AI Security Threat Feed
Latest CVEs affecting AI/ML systems, updated continuously. Tracked from NVD, GitHub Advisory, and CISA KEV.
AI/ML CVEs Tracked
Critical
New This Week
In CISA KEV
Latest AI Security Threats
Showing 20 of 167 results — Critical severity, no patchcline: WebSocket auth bypass enables terminal RCE
CVE-2026-44211 LiteLLM: SQL injection exposes LLM API credentials
CVE-2026-42208 pytorch-lightning: supply chain, credential harvesting
CVE-2026-44484 Ollama: heap OOB read leaks API keys and chat data
CVE-2026-7482 Gemini CLI: RCE via malicious workspace in CI/CD
GHSA-wpqr-6v78-jr5g Flowise: auth bypass enables full account takeover via reset
CVE-2026-41276 Flowise: unauthenticated RCE via NODE_OPTIONS env injection
CVE-2026-41268 Flowise: mass assignment auth bypass in registration
CVE-2026-41267 Flowise: RCE via prompt injection in Airtable Agent
CVE-2026-41265 OpenAI Codex CLI: RCE via malicious MCP config files
CVE-2025-61260 Claude Code: OS command injection, credential theft
CVE-2026-35022 Budibase: Unauthenticated RCE as root via webhook
CVE-2026-35216 MLflow: auth bypass in job API enables unauthenticated RCE
CVE-2026-0545 MLflow: command injection via model_uri in mlserver mode
CVE-2026-0596 telnyx: PyPI supply chain attack steals cloud creds
GHSA-955r-262c-33jc litellm: supply chain attack harvests AI API credentials
GHSA-5mg7-485q-xm76 NVIDIA: Deserialization enables RCE
CVE-2025-33244 langflow: security flaw enables exploitation
CVE-2026-33475 langflow: Code Injection enables RCE
CVE-2026-33017 onnx: Integrity Verification bypass enables tampering
CVE-2026-28500 Need deeper analysis?
Get ATLAS technique mappings, compliance reports (ISO 42001, EU AI Act), breaking alerts, and full CISO analysis with a Pro subscription.
Start 14-Day Free Trial
AI Threat Alert