AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 570 results — Medium severityn8n: LDAP injection enables auth bypass in workflows
CVE-2026-33751 n8n: secrets vault bypass exposes credentials to low-priv users
CVE-2026-33722 n8n: OAuth state forgery hijacks user credentials
CVE-2026-33720 n8n: uninitialized buffer leaks secrets via Task Runner
CVE-2026-27496 AI component: IDOR enables unauthorized data access
CVE-2026-30886 AI component: Input Validation flaw enables exploitation
CVE-2026-4538 fickling: Allowlist Bypass evades input filtering
GHSA-5cxw-w2xg-2m8h fickling: Allowlist Bypass evades input filtering
GHSA-r48f-3986-4f9c Greenshift: Info Disclosure leaks sensitive data
CVE-2026-2589 langgraph: Deserialization enables RCE
CVE-2026-28277 gradio: Info Disclosure leaks sensitive data
CVE-2026-28415 gradio: Weak Credentials allow account compromise
CVE-2026-27167 n8n: XSS enables session hijacking
CVE-2026-27578 langgraph-checkpoint: Deserialization enables RCE
CVE-2026-27794 LangChain: SSRF allows internal network access
CVE-2026-27795 fickling: Allowlist Bypass evades input filtering
GHSA-mhc9-48gj-9gp3 ray: Missing Auth allows unauthenticated access
CVE-2026-27482 OpenClaw: path traversal allows arbitrary file write
CVE-2026-26972 OpenClaw: UI deception enables arbitrary command execution
CVE-2026-26320 ffmpeg: security flaw enables exploitation
CVE-2025-12343 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert