AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,604

AI/ML CVEs Tracked

225

Critical

79

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 29 results — Critical severity, Active exploitation, has patch
CRITICAL EXPLOIT AVAIL

Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability

CVE-2026-41264
9.8
EPSS 0.3%
flowise-components Patch: 3.1.0 CWE-184
CRITICAL EXPLOIT AVAIL

Flowise: RCE via MCP stdio command injection

CVE-2026-40933
9.9
EPSS 0.0%
Code Execution Supply Chain Auth Bypass Agent Plugin Framework
flowise-components Patch: 3.1.0 CWE-78 7 ATLAS
CRITICAL EXPLOIT AVAIL

PraisonAI: path traversal allows arbitrary file write via recipe unpack

CVE-2026-40157
--
EPSS 0.1%
Supply Chain Code Execution Agent Framework
PraisonAI Patch: 4.5.128 CWE-22 1 3 ATLAS
CRITICAL EXPLOIT AVAIL

PraisonAI: supply chain RCE via unverified template exec

CVE-2026-40154
9.3
EPSS 0.0%
Supply Chain Code Execution Agent Plugin Framework
PraisonAI Patch: 4.5.128 CWE-829 1 7 ATLAS
CRITICAL EXPLOIT AVAIL

lollms: Stored XSS enables wormable account takeover

CVE-2026-1115
9.6
EPSS 0.0%
Code Execution Auth Bypass Data Extraction Framework API
lollms Patch: 2.2.0 CWE-79 5 ATLAS
CRITICAL EXPLOIT AVAIL

PraisonAI: RCE via shell injection in memory hooks executor

CVE-2026-40111
--
EPSS 0.0%
Code Execution Prompt Injection Agent Framework
praisonaiagents Patch: 1.5.128 CWE-78 11 5 ATLAS
CRITICAL EXPLOIT AVAIL

PraisonAI: YAML deserialization enables unauthenticated RCE

CVE-2026-39890
9.8
EPSS 0.5%
Code Execution Supply Chain Agent Framework
praisonai Patch: 4.5.115 CWE-502 1 5 ATLAS
CRITICAL EXPLOIT AVAIL

PraisonAI: path traversal exposes full filesystem via agent tools

CVE-2026-35615
--
EPSS 0.1%
Data Extraction Code Execution Agent Framework
PraisonAI Patch: 1.5.113 CWE-22 1 5 ATLAS
CRITICAL EXPLOIT AVAIL

PraisonAI: path traversal enables arbitrary file write/RCE

CVE-2026-39305
9.0
EPSS 0.1%
Code Execution Prompt Injection Supply Chain Agent Framework
PraisonAI Patch: 4.5.113 1 5 ATLAS
CRITICAL EXPLOIT AVAIL

praisonaiagents: sandbox bypass enables full host RCE

CVE-2026-34938
10.0
EPSS 0.0%
Code Execution Prompt Injection Supply Chain Agent Framework Plugin
praisonaiagents Patch: 1.5.90 CWE-693 11 7 ATLAS
CRITICAL EXPLOIT AVAIL

MLflow: RCE via unsanitized model dependency specs

CVE-2025-15379
10.0
EPSS 0.2%
Code Execution Supply Chain Framework
mlflow Patch: 3.8.1 CWE-77 624 4 ATLAS 1 incident
CRITICAL EXPLOIT AVAIL

MLflow: path traversal enables sandbox escape, file overwrite

CVE-2025-15036
9.6
EPSS 0.0%
Supply Chain Code Execution Framework
mlflow Patch: 3.9.0rc0 CWE-29 624 5 ATLAS
CRITICAL EXPLOIT AVAIL

langflow: Path Traversal enables file access

CVE-2026-33309
9.9
EPSS 0.0%
Code Execution Auth Bypass Supply Chain Framework Agent Plugin
langflow Patch: 1.9.0 CWE-22 8 ATLAS
CRITICAL EXPLOIT AVAIL

mlflow: Path Traversal enables file access

CVE-2025-15031
9.1
EPSS 0.4%
Supply Chain Model Poisoning Code Execution Framework Model Training Data
mlflow Patch: 3.9.0rc0 CWE-22 624 6 ATLAS
CRITICAL EXPLOIT AVAIL

mcp-atlassian: Path Traversal enables file access

CVE-2026-27825
9.1
EPSS 0.0%
Code Execution Prompt Injection Supply Chain Agent Plugin Framework
mcp-atlassian Patch: 0.17.0 CWE-22 6 ATLAS
CRITICAL KEV

ray: Code Injection enables RCE

CVE-2025-62593
--
EPSS 0.0%
Code Execution Auth Bypass Social Engineering Framework
ray Patch: 2.52.0 CWE-94 845 8 ATLAS
CRITICAL EXPLOIT AVAIL

keras: Path Traversal enables file access

CVE-2025-12060
9.8
EPSS 0.1%
Supply Chain Code Execution Framework Training Data
keras Patch: 3.12.0 CWE-22 1.5K 4 ATLAS
CRITICAL EXPLOIT AVAIL

keras: Deserialization enables RCE

CVE-2025-49655
9.8
EPSS 0.1%
Code Execution Supply Chain Framework Model
keras Patch: 3.11.3 CWE-502 1.5K 5 ATLAS
CRITICAL EXPLOIT AVAIL

ExecuTorch: OOB read in model loader enables RCE

CVE-2025-54950
9.8
EPSS 0.3%
Code Execution Supply Chain Framework Model Inference
executorch Patch: 0.7.0 CWE-125 2 4 ATLAS
CRITICAL EXPLOIT AVAIL

llama_index: SQL injection in vector store integrations

CVE-2025-1793
9.8
EPSS 0.1%
Data Extraction Data Leakage Supply Chain Framework RAG
llama-index Patch: 0.12.28 CWE-89 229 5 ATLAS

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial