What changed in AI security
Sep 28 to Oct 4, 2026 (ISO week 2026-W40). Weeks run Monday to Sunday in UTC.
225 records published, -3 on the previous week: 32 vulnerabilities (-19), 2 incidents (+1), 10 research items (+2), 178 news items (+11), 3 policy items (+2).
Critical and high advisories
Vulnerability records rated critical or high, newest first.- High
GHSA-x8gv-g2g3-65fj: SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF)
GitHub Advisory Database - Critical
GHSA-v2f8-6655-7grj: Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain
GitHub Advisory Database - High
GHSA-5rmq-chc7-m22f: Vibe-Trading file-read tools expose arbitrary server-readable files
GitHub Advisory Database - Critical
GHSA-jqmf-mx4f-hfr6: Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF
GitHub Advisory Database - High
CVE-2026-104019 - OS command injection in the Studio Space startup script in Amazon SageMaker Distribution
AWS Security Bulletins - Critical
CVE-2026-103956, CVE-2026-103957, and CVE-2026-103958 - Issues in Loom for AWS
AWS Security Bulletins - Critical
CVE-2026-90970: GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from…
CVE-2026-90970NVD/CVE Database - High
CVE-2026-51888: langflow-ai langflow v1.8.4 is affected by: Directory Traversal. The impact is: Arbitrary file write outside the…
CVE-2026-51888NVD/CVE Database - Critical
CVE-2026-51886: langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The…
CVE-2026-51886NVD/CVE Database - High
CVE-2026-51884: The /knowledge_base/upload_temp_docs temporary document upload endpoint in Langchain Chatchat 0.3.1 is vulnerable to…
CVE-2026-51884NVD/CVE Database - High
CVE-2026-51883: The knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is vulnerable to path…
CVE-2026-51883NVD/CVE Database - High
CVE-2026-51882: The OpenAI-compatible file upload endpoint `/v1/files` in Langchain-Chatchat 0.3.0 is vulnerable to path traversal. An…
CVE-2026-51882NVD/CVE Database - High
CVE-2026-97662 - Argument injection in AWS security-agent-mcp-server diff scan
AWS Security Bulletins - High
CVE-2026-96561: The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site…
CVE-2026-96561NVD/CVE Database - High
CVE-2026-103012: Claude Code selected an API key stored by Claude Code, for example from an earlier `/login` or written directly to its…
CVE-2026-103012NVD/CVE Database - High
CVE-2026-103055: AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verification in the realtime WebSocket and SSE…
CVE-2026-103055NVD/CVE Database - Critical
CVE-2026-102730: Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap…
CVE-2026-102730NVD/CVE Database - High
CVE-2026-102697: Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization vulnerability in the experimental agent mode…
CVE-2026-102697NVD/CVE Database - High
CVE-2026-77177: Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code…
CVE-2026-77177NVD/CVE Database - High
CVE-2026-100308: Deserialization of untrusted data in the model loading component in Amazon GluonTS before 0.17.0 might allow…
CVE-2026-100308NVD/CVE Database - High
CVE-2026-93355: LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured…
CVE-2026-93355NVD/CVE Database - High
CVE-2026-55157: Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge…
CVE-2026-55157NVD/CVE Database - High
GHSA-456v-xq2p-r4cj: code-ollama: `grep_search` Command Injection via Unescaped `$()` Shell Substitution (CWE-78)
GitHub Advisory Database
Exploitation signals
Vulnerabilities published in the week that are listed in the CISA Known Exploited Vulnerabilities catalog or have an EPSS score of 10% or more.No vulnerability published in this week is listed as exploited or has an EPSS score of 10% or more.
Packages that began delegating to a language model
Exposure Registry packages whose first release declaring an LLM SDK, agent framework or MCP dependency was published in the week.No tracked package published its first release with an LLM SDK, agent framework or MCP dependency in this week.
Topics that moved
Largest increases over the mean of the 4 previous weeks, for topics with at least 3 records in the week.| Topic | Records | Weekly mean, previous 4 | Difference |
|---|---|---|---|
| AI agents | 42 | 28.0 | +14.0 |
| Adversarial machine learning | 4 | 2.3 | +1.8 |
| Frontier model safety | 5 | 3.5 | +1.5 |
| Model Context Protocol | 7 | 6.3 | +0.8 |
Research
Peer-reviewed first, then newest. Showing 8 of 10.HFL-Deflect: Defence framework against adaptive coordinated poisoning attacks in hierarchical federated learning
Peer-reviewedElsevier Security JournalsGDPFDL: A secure and efficient personalized federated distillation framework against inference attacks
Peer-reviewedElsevier Security JournalsHard-label black-box model extraction attacks against network intrusion detection systems via generative adversarial networks
Peer-reviewedElsevier Security Journals(Un)Cooperative Robots: From Compliance AI to Principled Uncooperative AI
Peer-reviewedAIS eLibrary (Journal of AIS, CAIS, etc.)Exploring the Perceived Awareness–Behaviour Gap in AI-Enabled Phishing: A Socio-Technical Perspective Informed by Complex Adaptive Systems
Peer-reviewedElsevier Security JournalsLarge Language Models and Social Media Information Integrity: Opportunities, Challenges, and Research Directions
Peer-reviewedACM Digital Library (TOPS, DTRAP, CSUR)Security threat modeling for emerging AI-agent protocols: A comparative analysis of MCP, A2A, agora, and ANP
Peer-reviewedElsevier Security JournalsEfficient model stealing in data-free scenarios: An attack method via elite sample distillation
Peer-reviewedElsevier Security Journals
Policy and regulation
Newest first.Generated from the AI Sec Watch database at . Every item links to its record.