AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,604

AI/ML CVEs Tracked

225

Critical

77

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 167 results — Critical severity, no patch
CRITICAL EXPLOIT AVAIL

OpenClaw: RCE via request-side prompt injection

CVE-2026-30741
9.8
EPSS 0.4%
Prompt Injection Code Execution Agent Framework
openclaw 4 5 ATLAS 1 incident
CRITICAL EXPLOIT AVAIL

vllm: SSRF allows internal network access

CVE-2026-25960
9.8
EPSS 0.0%
Data Extraction Data Leakage Code Execution Inference RAG Agent
vllm CWE-918 127 7 ATLAS
CRITICAL EXPLOIT AVAIL

Flowise: auth bypass exposes NVIDIA NIM container endpoints

CVE-2026-30824
9.8
EPSS 9.4%
Auth Bypass Code Execution Agent Inference Framework
flowise CWE-306 5 ATLAS
CRITICAL EXPLOIT AVAIL

flowise: Arbitrary File Upload enables RCE

CVE-2026-30821
9.8
EPSS 0.2%
Code Execution Framework RAG Plugin
flowise CWE-434 8 ATLAS 2 incidents
CRITICAL

OpenClaw: SSRF via Feishu extension exposes internal services

CVE-2026-28451
9.3
EPSS 0.0%
Prompt Injection Data Extraction Auth Bypass Agent Plugin
openclaw 4 5 ATLAS 1 incident
CRITICAL EXPLOIT AVAIL

langflow: Code Injection enables RCE

CVE-2026-27966
9.8
EPSS 36.6%
Prompt Injection Code Execution Framework RAG Agent
langflow CWE-94 12 ATLAS
CRITICAL

n8n: Code Injection enables RCE

CVE-2026-27577
9.9
EPSS 0.2%
Model Poisoning Code Execution Social Engineering Agent RAG API
n8n CWE-94 16 9 ATLAS
CRITICAL

n8n: Code Injection enables RCE

CVE-2026-27495
9.9
EPSS 0.1%
Code Execution Social Engineering Agent RAG API
n8n CWE-94 16 9 ATLAS
CRITICAL

n8n: security flaw enables exploitation

CVE-2026-27494
9.9
EPSS 0.1%
Code Execution Agent RAG API
n8n CWE-497 16 9 ATLAS
CRITICAL

n8n: Code Injection enables RCE

CVE-2026-27493
9.0
EPSS 0.3%
Code Execution Agent RAG API
n8n CWE-94 16 6 ATLAS
CRITICAL EXPLOIT AVAIL

smolagents: SSRF allows internal network access

CVE-2026-2654
9.8
EPSS 0.0%
Code Execution Data Extraction Auth Bypass Agent Framework Plugin
smolagents CWE-918 88 6 ATLAS
CRITICAL

n8n: Protection Bypass circumvents security controls

CVE-2026-25115
9.9
EPSS 0.1%
Code Execution Auth Bypass Data Extraction Agent Framework Plugin
n8n CWE-693 16 7 ATLAS
CRITICAL

n8n: Command Injection enables RCE

CVE-2026-25053
9.9
EPSS 0.0%
Code Execution Data Extraction Auth Bypass Agent Framework Plugin
n8n CWE-78 16 9 ATLAS
CRITICAL

n8n: security flaw enables exploitation

CVE-2026-25052
9.9
EPSS 0.0%
Auth Bypass Data Extraction Data Leakage Agent Framework API
n8n CWE-367 16 9 ATLAS
CRITICAL

n8n: security flaw enables exploitation

CVE-2026-25049
9.9
EPSS 0.0%
Code Execution Data Extraction Auth Bypass Agent Framework API
n8n CWE-913 16 8 ATLAS
CRITICAL

vllm: security flaw enables exploitation

CVE-2026-22778
9.8
EPSS 0.1%
Code Execution Data Leakage Inference Framework API
vllm CWE-532 127 6 ATLAS
CRITICAL EXPLOIT AVAIL

langroid: Code Injection enables RCE

CVE-2026-25481
--
EPSS 0.0%
Code Execution Prompt Injection Auth Bypass Agent Framework Plugin
CWE-94 6 ATLAS
CRITICAL EXPLOIT AVAIL

cai-framework: Command Injection enables RCE

CVE-2026-25130
9.7
EPSS 0.0%
Prompt Injection Code Execution Agent Framework Plugin
CWE-78 9 ATLAS
CRITICAL EXPLOIT AVAIL

n8n: Code Injection enables RCE

CVE-2026-1470
9.9
EPSS 1.9%
Code Execution Auth Bypass Data Extraction Agent Framework Plugin
n8n CWE-95 16 9 ATLAS
CRITICAL EXPLOIT AVAIL

Kalrav: Arbitrary File Upload enables RCE

CVE-2025-13374
9.8
EPSS 0.1%
Code Execution Auth Bypass Data Extraction Plugin Agent API
CWE-434 8 ATLAS

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial