Skip to content

Known exploited vulnerabilities in AI software

14 advisories in this database are listed in the CISA Known Exploited Vulnerabilities catalog, which names vulnerabilities that CISA reports as exploited in the wild. The catalog covers all kinds of software. This list includes only the entries that match an advisory for AI software in this database.

Every CVE in the database is compared with the catalog on each fetch cycle. Fetch cycles run every six hours. The methods page describes how each field is produced and its limits.

Advisories in this database that are listed in the CISA Known Exploited Vulnerabilities catalog, most recently added first
CVEAdvisorySeverityAdded by CISAEPSSRansomware usePublished
CVE-2026-49869CVE-2026-49869: Kestra OSS OS Command Injection VulnerabilityCritical2.1%Unknown
CVE-2026-59822CVE-2026-59822: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP…High0.8%Unknown
CVE-2026-64849GHSA-7gwp-5pfp-969j: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)Critical9.8%Unknown
CVE-2025-62593CVE-2025-62593: Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be…Critical62.5%Unknown
CVE-2026-9198CVE-2026-9198: IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER…Critical28.7%Unknown
CVE-2026-0770CVE-2026-0770: Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability…Critical63.0%Unknown
CVE-2026-55255GHSA-qrpv-q767-xqq2: Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's FlowCritical0.9%Unknown
CVE-2026-42271CVE-2026-42271: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before…Critical92.6%Unknown
CVE-2025-34291CVE-2025-34291: Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote…High92.8%Unknown
CVE-2026-42208CVE-2026-42208: LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before…Critical5.8%Unknown
CVE-2026-39987CVE-2026-39987: Marimo Remote Code Execution VulnerabilityCritical37.9%Unknown
CVE-2026-33017GHSA-vwmf-pq79-vjvx: Unauthenticated Remote Code Execution in Langflow via Public Flow Build EndpointCritical24.8%Unknown
CVE-2025-68613CVE-2025-68613: n8n Improper Control of Dynamically-Managed Code Resources VulnerabilityCritical99.0%Unknown
CVE-2025-3248CVE-2025-3248: Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and xCritical100.0%Known

Severity comes from the source advisory when it gives one, otherwise from the classifier. EPSS is the FIRST estimate of the probability that a CVE is exploited in the next 30 days, and it is read again about once a day. Ransomware use is the catalog's own field for known use in ransomware campaigns. A record stays on this list if CISA later removes its entry. Published dates are in UTC.