MITRE ATLAS Attack Landscape

3,325 AI-related CVEs analyzed → 10,055 mappings across 101 ATLAS techniques (each CVE may match multiple techniques).

3,325
AI CVEs
101
Techniques
10,055
Total Mappings
Exploit Public-Facing Application
#1 (2134 CVEs)
CISO Analysis Data updated 2026-09-14

Executive Summary

The AI attack landscape is dominated by a small set of high-volume techniques. Across 3,821 AI-related CVEs mapped to 170 MITRE ATLAS techniques, Exploit Public-Facing Application (AML.T0049) leads with 2,134 mapped CVEs — reflecting the reality that most AI/ML systems are deployed behind web APIs with insufficient input validation. AI Software (906), AI Agent Tool Invocation (894), Denial of AI Service (612), and Valid Accounts (598) round out the top five.

The concentration is meaningful: the top 5 techniques account for 38.8% of all CVE-to-technique mappings, while the long tail spans more than 165 techniques with much sparser coverage. Security teams can achieve disproportionate risk reduction by focusing detection and response on a small set of attack patterns — rather than spreading resources thin across the full ATLAS matrix.

Key Findings

  • Initial Access dominates the tactic ranking with 2,385 unique CVEs — public-facing exposure plus weaknesses in the software stack around models drive this category. Privilege Escalation (1,350) and Execution (1,300) follow.
  • AI Software is the second-largest technique with 906 CVEs (AML.T0010.001). This category is essentially the shadow attack surface around the model: deserialization in pickle files, RCE in inference servers, unsafe deserializers in agent frameworks.
  • AI Agent Tool Invocation is more prevalent than commonly assumed. 894 CVEs target this surface. Most AI incident response plans don't cover availability attacks at all.
  • 25 AI CVEs are in CISA's KEV catalog — actively exploited in the wild. They span inference servers (Ollama, vLLM), MLOps platforms (MLflow), and UI frameworks (Gradio).
  • 1,275 AI CVEs (33%) have public exploit code available — almost half of the AI CVE landscape has weaponized PoCs, dramatically shortening the window between disclosure and active exploitation.
  • Growth is steady. 532 new AI-related CVEs were added in the last 30 days alone, confirming the threat surface is expanding faster than most security programs adapt.

Trend Analysis

The shift from model-level attacks (adversarial examples, jailbreaks) toward infrastructure-level exploitation marks a maturation of the AI threat landscape. The data is unambiguous: the real attack surface is the software stack around the models — frameworks, APIs, serving infrastructure, data pipelines.

Agent frameworks remain the emerging frontier. As AI systems gain tool-use capabilities (file access, code execution, web browsing), each tool integration becomes a potential attack vector. Agent-related CVEs continue to grow in both volume and severity, with many enabling remote code execution through prompt injection chains that pivot into the underlying tool runtime.

The patching picture is more nuanced than the early "crisis" narrative suggested. Across all AI package CVE associations, 42.7% have a documented fix available — better than initially feared, but still well below the 60-70% rate typical of the broader software ecosystem. The gap between AI tooling and mainstream software security maturity is real but narrowing.

Recommendations

  1. Prioritize the top 5 ATLAS techniques for detection engineering. Build detection rules specifically for the leading techniques shown above. Together they cover 38.8% of the threat landscape.
  2. Audit your AI supply chain. Inventory all AI/ML dependencies, check against our package risk scores, and establish a vetting process for new framework adoption. Pay special attention to packages with risk scores above 70 (PyTorch, Ollama, MLflow, Gradio, LiteLLM, LangChain, LangFlow).
  3. Implement input validation at every AI system boundary. The dominance of "Exploit Public-Facing Application" and "AI Software" mappings means robust input sanitization at API endpoints, model inputs, and agent tool interfaces delivers the highest security ROI.
  4. Monitor CISA KEV for AI-specific entries. The 25 AI CVEs currently in KEV should be patched within CISA's remediation timelines. Set up automated alerts for new AI KEV additions.
  5. Plan for AI system availability attacks. Include resource exhaustion, recursive loops, and inference overload in incident response playbooks. Most organizations lack AI-specific DoS detection.

Methodology

This analysis is based on 3,821 AI-related CVEs tracked by AI Threat Alert, mapped to 170 MITRE ATLAS techniques via automated enrichment (Claude AI) and manual validation. Technique frequency reflects the number of distinct CVEs mapped to each technique — a single CVE may map to multiple techniques. Tactic counts reflect distinct CVEs mapped to any technique under that tactic. Data sources include NVD, GitHub Security Advisories, CISA KEV, EPSS, OSV, and vendor advisories. All numeric values in this analysis are pulled live from the database on every page load — they always match the charts and tables below.

# Technique CVEs
1 AML.T0049 Exploit Public-Facing Application 2134
2 AML.T0053 AI Agent Tool Invocation 894
3 AML.T0029 Denial of AI Service 612
4 AML.T0012 Valid Accounts 598
5 AML.T0050 Command and Scripting Interpreter 528
6 AML.T0025 Exfiltration via Cyber Means 470
7 AML.T0055 Unsecured Credentials 440
8 AML.T0037 Data from Local System 388
9 AML.T0107 Exploitation for Defense Evasion 310
10 AML.T0081 Modify AI Agent Configuration 292
11 AML.T0083 Credentials from AI Agent Configuration 282
12 AML.T0034 Cost Harvesting 226
13 AML.T0086 Exfiltration via AI Agent Tool Invocation 210
14 AML.T0011 User Execution 199
15 AML.T0040 AI Model Inference API Access 193
16 AML.T0072 Reverse Shell 178
17 AML.T0106 Exploitation for Credential Access 158
18 AML.T0105 Escape to Host 140
19 AML.T0058 Publish Poisoned Models 135
20 AML.T0006 Active Scanning 126
21 AML.T0035 AI Artifact Collection 120
22 AML.T0074 Masquerading 110
23 AML.T0084 Discover AI Agent Configuration 94
24 AML.T0075 Cloud Service Discovery 91
25 AML.T0078 Drive-by Compromise 81
26 AML.T0085 Data from AI Services 78
27 AML.T0036 Data from Information Repositories 77
28 AML.T0080 AI Agent Context Poisoning 77
29 AML.T0043 Craft Adversarial Data 64
30 AML.T0101 Data Destruction via AI Agent Tool Invocation 55
31 AML.T0098 AI Agent Tool Credential Harvesting 40
32 AML.T0057 LLM Data Leakage 38
33 AML.T0007 Discover AI Artifacts 37
34 AML.T0051 LLM Prompt Injection 37
35 AML.T0112 Machine Compromise 34
36 AML.T0110 AI Agent Tool Poisoning 33
37 AML.T0020 Poison Training Data 31
38 AML.T0108 AI Agent 29
39 AML.T0070 RAG Poisoning 27
40 AML.T0079 Stage Capabilities 27
41 AML.T0052 Phishing 26
42 AML.T0021 Establish Accounts 25
43 AML.T0091 Use Alternate Authentication Material 25
44 AML.T0097 Virtualization/Sandbox Evasion 23
45 AML.T0018 Manipulate AI Model 21
46 AML.T0064 Gather RAG-Indexed Targets 21
47 AML.T0073 Impersonation 20
48 AML.T0059 Erode Dataset Integrity 19
49 AML.T0102 Generate Malicious Commands 19
50 AML.T0031 Erode AI Model Integrity 18
51 AML.T0087 Gather Victim Identity Information 18
52 AML.T0093 Prompt Infiltration via Public-Facing Application 17
53 AML.T0024 Exfiltration via AI Inference API 15
54 AML.T0047 AI-Enabled Product or Service 15
55 AML.T0056 Extract LLM System Prompt 15
56 AML.T0099 AI Agent Tool Data Poisoning 15
57 AML.T0010 AI Supply Chain Compromise 14
58 AML.T0001 Search Open AI Vulnerability Analysis 11
59 AML.T0076 Corrupt AI Model 11
60 AML.T0096 AI Service API 11
61 AML.T0104 Publish Poisoned AI Agent Tool 11
62 AML.T0092 Manipulate User LLM Chat History 10
63 AML.T0044 Full AI Model Access 9
64 AML.T0100 AI Agent Clickbait 9
65 AML.T0109 AI Supply Chain Rug Pull 8
66 AML.T0019 Publish Poisoned Datasets 6
67 AML.T0054 LLM Jailbreak 6
68 AML.T0065 LLM Prompt Crafting 6
69 AML.T0077 LLM Response Rendering 6
70 AML.T0014 Discover AI Model Family 5
71 AML.T0015 Evade AI Model 5
72 AML.T0041 Physical Environment Access 5
73 AML.T0063 Discover AI Model Outputs 5
74 AML.T0066 Retrieval Content Crafting 4
75 AML.T0069 Discover LLM System Information 4
76 AML.T0103 Deploy AI Agent 3
77 AML.T0002 Acquire Public AI Artifacts 2
78 AML.T0071 False RAG Entry Injection 2
79 AML.T0000 Search Open Technical Databases 1
80 AML.T0013 Discover AI Model Ontology 1
81 AML.T0046 Spamming AI System with Chaff Data 1
82 AML.T0048 External Harms 1
83 AML.T0061 LLM Prompt Self-Replication 1
84 AML.T0068 LLM Prompt Obfuscation 1
85 AML.T0082 RAG Credential Harvesting 1
86 AML.T0089 Process Discovery 1
87 AML.T0090 OS Credential Dumping 1
88 AML.T0094 Delay Execution of LLM Instructions 1
89 AML.T0111 AI Supply Chain Reputation Inflation 1
90 AML.T0003 Search Victim-Owned Websites 0
91 AML.T0004 Search Application Repositories 0
92 AML.T0005 Create Proxy AI Model 0
93 AML.T0008 Acquire Infrastructure 0
94 AML.T0016 Obtain Capabilities 0
95 AML.T0017 Develop Capabilities 0
96 AML.T0042 Verify Attack 0
97 AML.T0060 Publish Hallucinated Entities 0
98 AML.T0062 Discover LLM Hallucinations 0
99 AML.T0067 LLM Trusted Output Components Manipulation 0
100 AML.T0088 Generate Deepfakes 0
101 AML.T0095 Search Open Websites/Domains 0

Track these techniques against your AI stack with real-time alerts.

Start 14-Day Free Trial