ATLAS Landscape
AML.T0085

Data from AI Services

Adversaries may use their access to a victim organization's AI-enabled services to collect proprietary or otherwise sensitive information. As organizations adopt generative AI in centralized services for accessing an organization's data, such as with chat agents which can access retrieval augmented generation (RAG) databases and other data sources via tools, they become increasingly valuable targets for adversaries. AI agents may be configured to have access to tools and data sources that are not directly accessible by users. Adversaries may abuse this to collect data that a regular user wouldn't be able to access directly.

Severity CVE CVSS
CRITICAL CVE-2025-53767 10.0
CRITICAL CVE-2026-1470 9.9
CRITICAL CVE-2024-8309 9.8
CRITICAL CVE-2026-44551 9.1
CRITICAL CVE-2026-21445 9.1
HIGH CVE-2025-6855 8.8
HIGH CVE-2026-27498 8.8
HIGH CVE-2026-26286 8.5
HIGH GHSA-48m6-ch88-55mj 8.1
HIGH CVE-2024-7043 8.1
HIGH CVE-2026-25750 8.1
HIGH CVE-2026-39889 7.5
HIGH CVE-2025-67644 7.3
HIGH CVE-2025-64104 7.3
MEDIUM CVE-2024-7044 6.8
MEDIUM CVE-2026-30886 6.5
MEDIUM CVE-2026-6542 6.5
MEDIUM CVE-2026-25640 5.4
MEDIUM CVE-2026-44558 5.4
MEDIUM CVE-2026-2589 5.3
MEDIUM CVE-2025-68492 4.2
MEDIUM CVE-2026-26019 4.1
MEDIUM CVE-2026-1163 4.1
MEDIUM GHSA-fwjq-xwfj-gv75
UNKNOWN CVE-2026-25083
HIGH CVE-2026-44504
LOW GHSA-v8qf-fr4g-28p2
UNKNOWN CVE-2026-42227
MEDIUM CVE-2025-68131
MEDIUM CVE-2026-35657