What changed in AI security, Jul 20 to Jul 26, 2026
Jul 20 to Jul 26, 2026 (ISO week 2026-W30). Weeks run Monday to Sunday in UTC.
196 records published, +1 on the previous week: 49 vulnerabilities (-18), 2 incidents (+2), 17 research items (-5), 128 news items (+23), 0 policy items (-1).
Critical and high advisories
Vulnerability records rated critical or high, newest first. Showing 25 of 26.- High
GHSA-j6g5-3hh3-pgw8: AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
CVE-2026-16796GitHub Advisory Database - High
GHSA-29w2-fq35-v728: AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
CVE-2026-16584GitHub Advisory Database - High
GHSA-pvcr-8mvp-w8qr: Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)
GitHub Advisory Database - Critical
GHSA-w28w-gp39-m4p6: Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
GitHub Advisory Database - High
CVE-2026-66027: Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated…
CVE-2026-66027NVD/CVE Database - Critical
CVE-2026-50517: Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
CVE-2026-50517NVD/CVE Database - High
CVE-2026-16796 - Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()
AWS Security Bulletins - High
CVE-2026-65918: PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the…
CVE-2026-65918NVD/CVE Database - Critical
CVE-2026-65700: h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows…
CVE-2026-65700NVD/CVE Database - High
CVE-2026-16584 - AWS API MCP Server Security Policy Bypass via Startup Failure
AWS Security Bulletins - High
GHSA-xwx6-jjhv-84p8: n8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service
GitHub Advisory Database - High
GHSA-xmc9-4f2h-jf9c: n8n: Edit Image Node Format Injection Allows Arbitrary File Write
GitHub Advisory Database - High
GHSA-cj9h-qx8g-pq2g: n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON
GitHub Advisory Database - High
GHSA-gv7g-jm28-cr3m: n8n: Expression sandbox escape via arrow-function bodies enabling command execution
GitHub Advisory Database - High
GHSA-9wcp-9r3j-383q: n8n: Stored DOM XSS via Resource Locator `cachedResultUrl`
CVE-2026-65592GitHub Advisory Database - High
GHSA-x5vx-c2c8-m3w9: n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool
CVE-2026-65015GitHub Advisory Database - High
GHSA-w46p-w7w2-fr9g: Duplicate Advisory: AI Agents Project Viewer Privilege Escalation via run_node_tool
GitHub Advisory Database - High
GHSA-h5xr-fqvj-253p: Duplicate Advisory: Stored DOM XSS via Resource Locator `cachedResultUrl`
GitHub Advisory Database - High
CVE-2026-65315: Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows…
CVE-2026-65315NVD/CVE Database - High
CVE-2026-65056: mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal…
CVE-2026-65056NVD/CVE Database - Critical
CVE-2026-63764: lmdeploy's OpenAI-compatible API server contains a server-side request forgery vulnerability that allows…
CVE-2026-63764NVD/CVE Database - High
CVE-2026-57495: AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39…
CVE-2026-57495NVD/CVE Database - High
CVE-2026-57494: AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a…
CVE-2026-57494NVD/CVE Database - High
CVE-2026-47255: AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and…
CVE-2026-47255NVD/CVE Database - Critical
CVE-2026-63766: GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise…
CVE-2026-63766NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.No vulnerability published in this week is listed as exploited or has an EPSS score of 10% or more.
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| lfx-ollama | PyPI | LangChain | 0.1.0 | |
| lfx-azure | PyPI | LangChain | 0.1.0 | |
| lfx-google | PyPI | Google Gemini SDK, LangChain | 0.1.0 | |
| genkit-google-genai | PyPI | Genkit, Google Gemini SDK, Google Vertex AI SDK | 0.8.0 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| AI agents | 30 | 20.8 | +9.3 |
| Adversarial machine learning | 4 | 1.3 | +2.8 |
| Model Context Protocol | 8 | 6.0 | +2.0 |
Research
Peer-reviewed first, then newest. Showing 8 of 17.A comprehensive analysis of adversarial attacks against spam filters
Peer-reviewedElsevier Security JournalsSemAder: Evading LLM-Based Binary Code Analysis via Structure-Semantics Joint Induction
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)Watermarking for Model Ownership Verification:Invisible at Deployment, Activated by Updates
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)With Power comes Responsibility: Attack Synthesis for Industrial Control Systems using Large Language Models
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)Privacy Against Agnostic Inference Attacks in Vertical Federated Learning
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)PREFed: An Effective and Stealthy Static-Anchor Backdoor Attack via Trigger Pre-Optimization in Federated Learning
Peer-reviewedIEEE Xplore (Security & AI Journals)UnVC: Protecting Your Voiceprint by Generative Adversarial Speech
Peer-reviewedIEEE Xplore (Security & AI Journals)Zero-Knowledge Proof-Based IP Protection of Visual Large Models of Autonomous Driving
Peer-reviewedIEEE Xplore (Security & AI Journals)
Policy and regulation
Newest first.No regulatory or policy records were published in this week.
Generated from the AI Sec Watch database at . Every item links to its record.