What changed in AI security, Aug 10 to Aug 16, 2026
Aug 10 to Aug 16, 2026 (ISO week 2026-W33). Weeks run Monday to Sunday in UTC.
175 records published, -65 on the previous week: 43 vulnerabilities (-36), 0 incidents (-2), 16 research items (+13), 116 news items (-36), 0 policy items (-4).
Critical and high advisories
Vulnerability records rated critical or high, newest first. Showing 25 of 29.- High
CVE-2026-49986: The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats…
CVE-2026-49986NVD/CVE Database - High
CVE-2026-73658: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until…
CVE-2026-73658NVD/CVE Database - Critical
CVE-2026-19297: IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due…
CVE-2026-19297NVD/CVE Database - Critical
CVE-2026-73656: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST…
CVE-2026-73656NVD/CVE Database - High
CVE-2026-73655: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.2…
CVE-2026-73655NVD/CVE Database - High
CVE-2026-73654: Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 3.3.8 until 4.5.6, the…
CVE-2026-73654NVD/CVE Database - High
CVE-2026-72675: Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data…
CVE-2026-72675NVD/CVE Database - High
CVE-2026-72642: The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model…
CVE-2026-72642NVD/CVE Database - High
CVE-2026-73557: vLLM is an inference and serving engine for large language models. From 0.20.2rc0 until 0.26.0, safe_load_prompt_embeds…
CVE-2026-73557NVD/CVE Database - High
CVE-2026-73614: Network-AI ClaudeHookBridge before 5.15.1 truncates the target string to 500 characters before evaluating denyPatterns…
CVE-2026-73614NVD/CVE Database - Critical
CVE-2026-73487: Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows…
CVE-2026-73487NVD/CVE Database - Critical
CVE-2026-73485: Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated…
CVE-2026-73485NVD/CVE Database - High
CVE-2026-73498: MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0…
CVE-2026-73498NVD/CVE Database - High
GHSA-49m4-vp58-wgc9: MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
CVE-2026-55071GitHub Advisory Database - High
CVE-2026-73325: Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers…
CVE-2026-73325NVD/CVE Database - High
CVE-2026-73264: Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration…
CVE-2026-73264NVD/CVE Database - Critical
CVE-2026-73032: PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary…
CVE-2026-73032NVD/CVE Database - High
CVE-2026-73222: Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio…
CVE-2026-73222NVD/CVE Database - High
CVE-2026-72742: DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows…
CVE-2026-72742NVD/CVE Database - High
CVE-2026-73218: Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in…
CVE-2026-73218NVD/CVE Database - High
CVE-2026-73217: Cursor is a code editor built for programming with AI. Prior to 3.1.2, Cursor IDE for macOS allows an agent running in…
CVE-2026-73217NVD/CVE Database - High
CVE-2026-70335: Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual…
CVE-2026-70335NVD/CVE Database - High
CVE-2026-65675: No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security…
CVE-2026-65675NVD/CVE Database - High
CVE-2026-24693: Protection mechanism failure for some Intel(R) oneCCL Bindings for PyTorch before version v2.8.0 within Ring 3: User…
CVE-2026-24693NVD/CVE Database - High
CVE-2026-21387: Protection mechanism failure for some Intel(R) LLM Library for PyTorch within Ring 3: User Applications may allow an…
CVE-2026-21387NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.No vulnerability published in this week is listed as exploited or has an EPSS score of 10% or more.
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.No tracked package published its first release with an LLM SDK, agent framework or MCP dependency in this week.
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| Inference infrastructure | 6 | 4.0 | +2.0 |
| Coding assistants | 4 | 3.8 | +0.3 |
Research
Peer-reviewed first, then newest. Showing 8 of 16.Adversarial Purification by Consistency-Aware Latent Space Optimization on Data Manifolds
Peer-reviewedIEEE Xplore (Security & AI Journals)Feature-Alteration Robustness for Out-of-Distribution Detection
Peer-reviewedIEEE Xplore (Security & AI Journals)Fed-CBE: Client-Side Backdoor Elimination in Federated Learning via Persistent Parameter Disruption
Peer-reviewedIEEE Xplore (Security & AI Journals)VocaLock: Watermark-Based Detection of Zero-Shot Voice Conversion Manipulation and Timbre Attribution
Peer-reviewedIEEE Xplore (Security & AI Journals)Patronus: Safeguarding Text-to-Image Models Against Adversarial Fine-Tuning
Peer-reviewedIEEE Xplore (Security & AI Journals)Text Adversarial Attacks With Dynamic Outputs
Peer-reviewedIEEE Xplore (Security & AI Journals)DeepU: Deeper Granular Within-Layer Machine Unlearning
Peer-reviewedIEEE Xplore (Security & AI Journals)Suspicious Frequency Amplified Hybrid Framework for Generalizable AIGC Image Detection
Peer-reviewedIEEE Xplore (Security & AI Journals)
Policy and regulation
Newest first.No regulatory or policy records were published in this week.
Generated from the AI Sec Watch database at . Every item links to its record.