<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>PlainCVE · This week</title><description>Vulnerabilities from the past 7 days in AI security or the software supply chain, or exploited / highest severity. Items we have written up link to our page. This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><link>https://plaincve.date/</link><language>en</language><item><title>CVE-2026-93577 Under certain conditions, an integer overflow in GitLab CE/EE 19.2–19.4 before patches may let authenticated users run code on the server.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-93577</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-93577</guid><description>CVSS 9.9 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-92874 GitLab CE/EE 18.3+ before fixes may let authenticated users with MCP-scoped tokens act beyond the token&apos;s intended scope.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-92874</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-92874</guid><description>AI trust boundary · CVSS 5.4 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-92628 A race condition in GitLab CE/EE&apos;s MCP search tool (18.6 through pre-19.4.1) could return search results under the wrong user context.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-92628</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-92628</guid><description>AI trust boundary · CVSS 3.1 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-89078 Under certain conditions, a double free in GitLab CE/EE 19.2–19.4 before patches may let authenticated users run code on the server.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-89078</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-89078</guid><description>CVSS 9.9 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-93352 Laravel-Mediable 7.0.0–7.0.1 misses .pht in its upload blocklist (incomplete CVE-2026-49972 fix), so Apache may run such files as PHP.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-93352</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-93352</guid><description>Vulnerable dependency · CVSS 9.3 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-96804 MLflow&apos;s statsmodel flavor (2.1.0–3.14.0) ignores the pickle-blocking setting, so a crafted MLmodel artifact can run arbitrary code.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-96804</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-96804</guid><description>AI trust boundary · CVSS 8.8 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-96775 MLflow&apos;s dspy flavor (2.0+) enforces its pickle-blocking setting only for .pkl paths, so a crafted MLmodel artifact can run code.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-96775</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-96775</guid><description>AI trust boundary · CVSS 8.8 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-96759 orval before 8.29.0 doesn&apos;t escape operationId, so crafted OpenAPI specs can inject JavaScript into generated query hooks.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-96759</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-96759</guid><description>Vulnerable dependency · CVSS 9.3 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-96758 @orval/core before 8.28.0&apos;s form-data serializer doesn&apos;t escape property names, so crafted OpenAPI specs can inject code.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-96758</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-96758</guid><description>Vulnerable dependency · CVSS 9.3 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-96757 orval before 8.29.0 doesn&apos;t escape OpenAPI media-type keys, letting crafted specs inject JavaScript into generated fetch or mock code.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-96757</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-96757</guid><description>Vulnerable dependency · CVSS 9.3 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-96756 orval before 8.30.0&apos;s @orval/core doesn&apos;t escape date defaults, so crafted OpenAPI specs can inject code into generated output.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-96756</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-96756</guid><description>Vulnerable dependency · CVSS 9.2 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-96755 orval 8.14.0–8.28.1&apos;s @orval/effect generator lets crafted OpenAPI schema defaults inject JavaScript that runs in generated code.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-96755</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-96755</guid><description>Vulnerable dependency · CVSS 9.3 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-96754 orval before 8.29.0&apos;s @orval/hono generator doesn&apos;t escape OpenAPI paths, so a crafted spec can inject code into generated output.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-96754</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-96754</guid><description>Vulnerable dependency · CVSS 9.3 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-18875 IBM FTM for Red Hat OpenShift&apos;s AI agent server lets unauthenticated users insert runbook content into its vector DB to steer the agent.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-18875</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-18875</guid><description>AI trust boundary · CVSS 7.3 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-96276 If a developer runs flatpak build-init with a malicious SDK&apos;s extension, files may be written outside the working directory.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-96276</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-96276</guid><description>Vulnerable dependency · CVSS 9.8 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-96560 LightLLM through 1.2.0, when run with --pd_trans_mode nccl, exposes an unauthenticated RPyC channel allowing remote code execution.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-96560</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-96560</guid><description>AI product bug · CVSS 9.3 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-59167 SunEditor before 2.47.11 fails to strip event-handler attributes from crafted custom/namespaced elements, risking XSS in apps using it.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-59167</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-59167</guid><description>Vulnerable dependency · CVSS 10.0 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-54892 Plug decodes nested query/body parameters in quadratic time, letting crafted requests cause denial of service in apps using Plug.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-54892</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-54892</guid><description>Vulnerable dependency · CVSS 8.7 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-86246 Apache Tomcat Native from 2.0.0 enables insecure TLS options by default, such as client renegotiation, weakening connection security.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-86246</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-86246</guid><description>Vulnerable dependency · CVSS 9.1 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-87022 Apache Tomcat 9.0, 10.1 and 11.0 (up to 9.0.121/10.1.59/11.0.25) allow WebSocket message smuggling when per-message-deflate is used.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-87022</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-87022</guid><description>Vulnerable dependency · CVSS 7.5 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-86350 A regression in Apache Tomcat 11.0.22+ and 10.1.55+ HTTP/2 handling can mix up request headers (request smuggling).</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-86350</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-86350</guid><description>Vulnerable dependency · CVSS 9.1 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-86248 In some Apache Tomcat 9.0, 10.1 and 11.0 versions, CLIENT_CERT authentication may not fail as expected when soft fail is disabled.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-86248</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-86248</guid><description>Vulnerable dependency · CVSS 9.8 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-76183 Apache Tomcat 9.0.0.M1–9.0.121, 10.1.0-M1–10.1.59 and 11.0.0-M1–11.0.25 let WebSocket endpoint security constraints be bypassed.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-76183</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-76183</guid><description>Vulnerable dependency · CVSS 9.8 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-19202 mcp-toolbox-sdk-python&apos;s toolbox-core reuses one cached Google ID token across audiences; affects apps using 2+ audiences in one process.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-19202</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-19202</guid><description>AI trust boundary · CVSS 9.1 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-88624 openCode v1.18.26&apos;s Worktree.remove lacks path validation, letting attackers trigger arbitrary recursive directory deletion.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-88624</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-88624</guid><description>AI product bug · CVSS 9.1 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-87121 An out-of-bounds write in the lwIP TCP/IP stack&apos;s MQTT component may let an attacker fully execute code on affected devices.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-87121</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-87121</guid><description>Vulnerable dependency · CVSS 9.3 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-28324 SolarWinds Observability Self-Hosted allows unauthenticated remote code execution, but only in non-default, non-secure configurations.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-28324</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28324</guid><description>CVSS 9.8 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-77244 +19 mcp-atlassian: 20 CVEs fixed in the same release</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-77244</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-77244</guid><description>AI trust boundary · CVSS 10.0 · Write-up in review · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-95660 Moonshot AI Kimi Code up to 0.31.0 has an OS command injection flaw in its MCP configuration loader, reportedly remotely triggerable.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-95660</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-95660</guid><description>AI trust boundary · CVSS 2.1 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-85734 lightrag-hku has no rate limiting on its /login endpoint, allowing password brute-force attempts.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-85734</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-85734</guid><description>AI product bug · CVSS 9.1 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-63374 AnyIO before 4.14.2 may check internationalized hostnames in connect_tcp()/TLSStream.wrap() using IDNA 2003 instead of IDNA 2008.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-63374</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-63374</guid><description>Vulnerable dependency · CVSS 9.3 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-94127 [KEV] BIG-IP APM configured as an OAuth Authorization Server with an access policy may allow remote code execution via malicious traffic.</title><link>https://plaincve.date/en/vulns/cve-2026-94127-f5-big-ip-apm-oauth-heap-overflow/</link><guid isPermaLink="true">https://plaincve.date/en/vulns/cve-2026-94127-f5-big-ip-apm-oauth-heap-overflow/</guid><description>CVSS 9.3 · Written up · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-93088 SGLang&apos;s disaggregated-diffusion DiffusionServer exposes an unauthenticated ZeroMQ socket, enabling unauthenticated code execution.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-93088</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-93088</guid><description>AI product bug · CVSS 9.8 · Write-up in review · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-79313 web.py 0.76 doesn&apos;t check session age on load, so expired sessions not yet cleaned up may still be accepted.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-79313</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-79313</guid><description>Vulnerable dependency · CVSS 9.8 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-65178 NVIDIA NeMo&apos;s dataset loading can accept unsafe parameters from a crafted model_config.yaml, possibly leading to code execution.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-65178</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-65178</guid><description>AI trust boundary · CVSS 7.8 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-93616 [KEV] A directory traversal and file upload flaw lets unauthenticated attackers upload and run scripts on Check Point Management Server.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-93616</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-93616</guid><description>CVSS 9.8 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-89422 Erlang/OTP ssl TLS 1.3 clients may finish a handshake without validating the server, letting a responding peer impersonate it.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-89422</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-89422</guid><description>Vulnerable dependency · CVSS 9.3 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-93952 [KEV] On-prem VeloCloud Orchestrator may let a remote attacker access privileged internal functions and compromise the orchestrator host.