AI Security Threat Feed

Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.

1,624

AI/ML CVEs Tracked

226

Critical

94

New This Week

16

In CISA KEV

Latest AI Security Threats

Showing 20 of 1624 results
Severity CVE ID Summary CVSS EPSS Package Date
HIGH GHSA-5r2p-pjr8-7fh7 sagemaker: Allowlist Bypass evades input filtering sagemaker Mar 5 MEDI CVE-2026-28277 langgraph: Deserialization enables RCE 6.8 0.3% langgraph Mar 5 HIGH CVE-2026-25048 xgrammar: security flaw enables exploitation 0.1% xgrammar Mar 5 HIGH CVE-2026-25750 langsmith: security flaw enables exploitation 8.1 0.0% langsmith Mar 4 HIGH GHSA-5hwf-rc88-82xm fickling: Allowlist Bypass evades input filtering fickling Mar 4 HIGH GHSA-wccx-j62j-r448 fickling: Protection Bypass circumvents security controls fickling Mar 4 HIGH CVE-2026-0847 NLTK: path traversal exposes sensitive server files 8.6 0.1% Mar 4 HIGH E CVE-2026-27905 bentoml: security flaw enables exploitation 7.8 0.0% bentoml Mar 3 CRIT GHSA-g38g-8gr9-h9xp picklescan: Allowlist Bypass evades input filtering 9.8 picklescan Mar 3 CRIT GHSA-vvpj-8cmc-gx39 picklescan: security flaw enables exploitation 10.0 picklescan Mar 3 CRIT GHSA-7wx9-6375-f5wh picklescan: Allowlist Bypass evades input filtering 9.8 picklescan Mar 3 HIGH E CVE-2026-28416 gradio: SSRF allows internal network access 8.6 0.0% gradio Feb 27 MEDI CVE-2026-28415 gradio: Info Disclosure leaks sensitive data 4.7 0.0% gradio Feb 27 HIGH E CVE-2026-28414 gradio: security flaw enables exploitation 7.5 3.2% gradio Feb 27 MEDI E CVE-2026-27167 gradio: Weak Credentials allow account compromise 5.9 0.0% gradio Feb 27 CRIT E CVE-2026-27966 langflow: Code Injection enables RCE 9.8 36.6% langflow Feb 26 MEDI CVE-2026-27578 n8n: XSS enables session hijacking 5.4 0.0% n8n Feb 25 CRIT CVE-2026-27577 n8n: Code Injection enables RCE 9.9 0.2% n8n Feb 25 HIGH CVE-2026-27498 n8n: Code Injection enables RCE 8.8 0.6% n8n Feb 25 HIGH CVE-2026-27497 n8n: SQL Injection exposes database 8.8 0.1% n8n Feb 25

Need deeper analysis?

Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.

Start 14-Day Free Trial