What changed in AI security
Sep 14 to Sep 20, 2026 (ISO week 2026-W38). Weeks run Monday to Sunday in UTC.
255 records published, +40 on the previous week: 51 vulnerabilities (-11), 0 incidents (no change), 12 research items (+9), 190 news items (+43), 2 policy items (-1).
Critical and high advisories
Vulnerability records rated critical or high, newest first. Showing 25 of 27.- High
CVE-2026-93993: Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that…
CVE-2026-93993NVD/CVE Database - High
GHSA-qg2g-g9w3-m5h8: ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement
CVE-2026-58197GitHub Advisory Database - High
GHSA-3hmm-rh5q-gwwr: LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading
CVE-2026-33625Hugging Face Security Advisories - Critical
GHSA-2vh9-42vm-xmv2: LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
CVE-2025-66455GitHub Advisory Database - High
CVE-2026-93592: vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints…
CVE-2026-93592NVD/CVE Database - High
CVE-2026-85887: Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose…
CVE-2026-85887NVD/CVE Database - High
CVE-2026-93436: vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode…
CVE-2026-93436NVD/CVE Database - Critical
CVE-2026-85885: Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an…
CVE-2026-85885NVD/CVE Database - High
CVE-2026-78501: Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business…
CVE-2026-78501NVD/CVE Database - High
CVE-2026-68791: Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a…
CVE-2026-68791NVD/CVE Database - High
CVE-2026-54520: AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior…
CVE-2026-54520NVD/CVE Database - High
CVE-2026-54519: AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior…
CVE-2026-54519NVD/CVE Database - Critical
CVE-2026-53557: SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated…
CVE-2026-53557NVD/CVE Database - High
CVE-2026-53556: SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST…
CVE-2026-53556NVD/CVE Database - High
CVE-2026-53554: SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST…
CVE-2026-53554NVD/CVE Database - High
CVE-2026-54504: MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From…
CVE-2026-54504NVD/CVE Database - High
CVE-2026-62997: Kedro-Datasets provides data connectors for Kedro. From version 5.0.0 until 9.5.0…
CVE-2026-62997NVD/CVE Database - High
CVE-2026-59823: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.9, an authenticated…
CVE-2026-59823NVD/CVE Database - High
CVE-2026-59974: Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human…
CVE-2026-59974NVD/CVE Database - Critical
CVE-2025-59953: LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and…
CVE-2025-59953NVD/CVE Database - High
GHSA-5648-rgj9-v224: @zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS
GitHub Advisory Database - High
CVE-2026-83071: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Machine…
CVE-2026-83071NVD/CVE Database - High
CVE-2026-91933: Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing…
CVE-2026-91933NVD/CVE Database - Critical
CVE-2026-19407: Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an…
CVE-2026-19407NVD/CVE Database - High
CVE-2026-57586: CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the…
CVE-2026-57586NVD/CVE Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.No vulnerability published in this week is listed as exploited or has an EPSS score of 10% or more.
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.| Package | Ecosystem | LLM SDKs | Release | Released |
|---|---|---|---|---|
| @copilotkit/mcp-apps-renderer | npm | Model Context Protocol SDK | 1.71.2 |
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| Inference infrastructure | 11 | 4.5 | +6.5 |
| AI agents | 26 | 21.3 | +4.8 |
| Retrieval-augmented generation | 4 | 0.8 | +3.3 |
| AI regulation and standards | 3 | 0.3 | +2.8 |
| Deepfakes and impersonation | 3 | 0.8 | +2.3 |
Research
Peer-reviewed first, then newest. Showing 8 of 12.Pedagogical Twins: Conceptualizing an Educational Doppelganger
Peer-reviewedAIS eLibrary (Journal of AIS, CAIS, etc.)ABE-FL: Efficient and secure federated learning based on CP-ABE with high-security elliptic curves
Peer-reviewedElsevier Security JournalsAdvanced Cross-Attack Backdoor Detector Based on Disturbance Immunity Learned From Classic Backdoor Attacks
Peer-reviewedIEEE Xplore (Security & AI Journals)EXE-Bench: Ranking the Tradeoffs of AI-Based Windows Malware Detectors for Real-World Usability
Peer-reviewedIEEE Xplore (Security & AI Journals)Practical Federated Unlearning: A Target Client-Driven Approach to Model Forgetting
Peer-reviewedIEEE Xplore (Security & AI Journals)SVAttack: Spatial-Viewpoint Transfer Attack on Graph Convolutional Skeleton Action Recognition
Peer-reviewedIEEE Xplore (Security & AI Journals)Unveiling the Backdoor’s Suppression Effect for Backdoor Defence
Peer-reviewedIEEE Xplore (Security & AI Journals)Vec2Null: Structured Identity Vectorization and Nulling for One-Shot Face Unlearning
Peer-reviewedIEEE Xplore (Security & AI Journals)
Policy and regulation
Newest first.Generated from the AI Sec Watch database at . Every item links to its record.