What changed in AI security, Aug 24 to Aug 30, 2026
Aug 24 to Aug 30, 2026 (ISO week 2026-W35). Weeks run Monday to Sunday in UTC.
179 records published, +7 on the previous week: 67 vulnerabilities (+13), 1 incident (+1), 2 research items (-10), 108 news items (+3), 1 policy item (no change).
Critical and high advisories
Vulnerability records rated critical or high, newest first. Showing 25 of 53.- High
CVE-2026-82639: NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint…
CVE-2026-82639NVD/CVE Database - Critical
CVE-2026-19295: IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands…
CVE-2026-19295NVD/CVE Database - Critical
CVE-2026-19286: IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper…
CVE-2026-19286NVD/CVE Database - High
CVE-2026-18904: IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject…
CVE-2026-18904NVD/CVE Database - High
CVE-2026-18899: IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to path traversal.
CVE-2026-18899NVD/CVE Database - High
CVE-2026-18891: IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive…
CVE-2026-18891NVD/CVE Database - High
CVE-2026-18729: IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to…
CVE-2026-18729NVD/CVE Database - High
CVE-2026-82288: Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags…
CVE-2026-82288NVD/CVE Database - High
CVE-2026-82275: Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the document parser that fails to restrict file…
CVE-2026-82275NVD/CVE Database - High
CVE-2026-82268: Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats…
CVE-2026-82268NVD/CVE Database - Critical
CVE-2026-54745: Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0…
CVE-2026-54745NVD/CVE Database - High
GHSA-86m2-fcxq-5q7c: 9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
CVE-2026-55641GitHub Advisory Database - High
GHSA-8gmq-j984-vp4r: 9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
CVE-2026-55638GitHub Advisory Database - High
CVE-2026-74820: ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This…
CVE-2026-74820NVD/CVE Database - High
CVE-2026-37009: A SQL injection vulnerability in NL2SQLTool in crewai-tools v1.10.2rc1 allows a remote attacker to execute arbitrary…
CVE-2026-37009NVD/CVE Database - High
CVE-2026-37007: A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows a remote attacker to achieve code execution via…
CVE-2026-37007NVD/CVE Database - Critical
CVE-2026-37004: BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote…
CVE-2026-37004NVD/CVE Database - Critical
CVE-2026-37003: Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection. The PythonTools and…
CVE-2026-37003NVD/CVE Database - High
CVE-2026-18885: ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This…
CVE-2026-18885NVD/CVE Database - High
CVE-2026-75871: GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from…
CVE-2026-75871NVD/CVE Database - High
CVE-2026-19889: GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from…
CVE-2026-19889NVD/CVE Database - High
CVE-2026-47852: A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model…
CVE-2026-47852NVD/CVE Database - High
CVE-2025-61165: An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows…
CVE-2025-61165NVD/CVE Database - High
CVE-2025-61162: Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user info via a crafted…
CVE-2025-61162NVD/CVE Database - High
CVE-2026-58474: whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote…
CVE-2026-58474NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.No vulnerability published in this week is listed as exploited or has an EPSS score of 10% or more.
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| lfx-openai-compatible | PyPI | LangChain | 0.1.2rc2 | |
| n8n-nodes-base | npm | 2.37.0 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| Model Context Protocol | 8 | 7.5 | +0.5 |
Research
Peer-reviewed first, then newest.Policy and regulation
Newest first.Generated from the AI Sec Watch database at . Every item links to its record.