What changed in AI security, Jun 29 to Jul 5, 2026
Jun 29 to Jul 5, 2026 (ISO week 2026-W27). Weeks run Monday to Sunday in UTC.
135 records published, -21 on the previous week: 37 vulnerabilities (-4), 0 incidents (no change), 12 research items (-1), 86 news items (-16), 0 policy items (no change).
Critical and high advisories
Vulnerability records rated critical or high, newest first. Showing 25 of 29.- High
CVE-2026-14535: In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls…
CVE-2026-14535NVD/CVE Database - High
CVE-2025-71372: Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods…
CVE-2025-71372NVD/CVE Database - High
CVE-2025-71342: picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods…
CVE-2025-71342NVD/CVE Database - Critical
CVE-2026-12481: A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of…
CVE-2026-12481NVD/CVE Database - High
CVE-2026-13341: A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0, which could…
CVE-2026-13341NVD/CVE Database - Critical
CVE-2026-45499: Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
CVE-2026-45499NVD/CVE Database - Critical
CVE-2026-41106: Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate…
CVE-2026-41106NVD/CVE Database - High
CVE-2026-59093: Weaviate before 1.38.0 does not verify that a principal performing an RBAC role assignment holds the permissions…
CVE-2026-59093NVD/CVE Database - High
GHSA-f9ff-5x35-7gfw: Grackle: Fail-open authorization in the MCP tool layer lets scoped agents perform cross-task and cross-session mutations (IDOR)
GitHub Advisory Database - High
GHSA-pmch-g965-grmr: Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read
CVE-2026-50180GitHub Advisory Database - High
GHSA-fg23-3346-88f5: Langroid: Path traversal in the file tools allows read/write outside configured current directory
CVE-2026-50181GitHub Advisory Database - Critical
GHSA-84hp-mqvj-3p8h: mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete
CVE-2026-50027Hugging Face Security Advisories - High
CVE-2025-69134: Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions.
CVE-2025-69134NVD/CVE Database - High
CVE-2026-8147: In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper…
CVE-2026-8147NVD/CVE Database - High
CVE-2026-49119: Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that…
CVE-2026-49119NVD/CVE Database - High
CVE-2026-24264: NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause improper handling of…
CVE-2026-24264NVD/CVE Database - Critical
CVE-2026-7874: IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use of a…
CVE-2026-7874NVD/CVE Database - Critical
CVE-2026-7873: IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read…
CVE-2026-7873NVD/CVE Database - Critical
CVE-2026-7871: IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application…
CVE-2026-7871NVD/CVE Database - Critical
CVE-2026-7803: IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow nodes…
CVE-2026-7803NVD/CVE Database - Critical
CVE-2026-7663: IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources…
CVE-2026-7663NVD/CVE Database - High
CVE-2026-10564: IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). The legacy RSSReaderComponent in…
CVE-2026-10564NVD/CVE Database - High
CVE-2026-10560: IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/…
CVE-2026-10560NVD/CVE Database - High
CVE-2026-10546: IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the URL component…
CVE-2026-10546NVD/CVE Database - Critical
CVE-2026-10140: IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API…
CVE-2026-10140NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.No vulnerability published in this week is listed as exploited or has an EPSS score of 10% or more.
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| lfx-empiriolabs | PyPI | LangChain | 0.1.0 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| Model Context Protocol | 7 | 3.3 | +3.8 |
| Prompt injection and jailbreaks | 6 | 3.8 | +2.3 |
Research
Peer-reviewed first, then newest. Showing 8 of 12.A Layered Needs-Affordances-Features Approach to Advancing Artificial Intelligence Fairness in Hiring Systems
Peer-reviewedAIS eLibrary (Journal of AIS, CAIS, etc.)Efficient Prompt Security Detection for LLM Service Deployment in Edge-Cloud Networks
Peer-reviewedIEEE Xplore (Security & AI Journals)Benchmarking the Robustness of Autonomous Driving to Environmental Illusions: A Lane Perception Perspective
Peer-reviewedIEEE Xplore (Security & AI Journals)Google’s Gemini Image Generation: AI Bias and the Rewriting of History
Peer-reviewedAIS eLibrary (Journal of AIS, CAIS, etc.)Algorithmic Fragility: How Organizations Stabilize Unstable Machines
Peer-reviewedAIS eLibrary (Journal of AIS, CAIS, etc.)Bias Amplification in RAG: Poisoning Knowledge Retrieval to Steer LLMs
Peer-reviewedIEEE Xplore (Security & AI Journals)PromptFishing: Active Hallucination Inducement to Distinguish LLMs From Humans
Peer-reviewedIEEE Xplore (Security & AI Journals)Tracing the Use of Open-Source Training Datasets for Neural Radiance Field Models
Peer-reviewedIEEE Xplore (Security & AI Journals)
Policy and regulation
Newest first.No regulatory or policy records were published in this week.
Generated from the AI Sec Watch database at . Every item links to its record.