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-93952</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-93952</guid><description>CVSS 9.5 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-85102 [KEV] A VPN certificate validation flaw in Check Point Quantum Security Gateway may let unauthenticated remote attackers run code on it.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-85102</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-85102</guid><description>CVSS 9.8 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-78847 gray-matter (all versions, verified 4.0.3) uses eval() to parse JavaScript front matter, allowing arbitrary code execution.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-78847</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-78847</guid><description>Vulnerable dependency · CVSS 9.8 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-79916 MaxKB before 2.10.5-lts lets authenticated workspace members inject control characters into the server&apos;s AWS credentials file.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-79916</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-79916</guid><description>AI product bug · CVSS 9.1 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-77521 MaxKB before 2.10.5-lts exposes a shell execute tool without human approval to assistants that have tools, MCP tools, skills or sub-apps.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-77521</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-77521</guid><description>AI trust boundary · CVSS 10.0 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-77519 MaxKB 2.10.2-lts and earlier don&apos;t check API key expiry on /chat/api/mcp, so expired non-permanent keys may still authenticate.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-77519</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-77519</guid><description>AI trust boundary · CVSS 5.4 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-77516 MaxKB 2.0.0–2.9.2 lets lowest-role workspace members run tools they were denied by binding tool IDs in agents or workflows.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-77516</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-77516</guid><description>AI trust boundary · CVSS 5.4 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-61647 @roomi-fields/notebooklm-mcp&apos;s vault.batch tool has a path traversal allowing files to be written outside the intended vault directory.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-61647</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-61647</guid><description>AI trust boundary · CVSS 7.1 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-93012 On Windows, Perl&apos;s Email::Sender::Transport::Sendmail before 2.602 may run arbitrary commands via envelope addresses reaching a shell.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-93012</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-93012</guid><description>Vulnerable dependency · CVSS 9.8 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-94301 MINA&apos;s fix for CVE-2026-47065 (acceptMatchers filter bypass) was only committed to 2.2.X, so 2.0.X/2.1.X releases may lack it.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-94301</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-94301</guid><description>Vulnerable dependency · CVSS 9.8 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-55071 MCP-for-Stata before 1.19.0 puts unvalidated input from its ado_package_install tool into Stata commands, enabling command injection.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-55071</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-55071</guid><description>AI trust boundary · CVSS 8.4 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-7273 [KEV] Zyxel GS1900-48HPv2 firmware ≤2.90(ABTQ.1)C0 has a CGI stack overflow that may let unauthenticated LAN attackers run OS commands.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-7273</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7273</guid><description>CVSS 8.8 · Not classified yet · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-33625 LMDeploy 0.12.1–0.12.2 can run arbitrary Python code when loading a malicious HuggingFace model, due to code injection in config.py.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-33625</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33625</guid><description>AI trust boundary · CVSS 8.8 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2025-66455 LMDeploy deserializes pickle data in handle_zmq_recv (disaggregation engine connection), allowing remote code execution.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2025-66455</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66455</guid><description>AI product bug · CVSS 9.8 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2025-39682 [KEV] Linux kernel TLS (kTLS) receive code mishandles zero-length records on the rx_list; affects systems using kernel TLS.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2025-39682</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-39682</guid><description>CVSS 9.8 · Not classified yet · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-53266 [KEV] An out-of-bounds write in the Linux kernel; the affected component and impact details are unknown from the data provided.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-53266</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-53266</guid><description>CVSS 8.8 · Not classified yet · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2025-39964 [KEV] A race condition in the Linux kernel; the affected component and impact details are unknown from the data provided.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2025-39964</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-39964</guid><description>CVSS 5.5 · Not classified yet · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-87886 [KEV] Acronis Backup has incorrect default permissions; affected versions and impact details are not given.</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-87886</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-87886</guid><description>CVSS 7.8 · Not classified yet · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-92940 vm2 3.11.3–3.11.6 exposes the host&apos;s real https.globalAgent to sandboxed code when a NodeVM allows require(&apos;https&apos;).</title><link>https://nvd.nist.gov/vuln/detail/CVE-2026-92940</link><guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-92940</guid><description>Vulnerable dependency · CVSS 10.0 · Candidate · This list is collected daily and classified by AI in our research pipeline; it is not human-reviewed. Rely on the original advisories for facts.</description><pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate></item></channel></rss>