What changed in AI security, Aug 3 to Aug 9, 2026
Aug 3 to Aug 9, 2026 (ISO week 2026-W32). Weeks run Monday to Sunday in UTC.
240 records published, +47 on the previous week: 79 vulnerabilities (+58), 2 incidents (+2), 3 research items (no change), 152 news items (-15), 4 policy items (+2).
Critical and high advisories
Vulnerability records rated critical or high, newest first. Showing 25 of 59.- Critical
CVE-2026-14526: The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to…
CVE-2026-14526NVD/CVE Database - High
CVE-2026-12261: A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model…
CVE-2026-12261NVD/CVE Database - Critical
CVE-2026-67622: Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration…
CVE-2026-67622NVD/CVE Database - High
CVE-2026-19111 - Insecure direct object reference in Strands Agents Tools memory tools
AWS Security Bulletins - Critical
CVE-2026-67531: FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed…
CVE-2026-67531NVD/CVE Database - High
CVE-2026-18954 - Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server
AWS Security Bulletins - High
CVE-2026-18953 - Improper limitation of a pathname in AWS Transform MCP Server
AWS Security Bulletins - High
CVE-2026-69111: Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote…
CVE-2026-69111NVD/CVE Database - High
CVE-2026-9205: IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.
CVE-2026-9205NVD/CVE Database - High
CVE-2026-9201: IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a…
CVE-2026-9201NVD/CVE Database - High
CVE-2026-9196: IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic…
CVE-2026-9196NVD/CVE Database - High
CVE-2026-9130: IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows…
CVE-2026-9130NVD/CVE Database - High
CVE-2026-8478: IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the…
CVE-2026-8478NVD/CVE Database - High
CVE-2026-8470: IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use…
CVE-2026-8470NVD/CVE Database - High
CVE-2026-8183: IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through…
CVE-2026-8183NVD/CVE Database - High
CVE-2026-8182: IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the…
CVE-2026-8182NVD/CVE Database - Critical
CVE-2026-48168: PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is…
CVE-2026-48168NVD/CVE Database - High
CVE-2026-17633: IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code…
CVE-2026-17633NVD/CVE Database - High
CVE-2026-17632: IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to…
CVE-2026-17632NVD/CVE Database - High
CVE-2026-17624: IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through…
CVE-2026-17624NVD/CVE Database - High
CVE-2026-9081: IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF)…
CVE-2026-9081NVD/CVE Database - High
CVE-2026-17625: IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through…
CVE-2026-17625NVD/CVE Database - High
CVE-2026-9077: IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only…
CVE-2026-9077NVD/CVE Database - High
CVE-2026-8446: IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol…
CVE-2026-8446NVD/CVE Database - High
CVE-2026-17630: IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper…
CVE-2026-17630NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.No vulnerability published in this week is listed as exploited or has an EPSS score of 10% or more.
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| vortex-data | PyPI | Hugging Face Hub / Transformers | 0.84.0 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| Model Context Protocol | 12 | 6.8 | +5.3 |
| Frontier model safety | 6 | 2.3 | +3.8 |
| Deepfakes and impersonation | 4 | 2.0 | +2.0 |
| Prompt injection and jailbreaks | 6 | 5.5 | +0.5 |
Research
Peer-reviewed first, then newest.DeepForgeSeal: Latent Space-Driven Semi-Fragile Watermarking for Deepfake Detection Using Adversarial Reinforcement Learning
Peer-reviewedIEEE Xplore (Security & AI Journals)Privacy-Preserving GAN for Synthetic Data against Membership Inference Attack
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)WeatherNext: AI model achieves breakthrough in forecasting cyclones
IndustryDeepMind Safety Research
Policy and regulation
Newest first.AI Therapy under the EU AI Act
EU AI Act UpdatesNCSC statement in response to recent incidents resulting from frontier AI evaluations
UK NCSCWhite House to host AI companies Tuesday to review new model-testing framework
CNBC TechnologyAnthropic, OpenAI among firms facing new scrutiny under EU AI Act enforcement powers
CNBC Technology
Generated from the AI Sec Watch database at . Every item links to its record.