What changed in AI security, Jul 6 to Jul 12, 2026
Jul 6 to Jul 12, 2026 (ISO week 2026-W28). Weeks run Monday to Sunday in UTC.
156 records published, +21 on the previous week: 43 vulnerabilities (+6), 0 incidents (no change), 8 research items (-4), 103 news items (+17), 2 policy items (+2).
Critical and high advisories
Vulnerability records rated critical or high, newest first. Showing 25 of 27.- Critical
CVE-2026-61447: PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes…
CVE-2026-61447NVD/CVE Database - High
CVE-2026-61439: PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults…
CVE-2026-61439NVD/CVE Database - High
GHSA-g5r6-gv6m-f5jv: mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment
GitHub Advisory Database - High
GHSA-m8gf-v64p-gfmg: BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py
CVE-2026-54071GitHub Advisory Database - Critical
CVE-2026-59726: Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment…
CVE-2026-59726NVD/CVE Database - High
CVE-2026-59207: n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not enforce…
CVE-2026-59207NVD/CVE Database - High
GHSA-52vm-mxx8-f227: Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths
GitHub Advisory Database - High
CVE-2026-54499: Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human…
CVE-2026-54499NVD/CVE Database - High
GHSA-37h2-6p4f-mp3q: Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
CVE-2026-49471GitHub Advisory Database - High
CVE-2026-59822: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP…
CVE-2026-59822NVD/CVE Database - High
CVE-2026-59820: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM…
CVE-2026-59820NVD/CVE Database - High
CVE-2026-59806: Gradio before 6.20.0 contains an open redirect and server-side request forgery vulnerability that allows attackers to…
CVE-2026-59806NVD/CVE Database - Critical
CVE-2026-59706: mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request…
CVE-2026-59706NVD/CVE Database - High
GHSA-7w99-5wm4-3g79: @better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
CVE-2026-53518GitHub Advisory Database - Critical
CVE-2026-59800: 9Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST…
CVE-2026-59800NVD/CVE Database - Critical
GHSA-2pq5-3q89-j7cc: Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879
CVE-2026-55615GitHub Advisory Database - Critical
GHSA-vjc7-jrh9-9j86: 9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
GitHub Advisory Database - High
CVE-2026-55574: vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the…
CVE-2026-55574NVD/CVE Database - High
CVE-2026-55514: vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in…
CVE-2026-55514NVD/CVE Database - High
CVE-2026-54234: vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal…
CVE-2026-54234NVD/CVE Database - High
GHSA-84rm-42xw-mx52: Coder's AI Bridge Proxy skips TLS certificate verification in default configuration
CVE-2026-55436GitHub Advisory Database - High
CVE-2026-14471 - Authenticated SQL injection in the metrics-service retention policy subsystem of mcp-gateway-registry
AWS Security Bulletins - High
GHSA-gjgq-w2m6-wr5q: Langroid: handle_message() executes user-supplied tool JSON without sender verification
CVE-2026-54771GitHub Advisory Database - Critical
GHSA-q9p7-wqxg-mrhc: Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent
CVE-2026-54769GitHub Advisory Database - Critical
GHSA-6xc5-4r68-67fc: Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls
CVE-2026-54760GitHub Advisory Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.| Advisory | Exploitation | EPSS | Published |
|---|---|---|---|
| CVE-2026-59822: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP… CVE-2026-59822NVD/CVE Database | Known exploited | 0.8% |
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| opentelemetry-instrumentation-genai-anthropic | PyPI | Anthropic SDK | 1.0b0 | |
| opentelemetry-instrumentation-genai-openai | PyPI | OpenAI SDK | 1.0b0 | |
| lfx-exa | PyPI | LangChain | 0.1.0 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| AI agents | 35 | 18.0 | +17.0 |
| Prompt injection and jailbreaks | 12 | 4.3 | +7.8 |
| Inference infrastructure | 4 | 3.3 | +0.8 |
Research
Peer-reviewed first, then newest.Using private data with freedom: A cloud-assisted ID-Private data join protocol for privacy-preserving machine learning over distributed data
Peer-reviewedElsevier Security JournalsA Deep Dive into Fairness, Bias, Threats, and Privacy in Recommender Systems: Insights and Future Research
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)RFA-Tex: Range-Flexible Adaptive Physical Adversarial Texture Against Real-World Person Detectors
Peer-reviewedIEEE Xplore (Security & AI Journals)Backdoor-Based Watermarking in Multi-Client Split Learning
Peer-reviewedIEEE Xplore (Security & AI Journals)FedDC: Efficient protection scheme based on chaotic system in federated learning
Peer-reviewedElsevier Security JournalsSecure and efficient federated learning using attribute-based homomorphic encryption
Peer-reviewedElsevier Security JournalsSystematic Evaluation of Dataset Watermarking for Intellectual Protection
Peer-reviewedIEEE Xplore (Security & AI Journals)Separating signal from noise in coding evaluations
Blog ResearchOpenAI Blog
Policy and regulation
Newest first.Generated from the AI Sec Watch database at . Every item links to its record.