database - High
CVE-2026-24209: NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A…
CVE-2026-24209NVD/CVE Database - Critical
CVE-2026-24207: NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A…
CVE-2026-24207NVD/CVE Database - High
CVE-2026-24206: NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A…
CVE-2026-24206NVD/CVE Database - High
GHSA-22qr-rp27-j9wm: PenPot MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE
CVE-2026-45805GitHub Advisory Database - Critical
GHSA-fhh6-4qxv-rpqj: 9router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
CVE-2026-46339GitHub Advisory Database - High
GHSA-fhvh-vw7h-9xf3: libcrux-ml-dsa: Signature Verification on AVX2 Platforms Mishandles Edge Case
GitHub Advisory Database - High
GHSA-hv85-774v-26fg: auth-fetch-mcp: SSRF and disk exfiltration via unvalidated auth_fetch and download_media URLs
GitHub Advisory Database - Critical
GHSA-xmpw-2vmm-p4p6: Malicious code in guardrails-ai 0.10.1 (supply chain compromise)
CVE-2026-45758GitHub Advisory Database - High
CVE-2026-2611: In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints…
CVE-2026-2611NVD/CVE Database - High
CVE-2026-4137: In mlflow/mlflow versions prior to 3.11.0, the `get_or_create_nfs_tmp_dir()` function in `mlflow/utils/file_utils.py`…
CVE-2026-4137NVD/CVE Database - High
GHSA-jfrm-rx66-g536: NiceGUI: Local file disclosure via Docutils file insertion in ui.restructured_text()
CVE-2026-45553GitHub Advisory Database - High
CVE-2026-47092: Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local…
CVE-2026-47092NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.No vulnerability published in this week is listed as exploited or has an EPSS score of 10% or more.
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| google-antigravity | PyPI | Google Gemini SDK, Model Context Protocol SDK | 0.1.0 | |
| lfx-duckduckgo | PyPI | LangChain | 0.1.0 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| Inference infrastructure | 8 | 2.8 | +5.3 |
| Model Context Protocol | 9 | 4.3 | +4.8 |
| Deepfakes and impersonation | 5 | 2.5 | +2.5 |
Research
Peer-reviewed first, then newest. Showing 8 of 19.DWT-AMSA: Robust image steganography via frequency-domain adaptive masking and progressive adversarial training
Peer-reviewedElsevier Security JournalsAdaptive Trust-Aware SOC Human–AI Teaming for resilient operations
Peer-reviewedElsevier Security JournalsFairRoP: Robust Client Selection Scheme for Fairness-Aware Federated Learning
Peer-reviewedIEEE Xplore (Security & AI Journals)MDV: Resolving the Auxiliary Data Dilemma in Model Extraction Defenses
Peer-reviewedIEEE Xplore (Security & AI Journals)Trigger Without Trace: Toward Stealthy Backdoor Attack on Text-to-Image Diffusion Models
Peer-reviewedIEEE Xplore (Security & AI Journals)Deepfake Detection via Exploring Degradation Inconsistency
Peer-reviewedIEEE Xplore (Security & AI Journals)PersGuard: Preventing Malicious Personalization in Text-to-Image Diffusion Models via Model Backdoors
Peer-reviewedIEEE Xplore (Security & AI Journals)Palladium: Guarding Neural Network Training With Confidential Computing
Peer-reviewedIEEE Xplore (Security & AI Journals)
Policy and regulation
Newest first.No regulatory or policy records were published in this week.
Generated from the AI Sec Watch database at . Every item links to its record.