What changed in AI security, Jul 27 to Aug 2, 2026
Jul 27 to Aug 2, 2026 (ISO week 2026-W31). Weeks run Monday to Sunday in UTC.
193 records published, -3 on the previous week: 21 vulnerabilities (-28), 0 incidents (-2), 3 research items (-14), 167 news items (+39), 2 policy items (+2).
Critical and high advisories
Vulnerability records rated critical or high, newest first.- High
CVE-2026-9856: A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes…
CVE-2026-9856NVD/CVE Database - High
CVE-2026-9335: A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to…
CVE-2026-9335NVD/CVE Database - High
CVE-2026-18394 - Incorrect authorization in Strands Agents Tools http_request tool
AWS Security Bulletins - Critical
CVE-2026-12946: IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the…
CVE-2026-12946NVD/CVE Database - Critical
CVE-2026-15976: SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically…
CVE-2026-15976NVD/CVE Database - High
CVE-2026-13444: IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by…
CVE-2026-13444NVD/CVE Database - Critical
CVE-2026-13435: IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox…
CVE-2026-13435NVD/CVE Database - High
CVE-2026-12942: IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker…
CVE-2026-12942NVD/CVE Database - High
CVE-2026-12945: IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs…
CVE-2026-12945NVD/CVE Database - Critical
CVE-2026-12940: IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable x
CVE-2026-12940NVD/CVE Database - High
GHSA-hr7p-wg7r-hg9m: Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
CVE-2026-67427GitHub Advisory Database - High
CVE-2026-67428: Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules…
CVE-2026-67428NVD/CVE Database - High
CVE-2026-67425: Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys…
CVE-2026-67425NVD/CVE Database - High
CVE-2026-13442: IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access…
CVE-2026-13442NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.No vulnerability published in this week is listed as exploited or has an EPSS score of 10% or more.
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| genkit-vertexai | PyPI | Anthropic SDK, Genkit, Google Gemini SDK, Google Vertex AI SDK | 0.9.0 | |
| genkit-openai | PyPI | Genkit, OpenAI SDK | 0.9.0 | |
| genkit-ollama | PyPI | Genkit, Ollama client | 0.9.0 | |
| genkit-middleware | PyPI | Genkit | 0.9.0 | |
| genkit-google-cloud | PyPI | Genkit | 0.9.0 | |
| genkit-flask | PyPI | Genkit | 0.9.0 | |
| genkit-fastapi | PyPI | Genkit | 0.9.0 | |
| genkit-evaluators | PyPI | Genkit | 0.9.0 | |
| genkit-django | PyPI | Genkit | 0.9.0 | |
| genkit-anthropic | PyPI | Anthropic SDK, Genkit | 0.9.0 | |
| lfx-datastax | PyPI | LangChain | 0.1.3 | |
| @ai-sdk/minimax | npm | Vercel AI SDK | 0.0.0 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| AI agents | 42 | 24.5 | +17.5 |
| Frontier model safety | 6 | 0.8 | +5.3 |
| AI regulation and standards | 3 | 0.0 | +3.0 |
| Robotics and embodied AI | 3 | 0.3 | +2.8 |
| Deepfakes and impersonation | 3 | 1.3 | +1.8 |
Research
Peer-reviewed first, then newest.Policy and regulation
Newest first.Generated from the AI Sec Watch database at . Every item links to its record.