This week

Vulnerabilities from the past 7 days in AI security or the software supply chain, or exploited / highest severity. Items we have written up link to our page.

This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.

Updated 2026-09-24 13:45 UTC · 56 items · 9 in KEV · 1 written up · RSS

DateIDCategory and summaryCVSSOur status
2026-09-24CVE-2026-93577
Other high risk

AI summaryUnder certain conditions, an integer overflow in GitLab CE/EE 19.2–19.4 before patches may let authenticated users run code on the server.

9.9Candidate
2026-09-24CVE-2026-92874
AI trust boundary

AI summaryGitLab CE/EE 18.3+ before fixes may let authenticated users with MCP-scoped tokens act beyond the token's intended scope.

5.4Candidate
2026-09-24CVE-2026-92628
AI trust boundary

AI summaryA race condition in GitLab CE/EE's MCP search tool (18.6 through pre-19.4.1) could return search results under the wrong user context.

3.1Candidate
2026-09-24CVE-2026-89078
Other high risk

AI summaryUnder certain conditions, a double free in GitLab CE/EE 19.2–19.4 before patches may let authenticated users run code on the server.

9.9Candidate
2026-09-23CVE-2026-93352
Vulnerable dependency

AI summaryLaravel-Mediable 7.0.0–7.0.1 misses .pht in its upload blocklist (incomplete CVE-2026-49972 fix), so Apache may run such files as PHP.

9.3Candidate
2026-09-23CVE-2026-96804
AI trust boundary

AI summaryMLflow's statsmodel flavor (2.1.0–3.14.0) ignores the pickle-blocking setting, so a crafted MLmodel artifact can run arbitrary code.

8.8Candidate
2026-09-23CVE-2026-96775
AI trust boundary

AI summaryMLflow's dspy flavor (2.0+) enforces its pickle-blocking setting only for .pkl paths, so a crafted MLmodel artifact can run code.

8.8Candidate
2026-09-23CVE-2026-96759
Vulnerable dependency

AI summaryorval before 8.29.0 doesn't escape operationId, so crafted OpenAPI specs can inject JavaScript into generated query hooks.

9.3Candidate
2026-09-23CVE-2026-96758
Vulnerable dependency

AI summary@orval/core before 8.28.0's form-data serializer doesn't escape property names, so crafted OpenAPI specs can inject code.

9.3Candidate
2026-09-23CVE-2026-96757
Vulnerable dependency

AI summaryorval before 8.29.0 doesn't escape OpenAPI media-type keys, letting crafted specs inject JavaScript into generated fetch or mock code.

9.3Candidate
2026-09-23CVE-2026-96756
Vulnerable dependency

AI summaryorval before 8.30.0's @orval/core doesn't escape date defaults, so crafted OpenAPI specs can inject code into generated output.

9.2Candidate
2026-09-23CVE-2026-96755
Vulnerable dependency

AI summaryorval 8.14.0–8.28.1's @orval/effect generator lets crafted OpenAPI schema defaults inject JavaScript that runs in generated code.

9.3Candidate
2026-09-23CVE-2026-96754
Vulnerable dependency

AI summaryorval before 8.29.0's @orval/hono generator doesn't escape OpenAPI paths, so a crafted spec can inject code into generated output.

9.3Candidate
2026-09-23CVE-2026-18875
AI trust boundary

AI summaryIBM FTM for Red Hat OpenShift's AI agent server lets unauthenticated users insert runbook content into its vector DB to steer the agent.

7.3Candidate
2026-09-23CVE-2026-96276
Vulnerable dependency

AI summaryIf a developer runs flatpak build-init with a malicious SDK's extension, files may be written outside the working directory.

9.8Candidate
2026-09-23CVE-2026-96560
AI product bug

AI summaryLightLLM through 1.2.0, when run with --pd_trans_mode nccl, exposes an unauthenticated RPyC channel allowing remote code execution.

9.3Candidate
2026-09-23CVE-2026-59167
Vulnerable dependency

AI summarySunEditor before 2.47.11 fails to strip event-handler attributes from crafted custom/namespaced elements, risking XSS in apps using it.

10.0Candidate
2026-09-23CVE-2026-54892
Vulnerable dependency

AI summaryPlug decodes nested query/body parameters in quadratic time, letting crafted requests cause denial of service in apps using Plug.

8.7Candidate
2026-09-23CVE-2026-86246
Vulnerable dependency

AI summaryApache Tomcat Native from 2.0.0 enables insecure TLS options by default, such as client renegotiation, weakening connection security.

9.1Candidate
2026-09-23CVE-2026-87022
Vulnerable dependency

AI summaryApache Tomcat 9.0, 10.1 and 11.0 (up to 9.0.121/10.1.59/11.0.25) allow WebSocket message smuggling when per-message-deflate is used.

7.5Candidate
2026-09-23CVE-2026-86350
Vulnerable dependency

AI summaryA regression in Apache Tomcat 11.0.22+ and 10.1.55+ HTTP/2 handling can mix up request headers (request smuggling).

9.1Candidate
2026-09-23CVE-2026-86248
Vulnerable dependency

AI summaryIn some Apache Tomcat 9.0, 10.1 and 11.0 versions, CLIENT_CERT authentication may not fail as expected when soft fail is disabled.

9.8Candidate
2026-09-23CVE-2026-76183
Vulnerable dependency

AI summaryApache Tomcat 9.0.0.M1–9.0.121, 10.1.0-M1–10.1.59 and 11.0.0-M1–11.0.25 let WebSocket endpoint security constraints be bypassed.

9.8Candidate
2026-09-22CVE-2026-19202
AI trust boundary

AI summarymcp-toolbox-sdk-python's toolbox-core reuses one cached Google ID token across audiences; affects apps using 2+ audiences in one process.

9.1Candidate
2026-09-22CVE-2026-88624
AI product bug

AI summaryopenCode v1.18.26's Worktree.remove lacks path validation, letting attackers trigger arbitrary recursive directory deletion.

9.1Candidate
2026-09-22CVE-2026-87121
Vulnerable dependency

AI summaryAn out-of-bounds write in the lwIP TCP/IP stack's MQTT component may let an attacker fully execute code on affected devices.

9.3Candidate
2026-09-22CVE-2026-28324
Other high risk

AI summarySolarWinds Observability Self-Hosted allows unauthenticated remote code execution, but only in non-default, non-secure configurations.

9.8Candidate
2026-09-22CVE-2026-77244
AI trust boundary
mcp-atlassian: 20 CVEs fixed in the same release
Show all IDs
  • CVE-2026-77244 MCP Atlassian's HTTP transport accepts any non-empty token via AtlassianOpaqueTokenVerifier, bypassing authentication.
  • CVE-2026-77242 MCP Atlassian before 0.22.0 checks URLs for SSRF but resolves DNS again when connecting, so DNS rebinding can bypass the check.
  • CVE-2026-77243 MCP Atlassian's ENABLED_TOOLS / toolset authorization restrictions can be bypassed, affecting deployments that rely on them.
  • CVE-2026-77246 MCP Atlassian's attachment upload doesn't validate paths, letting MCP HTTP clients exfiltrate files local to the server.
  • CVE-2026-77247 MCP Atlassian's unrestricted file_path parameters let callers upload any server-local file as a Jira or Confluence attachment.
  • CVE-2026-77248 MCP Atlassian's streamable-http transport lacks auth, so unauthenticated callers can read local files via upload_attachment's file_path.
  • CVE-2026-77251 MCP Atlassian's project/space filters (JIRA_PROJECTS_FILTER, CONFLUENCE_SPACES_FILTER) can be bypassed to read forbidden content.
  • CVE-2026-77252 MCP Atlassian before 0.22.0 lets caller-supplied project/space filters override administrator-configured allowlists.
  • CVE-2026-77253 MCP Atlassian's Jira and Confluence attachment upload tools can read arbitrary files on the server running it.
  • CVE-2026-77254 MCP Atlassian before 0.22.0 lets HTTP requests without a per-user identity use the globally configured Jira/Confluence credentials.
  • CVE-2026-77255 MCP Atlassian's Jira update_issue tool can be abused as a confused deputy to read and exfiltrate arbitrary files from the server.
  • CVE-2026-77257 MCP Atlassian's upload tools, when served over HTTP, accept arbitrary server-local file paths, exposing files on the server.
  • CVE-2026-77258 MCP Atlassian's upload_attachment lacks validate_safe_path(), allowing arbitrary file read and exfiltration from the server.
  • CVE-2026-77259 MCP Atlassian's confluence_upload_attachment tool can read arbitrary files, allowing exfiltration of server credentials.
  • CVE-2026-77260 MCP Atlassian's Jira and Confluence upload_attachment tools accept an unconstrained file_path, allowing arbitrary local file reads.
  • CVE-2026-77262 MCP Atlassian's confluence_upload_attachment tool allows path traversal file reads due to an incomplete fix of GHSA-xjgw-4wvw-rgm4.
  • CVE-2026-77266 MCP Atlassian's upload_attachment tool has a path traversal letting MCP tool callers read and exfiltrate arbitrary files.
  • CVE-2026-77269 MCP Atlassian's upload_attachment still allows path traversal to read arbitrary files, due to an incomplete fix for CVE-2026-27825.
  • CVE-2026-77270 MCP Atlassian's attachment upload tools can be used to read arbitrary files on the server hosting it.
  • CVE-2026-77271 MCP Atlassian's incomplete path traversal fix still allows overwriting modules in the working directory, leading to code execution.
10.0Write-up in review
2026-09-22CVE-2026-95660
AI trust boundary

AI summaryMoonshot AI Kimi Code up to 0.31.0 has an OS command injection flaw in its MCP configuration loader, reportedly remotely triggerable.

2.1Candidate
2026-09-22CVE-2026-85734
AI product bug

AI summarylightrag-hku has no rate limiting on its /login endpoint, allowing password brute-force attempts.

9.1Candidate
2026-09-22CVE-2026-63374
Vulnerable dependency

AI summaryAnyIO before 4.14.2 may check internationalized hostnames in connect_tcp()/TLSStream.wrap() using IDNA 2003 instead of IDNA 2008.

9.3Candidate
2026-09-22CVE-2026-94127
Not classified yet

AI summaryBIG-IP APM configured as an OAuth Authorization Server with an access policy may allow remote code execution via malicious traffic.

9.3KEVWritten up →
2026-09-22CVE-2026-93088
AI product bug

AI summarySGLang's disaggregated-diffusion DiffusionServer exposes an unauthenticated ZeroMQ socket, enabling unauthenticated code execution.

9.8Write-up in review
2026-09-22CVE-2026-79313
Vulnerable dependency

AI summaryweb.py 0.76 doesn't check session age on load, so expired sessions not yet cleaned up may still be accepted.

9.8Candidate
2026-09-22CVE-2026-65178
AI trust boundary

AI summaryNVIDIA NeMo's dataset loading can accept unsafe parameters from a crafted model_config.yaml, possibly leading to code execution.

7.8Candidate
2026-09-22CVE-2026-93616
Other high risk

AI summaryA directory traversal and file upload flaw lets unauthenticated attackers upload and run scripts on Check Point Management Server.

9.8KEVCandidate
2026-09-22CVE-2026-89422
Vulnerable dependency

AI summaryErlang/OTP ssl TLS 1.3 clients may finish a handshake without validating the server, letting a responding peer impersonate it.

9.3Candidate
2026-09-22CVE-2026-93952
Other high risk

AI summaryOn-prem VeloCloud Orchestrator may let a remote attacker access privileged internal functions and compromise the orchestrator host.

9.5KEVCandidate
2026-09-22CVE-2026-85102
Other high risk

AI summaryA VPN certificate validation flaw in Check Point Quantum Security Gateway may let unauthenticated remote attackers run code on it.

9.8KEVCandidate
2026-09-21CVE-2026-78847
Vulnerable dependency

AI summarygray-matter (all versions, verified 4.0.3) uses eval() to parse JavaScript front matter, allowing arbitrary code execution.

9.8Candidate
2026-09-21CVE-2026-79916
AI product bug

AI summaryMaxKB before 2.10.5-lts lets authenticated workspace members inject control characters into the server's AWS credentials file.

9.1Candidate
2026-09-21CVE-2026-77521
AI trust boundary

AI summaryMaxKB before 2.10.5-lts exposes a shell execute tool without human approval to assistants that have tools, MCP tools, skills or sub-apps.

10.0Candidate
2026-09-21CVE-2026-77519
AI trust boundary

AI summaryMaxKB 2.10.2-lts and earlier don't check API key expiry on /chat/api/mcp, so expired non-permanent keys may still authenticate.

5.4Candidate
2026-09-21CVE-2026-77516
AI trust boundary

AI summaryMaxKB 2.0.0–2.9.2 lets lowest-role workspace members run tools they were denied by binding tool IDs in agents or workflows.

5.4Candidate
2026-09-21CVE-2026-61647
AI trust boundary

AI summary@roomi-fields/notebooklm-mcp's vault.batch tool has a path traversal allowing files to be written outside the intended vault directory.

7.1Candidate
2026-09-21CVE-2026-93012
Vulnerable dependency

AI summaryOn Windows, Perl's Email::Sender::Transport::Sendmail before 2.602 may run arbitrary commands via envelope addresses reaching a shell.

9.8Candidate
2026-09-21CVE-2026-94301
Vulnerable dependency

AI summaryMINA's fix for CVE-2026-47065 (acceptMatchers filter bypass) was only committed to 2.2.X, so 2.0.X/2.1.X releases may lack it.

9.8Candidate
2026-09-21CVE-2026-55071
AI trust boundary

AI summaryMCP-for-Stata before 1.19.0 puts unvalidated input from its ado_package_install tool into Stata commands, enabling command injection.

8.4Candidate
2026-09-21CVE-2026-7273
Not classified yet

AI summaryZyxel GS1900-48HPv2 firmware ≤2.90(ABTQ.1)C0 has a CGI stack overflow that may let unauthenticated LAN attackers run OS commands.

8.8KEVNot classified yet
2026-09-18CVE-2026-33625
AI trust boundary

AI summaryLMDeploy 0.12.1–0.12.2 can run arbitrary Python code when loading a malicious HuggingFace model, due to code injection in config.py.

8.8Candidate
2026-09-18CVE-2025-66455
AI product bug

AI summaryLMDeploy deserializes pickle data in handle_zmq_recv (disaggregation engine connection), allowing remote code execution.

9.8Candidate
2026-09-18CVE-2025-39682
Not classified yet

AI summaryLinux kernel TLS (kTLS) receive code mishandles zero-length records on the rx_list; affects systems using kernel TLS.

9.8KEVNot classified yet
2026-09-18CVE-2026-53266
Not classified yet

AI summaryAn out-of-bounds write in the Linux kernel; the affected component and impact details are unknown from the data provided.

8.8KEVNot classified yet
2026-09-18CVE-2025-39964
Not classified yet

AI summaryA race condition in the Linux kernel; the affected component and impact details are unknown from the data provided.

5.5KEVNot classified yet
2026-09-17CVE-2026-87886
Not classified yet

AI summaryAcronis Backup has incorrect default permissions; affected versions and impact details are not given.

7.8KEVNot classified yet
2026-09-17CVE-2026-92940
Vulnerable dependency

AI summaryvm2 3.11.3–3.11.6 exposes the host's real https.globalAgent to sandboxed code when a NodeVM allows require('https').

10.0Candidate