Skip to content

What changed in AI security, Jul 13 to Jul 19, 2026

Jul 13 to Jul 19, 2026 (ISO week 2026-W29). Weeks run Monday to Sunday in UTC.

195 records published, +39 on the previous week: 67 vulnerabilities (+24), 0 incidents (no change), 22 research items (+14), 105 news items (+2), 1 policy item (-1).

Critical and high advisories

Vulnerability records rated critical or high, newest first. Showing 25 of 50.

Exploitation signals

Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.
AdvisoryExploitationEPSSPublished
CVE-2026-9198: IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER…
CVE-2026-9198NVD/CVE Database
Known exploited28.7%

Packages that began delegating to a language model

Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.
PackageEcosystemLLM SDKsReleaseReleased
smg-grpc-servicerPyPIHugging Face Hub / Transformers0.7.0
lfx-valkeyPyPILangChain0.1.0
axolotl-ringmasterPyPIHugging Face Hub / Transformers0.1.0
runta-sdkPyPIOpenAI Agents SDK0.1.10
giskard-scanPyPIHugging Face Hub / Transformers1.0.0b3

Topics that moved

Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.
TopicRecordsWeekly mean, previous 4Difference
Inference infrastructure133.8+9.3
Model Context Protocol95.0+4.0
Adversarial machine learning40.5+3.5
Coding assistants73.8+3.3

Research

Peer-reviewed first, then newest. Showing 8 of 22.

Policy and regulation

Newest first.

Generated from the AI Sec Watch database at . Every item links to its record.

RSS feed of weekly changesPrevious week