This week
Vulnerabilities from the past 7 days in AI security or the software supply chain, or exploited / highest severity. Items we have written up link to our page.
This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.
Updated 2026-09-24 13:45 UTC · 56 items · 9 in KEV · 1 written up · RSS
| Date | ID | Category and summary | CVSS | Our status |
|---|---|---|---|---|
| 2026-09-24 | CVE-2026-93577 | Other high risk AI summaryUnder certain conditions, an integer overflow in GitLab CE/EE 19.2–19.4 before patches may let authenticated users run code on the server. | 9.9 | Candidate |
| 2026-09-24 | CVE-2026-92874 | AI trust boundary AI summaryGitLab CE/EE 18.3+ before fixes may let authenticated users with MCP-scoped tokens act beyond the token's intended scope. | 5.4 | Candidate |
| 2026-09-24 | CVE-2026-92628 | AI trust boundary AI summaryA race condition in GitLab CE/EE's MCP search tool (18.6 through pre-19.4.1) could return search results under the wrong user context. | 3.1 | Candidate |
| 2026-09-24 | CVE-2026-89078 | Other high risk AI summaryUnder certain conditions, a double free in GitLab CE/EE 19.2–19.4 before patches may let authenticated users run code on the server. | 9.9 | Candidate |
| 2026-09-23 | CVE-2026-93352 | Vulnerable dependency AI summaryLaravel-Mediable 7.0.0–7.0.1 misses .pht in its upload blocklist (incomplete CVE-2026-49972 fix), so Apache may run such files as PHP. | 9.3 | Candidate |
| 2026-09-23 | CVE-2026-96804 | AI trust boundary AI summaryMLflow's statsmodel flavor (2.1.0–3.14.0) ignores the pickle-blocking setting, so a crafted MLmodel artifact can run arbitrary code. | 8.8 | Candidate |
| 2026-09-23 | CVE-2026-96775 | AI trust boundary AI summaryMLflow's dspy flavor (2.0+) enforces its pickle-blocking setting only for .pkl paths, so a crafted MLmodel artifact can run code. | 8.8 | Candidate |
| 2026-09-23 | CVE-2026-96759 | Vulnerable dependency AI summaryorval before 8.29.0 doesn't escape operationId, so crafted OpenAPI specs can inject JavaScript into generated query hooks. | 9.3 | Candidate |
| 2026-09-23 | CVE-2026-96758 | Vulnerable dependency AI summary@orval/core before 8.28.0's form-data serializer doesn't escape property names, so crafted OpenAPI specs can inject code. | 9.3 | Candidate |
| 2026-09-23 | CVE-2026-96757 | Vulnerable dependency AI summaryorval before 8.29.0 doesn't escape OpenAPI media-type keys, letting crafted specs inject JavaScript into generated fetch or mock code. | 9.3 | Candidate |
| 2026-09-23 | CVE-2026-96756 | Vulnerable dependency AI summaryorval before 8.30.0's @orval/core doesn't escape date defaults, so crafted OpenAPI specs can inject code into generated output. | 9.2 | Candidate |
| 2026-09-23 | CVE-2026-96755 | Vulnerable dependency AI summaryorval 8.14.0–8.28.1's @orval/effect generator lets crafted OpenAPI schema defaults inject JavaScript that runs in generated code. | 9.3 | Candidate |
| 2026-09-23 | CVE-2026-96754 | Vulnerable dependency AI summaryorval before 8.29.0's @orval/hono generator doesn't escape OpenAPI paths, so a crafted spec can inject code into generated output. | 9.3 | Candidate |
| 2026-09-23 | CVE-2026-18875 | AI trust boundary AI summaryIBM FTM for Red Hat OpenShift's AI agent server lets unauthenticated users insert runbook content into its vector DB to steer the agent. | 7.3 | Candidate |
| 2026-09-23 | CVE-2026-96276 | Vulnerable dependency AI summaryIf a developer runs flatpak build-init with a malicious SDK's extension, files may be written outside the working directory. | 9.8 | Candidate |
| 2026-09-23 | CVE-2026-96560 | AI product bug AI summaryLightLLM through 1.2.0, when run with --pd_trans_mode nccl, exposes an unauthenticated RPyC channel allowing remote code execution. | 9.3 | Candidate |
| 2026-09-23 | CVE-2026-59167 | Vulnerable dependency AI summarySunEditor before 2.47.11 fails to strip event-handler attributes from crafted custom/namespaced elements, risking XSS in apps using it. | 10.0 | Candidate |
| 2026-09-23 | CVE-2026-54892 | Vulnerable dependency AI summaryPlug decodes nested query/body parameters in quadratic time, letting crafted requests cause denial of service in apps using Plug. | 8.7 | Candidate |
| 2026-09-23 | CVE-2026-86246 | Vulnerable dependency AI summaryApache Tomcat Native from 2.0.0 enables insecure TLS options by default, such as client renegotiation, weakening connection security. | 9.1 | Candidate |
| 2026-09-23 | CVE-2026-87022 | Vulnerable dependency AI summaryApache Tomcat 9.0, 10.1 and 11.0 (up to 9.0.121/10.1.59/11.0.25) allow WebSocket message smuggling when per-message-deflate is used. | 7.5 | Candidate |
| 2026-09-23 | CVE-2026-86350 | Vulnerable dependency AI summaryA regression in Apache Tomcat 11.0.22+ and 10.1.55+ HTTP/2 handling can mix up request headers (request smuggling). | 9.1 | Candidate |
| 2026-09-23 | CVE-2026-86248 | Vulnerable dependency AI summaryIn some Apache Tomcat 9.0, 10.1 and 11.0 versions, CLIENT_CERT authentication may not fail as expected when soft fail is disabled. | 9.8 | Candidate |
| 2026-09-23 | CVE-2026-76183 | Vulnerable dependency AI summaryApache Tomcat 9.0.0.M1–9.0.121, 10.1.0-M1–10.1.59 and 11.0.0-M1–11.0.25 let WebSocket endpoint security constraints be bypassed. | 9.8 | Candidate |
| 2026-09-22 | CVE-2026-19202 | AI trust boundary AI summarymcp-toolbox-sdk-python's toolbox-core reuses one cached Google ID token across audiences; affects apps using 2+ audiences in one process. | 9.1 | Candidate |
| 2026-09-22 | CVE-2026-88624 | AI product bug AI summaryopenCode v1.18.26's Worktree.remove lacks path validation, letting attackers trigger arbitrary recursive directory deletion. | 9.1 | Candidate |
| 2026-09-22 | CVE-2026-87121 | Vulnerable dependency AI summaryAn out-of-bounds write in the lwIP TCP/IP stack's MQTT component may let an attacker fully execute code on affected devices. | 9.3 | Candidate |
| 2026-09-22 | CVE-2026-28324 | Other high risk AI summarySolarWinds Observability Self-Hosted allows unauthenticated remote code execution, but only in non-default, non-secure configurations. | 9.8 | Candidate |
| 2026-09-22 | CVE-2026-77244 | AI trust boundary mcp-atlassian: 20 CVEs fixed in the same releaseShow all IDs
| 10.0 | Write-up in review |
| 2026-09-22 | CVE-2026-95660 | AI trust boundary AI summaryMoonshot AI Kimi Code up to 0.31.0 has an OS command injection flaw in its MCP configuration loader, reportedly remotely triggerable. | 2.1 | Candidate |
| 2026-09-22 | CVE-2026-85734 | AI product bug AI summarylightrag-hku has no rate limiting on its /login endpoint, allowing password brute-force attempts. | 9.1 | Candidate |
| 2026-09-22 | CVE-2026-63374 | Vulnerable dependency AI summaryAnyIO before 4.14.2 may check internationalized hostnames in connect_tcp()/TLSStream.wrap() using IDNA 2003 instead of IDNA 2008. | 9.3 | Candidate |
| 2026-09-22 | CVE-2026-94127 | Not classified yet AI summaryBIG-IP APM configured as an OAuth Authorization Server with an access policy may allow remote code execution via malicious traffic. | 9.3KEV | Written up → |
| 2026-09-22 | CVE-2026-93088 | AI product bug AI summarySGLang's disaggregated-diffusion DiffusionServer exposes an unauthenticated ZeroMQ socket, enabling unauthenticated code execution. | 9.8 | Write-up in review |
| 2026-09-22 | CVE-2026-79313 | Vulnerable dependency AI summaryweb.py 0.76 doesn't check session age on load, so expired sessions not yet cleaned up may still be accepted. | 9.8 | Candidate |
| 2026-09-22 | CVE-2026-65178 | AI trust boundary AI summaryNVIDIA NeMo's dataset loading can accept unsafe parameters from a crafted model_config.yaml, possibly leading to code execution. | 7.8 | Candidate |
| 2026-09-22 | CVE-2026-93616 | Other high risk AI summaryA directory traversal and file upload flaw lets unauthenticated attackers upload and run scripts on Check Point Management Server. | 9.8KEV | Candidate |
| 2026-09-22 | CVE-2026-89422 | Vulnerable dependency AI summaryErlang/OTP ssl TLS 1.3 clients may finish a handshake without validating the server, letting a responding peer impersonate it. | 9.3 | Candidate |
| 2026-09-22 | CVE-2026-93952 | Other high risk AI summaryOn-prem VeloCloud Orchestrator may let a remote attacker access privileged internal functions and compromise the orchestrator host. | 9.5KEV | Candidate |
| 2026-09-22 | CVE-2026-85102 | Other high risk AI summaryA VPN certificate validation flaw in Check Point Quantum Security Gateway may let unauthenticated remote attackers run code on it. | 9.8KEV | Candidate |
| 2026-09-21 | CVE-2026-78847 | Vulnerable dependency AI summarygray-matter (all versions, verified 4.0.3) uses eval() to parse JavaScript front matter, allowing arbitrary code execution. | 9.8 | Candidate |
| 2026-09-21 | CVE-2026-79916 | AI product bug AI summaryMaxKB before 2.10.5-lts lets authenticated workspace members inject control characters into the server's AWS credentials file. | 9.1 | Candidate |
| 2026-09-21 | CVE-2026-77521 | AI trust boundary AI summaryMaxKB before 2.10.5-lts exposes a shell execute tool without human approval to assistants that have tools, MCP tools, skills or sub-apps. | 10.0 | Candidate |
| 2026-09-21 | CVE-2026-77519 | AI trust boundary AI summaryMaxKB 2.10.2-lts and earlier don't check API key expiry on /chat/api/mcp, so expired non-permanent keys may still authenticate. | 5.4 | Candidate |
| 2026-09-21 | CVE-2026-77516 | AI trust boundary AI summaryMaxKB 2.0.0–2.9.2 lets lowest-role workspace members run tools they were denied by binding tool IDs in agents or workflows. | 5.4 | Candidate |
| 2026-09-21 | CVE-2026-61647 | AI trust boundary AI summary@roomi-fields/notebooklm-mcp's vault.batch tool has a path traversal allowing files to be written outside the intended vault directory. | 7.1 | Candidate |
| 2026-09-21 | CVE-2026-93012 | Vulnerable dependency AI summaryOn Windows, Perl's Email::Sender::Transport::Sendmail before 2.602 may run arbitrary commands via envelope addresses reaching a shell. | 9.8 | Candidate |
| 2026-09-21 | CVE-2026-94301 | Vulnerable dependency AI summaryMINA's fix for CVE-2026-47065 (acceptMatchers filter bypass) was only committed to 2.2.X, so 2.0.X/2.1.X releases may lack it. | 9.8 | Candidate |
| 2026-09-21 | CVE-2026-55071 | AI trust boundary AI summaryMCP-for-Stata before 1.19.0 puts unvalidated input from its ado_package_install tool into Stata commands, enabling command injection. | 8.4 | Candidate |
| 2026-09-21 | CVE-2026-7273 | Not classified yet AI summaryZyxel GS1900-48HPv2 firmware ≤2.90(ABTQ.1)C0 has a CGI stack overflow that may let unauthenticated LAN attackers run OS commands. | 8.8KEV | Not classified yet |
| 2026-09-18 | CVE-2026-33625 | AI trust boundary AI summaryLMDeploy 0.12.1–0.12.2 can run arbitrary Python code when loading a malicious HuggingFace model, due to code injection in config.py. | 8.8 | Candidate |
| 2026-09-18 | CVE-2025-66455 | AI product bug AI summaryLMDeploy deserializes pickle data in handle_zmq_recv (disaggregation engine connection), allowing remote code execution. | 9.8 | Candidate |
| 2026-09-18 | CVE-2025-39682 | Not classified yet AI summaryLinux kernel TLS (kTLS) receive code mishandles zero-length records on the rx_list; affects systems using kernel TLS. | 9.8KEV | Not classified yet |
| 2026-09-18 | CVE-2026-53266 | Not classified yet AI summaryAn out-of-bounds write in the Linux kernel; the affected component and impact details are unknown from the data provided. | 8.8KEV | Not classified yet |
| 2026-09-18 | CVE-2025-39964 | Not classified yet AI summaryA race condition in the Linux kernel; the affected component and impact details are unknown from the data provided. | 5.5KEV | Not classified yet |
| 2026-09-17 | CVE-2026-87886 | Not classified yet AI summaryAcronis Backup has incorrect default permissions; affected versions and impact details are not given. | 7.8KEV | Not classified yet |
| 2026-09-17 | CVE-2026-92940 | Vulnerable dependency AI summaryvm2 3.11.3–3.11.6 exposes the host's real https.globalAgent to sandboxed code when a NodeVM allows require('https'). | 10.0 | Candidate |