What changed in AI security, Jun 22 to Jun 28, 2026
Jun 22 to Jun 28, 2026 (ISO week 2026-W26). Weeks run Monday to Sunday in UTC.
156 records published, -30 on the previous week: 41 vulnerabilities (-27), 0 incidents (no change), 13 research items (-2), 102 news items (no change), 0 policy items (-1).
Critical and high advisories
Vulnerability records rated critical or high, newest first.- High
CVE-2026-47214: Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI…
CVE-2026-47214NVD/CVE Database - High
CVE-2025-71340: picklescan through 0.0.26 fails to detect malicious pickle files that invoke…
CVE-2025-71340NVD/CVE Database - Critical
CVE-2026-50549: Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox…
CVE-2026-50549NVD/CVE Database - Critical
CVE-2026-50548: Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox…
CVE-2026-50548NVD/CVE Database - Critical
CVE-2026-55413: ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI…
CVE-2026-55413NVD/CVE Database - High
CVE-2026-55412: ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI…
CVE-2026-55412NVD/CVE Database - High
CVE-2026-54033: LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, LibreChat allows users…
CVE-2026-54033NVD/CVE Database - High
CVE-2026-54030: LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.5, LibreChat's MCP OAuth…
CVE-2026-54030NVD/CVE Database - High
CVE-2026-55583: Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.9.0, Twenty was vulnerable to a…
CVE-2026-55583NVD/CVE Database - High
GCP-2026-043
Google Cloud Security Bulletins - High
CVE-2026-44020: Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI…
CVE-2026-44020NVD/CVE Database - High
CVE-2026-44017: Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI…
CVE-2026-44017NVD/CVE Database - High
CVE-2026-44016: Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI…
CVE-2026-44016NVD/CVE Database - Critical
CVE-2026-12537: Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1)…
CVE-2026-12537NVD/CVE Database - High
CVE-2026-7574: Anthropic Claude Desktop Cowork VM image handling (confirmed across v1.1348.0 through v1.2278.0, including v1.1348.0…
CVE-2026-7574NVD/CVE Database - High
CVE-2026-54555: rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.42.2, the permission splitter…
CVE-2026-54555NVD/CVE Database - High
CVE-2026-54322: Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to…
CVE-2026-54322NVD/CVE Database - High
CVE-2026-54321: Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. From…
CVE-2026-54321NVD/CVE Database - High
CVE-2026-54320: Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to…
CVE-2026-54320NVD/CVE Database - High
GHSA-v7j5-vc4m-723w: Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF
CVE-2026-50132GitHub Advisory Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.No vulnerability published in this week is listed as exploited or has an EPSS score of 10% or more.
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| opentelemetry-instrumentation-litellm | PyPI | LiteLLM | 0.1.0 | |
| lfx-openai | PyPI | LangChain, OpenAI SDK | 0.1.0 | |
| lfx-cohere | PyPI | LangChain | 0.1.0 | |
| lfx-bundles | PyPI | FAISS, Hugging Face Hub / Transformers, LangChain, LiteLLM, OpenAI SDK, pgvector, Qdrant, smolagents, Weaviate | 1.0.0 | |
| lfx-anthropic | PyPI | LangChain | 0.1.0 | |
| lfx-amazon | PyPI | LangChain | 0.1.0 | |
| @n8n/instance-ai | npm | Vercel AI SDK | 1.13.0 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| Coding assistants | 6 | 3.3 | +2.8 |
| Model Context Protocol | 4 | 3.0 | +1.0 |
| Prompt injection and jailbreaks | 4 | 3.0 | +1.0 |
Research
Peer-reviewed first, then newest. Showing 8 of 13.Adaptive Affinity Memorization With Layer Mutation for Multimodal Deepfake Continual Detection
Peer-reviewedIEEE Xplore (Security & AI Journals)AMBER: Robust Federated Learning Based on Client Verification
Peer-reviewedIEEE Xplore (Security & AI Journals)Agentic AI in Healthcare: Opportunities, Challenges, and Future Directions
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)Ellipsoid Control: A White-List Jailbreak Defense via Benign Latent Modeling
Peer-reviewedIEEE Xplore (Security & AI Journals)Divergence-Based Adaptive Aggregation for Byzantine Robust Federated Learning
Peer-reviewedIEEE Xplore (Security & AI Journals)A Differentially Private Weighted Empirical Risk Minimization Procedure and Its Application to Outcome Weighted Learning
Peer-reviewedIEEE Xplore (Security & AI Journals)Detection and Mitigation Data Poisoning Attacks in Multimodal Online Federated Learning
Peer-reviewedIEEE Xplore (Security & AI Journals)LoRASculpt: Harmonious Low-Rank Adaptation for Multimodal Large Language Models
Peer-reviewedIEEE Xplore (Security & AI Journals)
Policy and regulation
Newest first.No regulatory or policy records were published in this week.
Generated from the AI Sec Watch database at . Every item links to its record.