What changed in AI security, Jul 13 to Jul 19, 2026
Jul 13 to Jul 19, 2026 (ISO week 2026-W29). Weeks run Monday to Sunday in UTC.
195 records published, +39 on the previous week: 67 vulnerabilities (+24), 0 incidents (no change), 22 research items (+14), 105 news items (+2), 1 policy item (-1).
Critical and high advisories
Vulnerability records rated critical or high, newest first. Showing 25 of 50.- High
CVE-2026-12484: A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle…
CVE-2026-12484NVD/CVE Database - Critical
CVE-2026-13446: IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which…
CVE-2026-13446NVD/CVE Database - High
CVE-2026-13445: IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read…
CVE-2026-13445NVD/CVE Database - Critical
CVE-2026-8859: IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations…
CVE-2026-8859NVD/CVE Database - Critical
CVE-2026-8635: IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly…
CVE-2026-8635NVD/CVE Database - Critical
CVE-2026-8505: IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows…
CVE-2026-8505NVD/CVE Database - Critical
CVE-2026-8481: IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API…
CVE-2026-8481NVD/CVE Database - Critical
CVE-2026-8476: IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching…
CVE-2026-8476NVD/CVE Database - High
CVE-2026-8056: IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the…
CVE-2026-8056NVD/CVE Database - High
CVE-2026-7872: IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT…
CVE-2026-7872NVD/CVE Database - High
CVE-2026-7755: IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation…
CVE-2026-7755NVD/CVE Database - High
CVE-2026-7754: IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure…
CVE-2026-7754NVD/CVE Database - High
CVE-2026-7667: IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an…
CVE-2026-7667NVD/CVE Database - High
CVE-2026-14499: IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with…
CVE-2026-14499NVD/CVE Database - High
CVE-2026-13448: IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in…
CVE-2026-13448NVD/CVE Database - High
CVE-2026-15415 - Path traversal and arbitrary file write in the workflow linters of aws-healthomics-mcp-server
AWS Security Bulletins - Critical
CVE-2026-9135: IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d)…
CVE-2026-9135NVD/CVE Database - Critical
CVE-2026-9103: IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper…
CVE-2026-9103NVD/CVE Database - High
CVE-2026-58195: Agentic-Flow is an AI agent orchestration platform. Prior to 2.0.14, agentic-flow MCP server tools in…
CVE-2026-58195NVD/CVE Database - Critical
CVE-2026-9202: IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any…
CVE-2026-9202NVD/CVE Database - Critical
CVE-2026-9198: IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER…
CVE-2026-9198NVD/CVE Database - Critical
CVE-2026-9810: The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any val…
CVE-2026-9810NVD/CVE Database - High
GHSA-vj7q-gjh5-988w: MCP Python SDK: WebSocket server transport does not support Host/Origin validation
CVE-2026-59950GitHub Advisory Database - High
GHSA-jpw9-pfvf-9f58: MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
CVE-2026-52869GitHub Advisory Database - High
GHSA-hvrp-rf83-w775: MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
CVE-2026-52870GitHub Advisory Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.| Advisory | Exploitation | EPSS | Published |
|---|---|---|---|
| CVE-2026-9198: IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER… CVE-2026-9198NVD/CVE Database | Known exploited | 28.7% |
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| smg-grpc-servicer | PyPI | Hugging Face Hub / Transformers | 0.7.0 | |
| lfx-valkey | PyPI | LangChain | 0.1.0 | |
| axolotl-ringmaster | PyPI | Hugging Face Hub / Transformers | 0.1.0 | |
| runta-sdk | PyPI | OpenAI Agents SDK | 0.1.10 | |
| giskard-scan | PyPI | Hugging Face Hub / Transformers | 1.0.0b3 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| Inference infrastructure | 13 | 3.8 | +9.3 |
| Model Context Protocol | 9 | 5.0 | +4.0 |
| Adversarial machine learning | 4 | 0.5 | +3.5 |
| Coding assistants | 7 | 3.8 | +3.3 |
Research
Peer-reviewed first, then newest. Showing 8 of 22.EncFormer: Secure and Efficient Transformer Inference Over Encrypted Data
Peer-reviewedIEEE Xplore (Security & AI Journals)Forgetting Similar Samples: Can Machine Unlearning Do it Better?
Peer-reviewedIEEE Xplore (Security & AI Journals)Forgotten Horizons in Concept Erasure: Safeguarding Close-Proximity Concepts in Text-to-Image Models
Peer-reviewedIEEE Xplore (Security & AI Journals)Spa: Stealthy and Persistent Backdoor Attacks in Federated Learning via Feature-Space Alignment
Peer-reviewedIEEE Xplore (Security & AI Journals)SafeSteer: Adaptive Subspace Steering for Efficient Jailbreak Defense in Vision Language Models
Peer-reviewedIEEE Xplore (Security & AI Journals)On Success and Simplicity: A Second Look at Transferable Vision–Language Attack Pipeline
Peer-reviewedIEEE Xplore (Security & AI Journals)PANDA: Diffusion-Guided Purification and Adaptation for Robust Point Cloud Classification Against Adversarial Attack
Peer-reviewedIEEE Xplore (Security & AI Journals)Toward a Generalized Defense Across Sparse, Continuous, and Structured Parameter Attacks
Peer-reviewedIEEE Xplore (Security & AI Journals)
Policy and regulation
Newest first.Generated from the AI Sec Watch database at . Every item links to its record.