What changed in AI security, Sep 7 to Sep 13, 2026
Sep 7 to Sep 13, 2026 (ISO week 2026-W37). Weeks run Monday to Sunday in UTC.
215 records published, -24 on the previous week: 62 vulnerabilities (+2), 0 incidents (no change), 3 research items (-11), 147 news items (-17), 3 policy items (+2).
Critical and high advisories
Vulnerability records rated critical or high, newest first. Showing 25 of 42.- High
CVE-2026-37008: CrewAI Python blocklist bypass via ctypes loading the C library
CVE-2026-37008NVD/CVE Database - High
CVE-2026-90777: ESPnet arbitrary code execution through pretrained checkpoint deserialization
CVE-2026-90777NVD/CVE Database - High
CVE-2026-90553: vLLM remote code execution in LlavaOnevision2 processor loader
CVE-2026-90553NVD/CVE Database - High
CVE-2026-89332 - Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration
AWS Security Bulletins - High
CVE-2026-87988: Mistral Vibe arbitrary file access by bypassing workspace restrictions
CVE-2026-87988NVD/CVE Database - High
CVE-2026-87987: Mistral Vibe arbitrary code execution via environment variable assignments
CVE-2026-87987NVD/CVE Database - High
CVE-2026-87986: Mistral Vibe arbitrary code execution by bypassing command permission checks
CVE-2026-87986NVD/CVE Database - High
CVE-2026-87985: Mistral Vibe arbitrary code execution via ANSI-C quoted command arguments
CVE-2026-87985NVD/CVE Database - High
CVE-2026-87984: Mistral Vibe arbitrary file write through shell redirection
CVE-2026-87984NVD/CVE Database - High
CVE-2026-87983: Mistral Vibe arbitrary file read via quoted absolute paths in shell commands
CVE-2026-87983NVD/CVE Database - High
CVE-2026-71416: Headroom WebSocket origin validation flaw enables unauthenticated LLM requests
CVE-2026-71416NVD/CVE Database - High
CVE-2026-19486: A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder…
CVE-2026-19486NVD/CVE Database - High
CVE-2026-84889: IBM Langflow OSS arbitrary code execution via path traversal
CVE-2026-84889NVD/CVE Database - High
CVE-2026-81941: IBM Langflow OSS command execution through MCP Tools stdio transport
CVE-2026-81941NVD/CVE Database - High
CVE-2026-81940: IBM Langflow OSS code execution via flow display names
CVE-2026-81940NVD/CVE Database - High
CVE-2026-81268: IBM Langflow OSS flaw keeps API key access after deactivation
CVE-2026-81268NVD/CVE Database - High
CVE-2026-81265: IBM Langflow OSS 1.0.0 through 1.11.5.
CVE-2026-81265NVD/CVE Database - High
CVE-2026-81213: IBM Langflow OSS information disclosure via unvalidated user-supplied URLs
CVE-2026-81213NVD/CVE Database - High
CVE-2026-81211: IBM Langflow OSS arbitrary Python code execution via stored flows
CVE-2026-81211NVD/CVE Database - Critical
CVE-2026-81204: IBM Langflow OSS remote code execution through code injection
CVE-2026-81204NVD/CVE Database - High
CVE-2026-79742: IBM Langflow OSS remote code execution via incomplete blocklist
CVE-2026-79742NVD/CVE Database - Critical
CVE-2026-79724: IBM Langflow OSS remote OS command execution via improper neutralization
CVE-2026-79724NVD/CVE Database - High
CVE-2026-78575: IBM Langflow OSS command execution via MCP stdio server configuration
CVE-2026-78575NVD/CVE Database - High
CVE-2026-78571: IBM Langflow OSS remote code execution through unguarded eval call
CVE-2026-78571NVD/CVE Database - High
CVE-2026-78569: IBM Langflow OSS code execution through incomplete security scanner denylist
CVE-2026-78569NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.No vulnerability published in this week is listed as exploited or has an EPSS score of 10% or more.
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| lfx-docling | PyPI | Hugging Face Hub / Transformers | 0.1.7rc0 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| Inference infrastructure | 7 | 4.3 | +2.8 |
| Frontier model safety | 5 | 2.5 | +2.5 |
| AI agents | 20 | 19.0 | +1.0 |
Research
Peer-reviewed first, then newest.Can LLMs Keep Up? Evaluating Phishing Detection on Telegram
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)CAFBA: Context-aware adaptive fusion backdoor attack for polyp segmentation
Peer-reviewedElsevier Security JournalsFunding grants for new research into AI and teen development
IndustryOpenAI Blog
Policy and regulation
Newest first.Generated from the AI Sec Watch database at . Every item links to its record.