What changed in AI security, Aug 17 to Aug 23, 2026
Aug 17 to Aug 23, 2026 (ISO week 2026-W34). Weeks run Monday to Sunday in UTC.
172 records published, -3 on the previous week: 54 vulnerabilities (+11), 0 incidents (no change), 12 research items (-4), 105 news items (-11), 1 policy item (+1).
Critical and high advisories
Vulnerability records rated critical or high, newest first. Showing 25 of 39.- Critical
GHSA-x2rj-828p-hx9m: Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
CVE-2026-61539GitHub Advisory Database - High
CVE-2026-62677: Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, an…
CVE-2026-62677NVD/CVE Database - High
CVE-2026-62676: Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, the…
CVE-2026-62676NVD/CVE Database - High
CVE-2026-62675: Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0…
CVE-2026-62675NVD/CVE Database - Critical
CVE-2026-62674: Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT…
CVE-2026-62674NVD/CVE Database - High
CVE-2026-49114: In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's…
CVE-2026-49114NVD/CVE Database - High
CVE-2026-72848: SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented…
CVE-2026-72848NVD/CVE Database - High
CVE-2026-69855: Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information…
CVE-2026-69855NVD/CVE Database - High
GHSA-533j-2v4q-mw5h: LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
CVE-2026-55253GitHub Advisory Database - High
CVE-2026-15679: Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability…
CVE-2026-15679NVD/CVE Database - High
CVE-2026-18482: Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the…
CVE-2026-18482NVD/CVE Database - High
CVE-2026-76832: Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to…
CVE-2026-76832NVD/CVE Database - High
CVE-2026-76395: In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the…
CVE-2026-76395NVD/CVE Database - High
CVE-2026-76394: In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles…
CVE-2026-76394NVD/CVE Database - High
CVE-2026-76391: In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run…
CVE-2026-76391NVD/CVE Database - High
GHSA-2xhg-73j7-rrgx: Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint
CVE-2026-53957GitHub Advisory Database - High
GHSA-rr55-jp92-8wp2: claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
GitHub Advisory Database - High
GHSA-j4r7-8ph4-43g3: faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
GitHub Advisory Database - High
GHSA-cc2g-gq8c-r332: grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools
GitHub Advisory Database - High
CVE-2026-19875: IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email information and…
CVE-2026-19875NVD/CVE Database - High
GHSA-wg9g-w2j2-8pgr: MONAI: Unsafe deserialization in NumpyReader allows arbitrary code execution via malicious .npy files
Hugging Face Security Advisories - High
GHSA-qxq5-qhx6-94qw: Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patch
GitHub Advisory Database - High
CVE-2026-47629: NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input…
CVE-2026-47629NVD/CVE Database - High
CVE-2026-47628: NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of…
CVE-2026-47628NVD/CVE Database - Critical
CVE-2026-47627: NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A…
CVE-2026-47627NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.| Advisory | Exploitation | EPSS | Published |
|---|---|---|---|
| GHSA-7gwp-5pfp-969j: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) CVE-2026-64849GitHub Advisory Database | Known exploited | 9.8% |
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| genkit-amazon-bedrock | PyPI | Genkit | 0.10.0 | |
| dashscope | PyPI | Anthropic SDK, OpenAI SDK | 1.27.0 | |
| lfx-confluent | PyPI | LangChain | 0.1.0 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| Inference infrastructure | 7 | 2.3 | +4.8 |
| Coding assistants | 7 | 3.0 | +4.0 |
Research
Peer-reviewed first, then newest. Showing 8 of 12.Deepfake Media Generation and Detection in the Generative AI Era: A Survey and Outlook
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)Impact of Intelligent Technologies on IoV Security: Integrating Edge Computing and AI
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)A Comparative Survey of Security Risks in AI Systems: From LLMs to AI Agents and Embodied Agents
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)Formal analysis of CAS under malicious service providers: Implications for trust-aware deployments
Peer-reviewedElsevier Security JournalsRobustness and interpretability of phishing detectors under generative AI shifts
Peer-reviewedElsevier Security JournalsSpikeTimer: Exploring Active Copyright Protection in Spiking Neural Networks via Temporal Backdoor Regularization
Peer-reviewedIEEE Xplore (Security & AI Journals)DP2-RAG: An Efficient Full-Process Differential Privacy Implementation in Retrieval-Augmented Generation
Peer-reviewedIEEE Xplore (Security & AI Journals)Quantum-KIP: Kernel Inducing Points for Quantum Privacy
Peer-reviewedIEEE Xplore (Security & AI Journals)
Policy and regulation
Newest first.Generated from the AI Sec Watch database at . Every item links to its record.