What changed in AI security, Aug 31 to Sep 6, 2026
Aug 31 to Sep 6, 2026 (ISO week 2026-W36). Weeks run Monday to Sunday in UTC.
239 records published, +60 on the previous week: 60 vulnerabilities (-7), 0 incidents (-1), 14 research items (+12), 164 news items (+56), 1 policy item (no change).
Critical and high advisories
Vulnerability records rated critical or high, newest first. Showing 25 of 36.- High
CVE-2026-85787 - An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server to modify data beyond the read-only scope
AWS Security Bulletins - High
CVE-2026-85654 - Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server
AWS Security Bulletins - High
GHSA-gx45-xrj5-g6c4: CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
CVE-2026-75911GitHub Advisory Database - High
GHSA-c6mw-8xh8-gpq6: CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
CVE-2026-75912GitHub Advisory Database - High
GHSA-h539-c7r8-3xq4: CodeWhale: js_execution leaks parent environment to model context via missing env scrub
CVE-2026-75915GitHub Advisory Database - High
GHSA-g29h-pfmp-qp9r: CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)
CVE-2026-75857GitHub Advisory Database - High
GHSA-62f5-cp2p-vq95: CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
CVE-2026-75859GitHub Advisory Database - Critical
CVE-2026-31020: In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt…
CVE-2026-31020NVD/CVE Database - High
CVE-2026-19306: IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server…
CVE-2026-19306NVD/CVE Database - High
CVE-2026-19305: IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side…
CVE-2026-19305NVD/CVE Database - High
CVE-2026-19304: IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information from…
CVE-2026-19304NVD/CVE Database - High
CVE-2026-19303: IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or…
CVE-2026-19303NVD/CVE Database - High
CVE-2026-19300: IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete…
CVE-2026-19300NVD/CVE Database - High
CVE-2026-19298: IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an…
CVE-2026-19298NVD/CVE Database - Critical
CVE-2026-85695: FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated…
CVE-2026-85695NVD/CVE Database - High
CVE-2026-85694: LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that…
CVE-2026-85694NVD/CVE Database - High
CVE-2026-85686: ms-swift 4.5.2 contains a server-side request forgery vulnerability in the swift deploy OpenAI-compatible API that…
CVE-2026-85686NVD/CVE Database - High
CVE-2026-85675: OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_document_content…
CVE-2026-85675NVD/CVE Database - High
CVE-2026-85673: LLaMA-Factory contains a server-side request forgery vulnerability in the OpenAI-compatible API multimodal media URL…
CVE-2026-85673NVD/CVE Database - High
CVE-2026-85666: OGX (formerly Llama Stack, affected at commit fbe8e0f) contains an unauthenticated server-side request forgery…
CVE-2026-85666NVD/CVE Database - Critical
CVE-2026-80098: Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate…
CVE-2026-80098NVD/CVE Database - High
CVE-2026-84779: Subscriber Broken Access Control in Agentimus – AI SEO, llms.txt & MCP for AI Agents <= 1.51.0 versions.
CVE-2026-84779NVD/CVE Database - High
CVE-2026-85180: Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing unauthenticated attackers to…
CVE-2026-85180NVD/CVE Database - High
CVE-2026-85178: Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET /v1/vault/key/{providerKeyId} endpoint fails…
CVE-2026-85178NVD/CVE Database - Critical
CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability
CVE-2026-49869CISA Known Exploited Vulnerabilities
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.| Advisory | Exploitation | EPSS | Published |
|---|---|---|---|
| CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability CVE-2026-49869CISA Known Exploited Vulnerabilities | Known exploited | 2.1% |
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| browser-harness | PyPI | Model Context Protocol SDK | 0.1.11 | |
| sgl-eval | PyPI | Hugging Face Hub / Transformers, OpenAI SDK | 0.1.0 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| AI agents | 29 | 21.5 | +7.5 |
| Adversarial machine learning | 4 | 0.5 | +3.5 |
| Robotics and embodied AI | 3 | 0.8 | +2.3 |
| Prompt injection and jailbreaks | 4 | 3.5 | +0.5 |
Research
Peer-reviewed first, then newest. Showing 8 of 14.AttackLogGen: Benchmarking LLMs for Generating Attack Logs
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)Towards Trustworthy Retrieval Augmented Generation for Large Language Models: A Survey
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)Deepfake Media Generation and Detection in the Generative AI Era: A Survey and Outlook
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)Impact of Intelligent Technologies on IoV Security: Integrating Edge Computing and AI
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)A Comparative Survey of Security Risks in AI Systems: From LLMs to AI Agents and Embodied Agents
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)Action-Level Backdoor Attacks Against Deep Reinforcement Learning Systems via Adaptive Reward Exploration
Peer-reviewedIEEE Xplore (Security & AI Journals)Defending Against Adversarial Malware Attacks on ML-Based Android Malware Detection Methods
Peer-reviewedIEEE Xplore (Security & AI Journals)Generative Textual Adversarial Attack Through Extensible Compositional Perturbation via Reinforcement Learning for Policy Optimization
Peer-reviewedIEEE Xplore (Security & AI Journals)
Policy and regulation
Newest first.Generated from the AI Sec Watch database at . Every item links to its record.