Articles
Daily digests summarizing the vulnerabilities and incidents tracked by VulnWatch.
-
· 16 entries · daily · Subscribers only
vLLM DoS Wave, MCP RCE Risks, and Agent Auth Flaws Dominate September 21 AI Security Landscape
A critical cluster of DoS vulnerabilities in vLLM threatens inference availability, while new RCE and SSRF flaws in MCP servers highlight escalating risks in agentic workflows. Immediate patching and configuration audits are required.
-
· 120 entries · weekly
VulnWatch Weekly: MCP Servers Under Siege, LLM RCE via Pickle
This week's digest highlights a critical wave of vulnerabilities in Model Context Protocol (MCP) servers, featuring unauthenticated RCEs, SSRF chains, and token theft. We also cover severe pickle deserialization flaws in LLM serving stacks like LMDeploy and vLLM.
-
· 17 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in LMDeploy, MCP Lateral Movement, and vLLM DoS
Today's digest highlights critical remote code execution flaws in LMDeploy's serving stack, dangerous network isolation gaps in ToolHive MCP servers, and multiple denial-of-service vectors in vLLM and SGLang engines.
-
· 27 entries · daily · Subscribers only
VulnWatch Digest: Critical MCP Auth Bypasses and LLM Infra DoS Risks
Today's digest highlights critical authentication flaws in Model Context Protocol servers, command injection in M365 Copilot, and resource exhaustion vectors in vLLM and SGLang disaggregated deployments.
-
· 38 entries · daily · Subscribers only
Critical MCP Supply Chain Crisis: RCE, SSRF, and Auth Bypasses Dominate September 15 Digest
A wave of critical vulnerabilities in Model Context Protocol (MCP) servers exposes AI agents to remote code execution, credential theft, and DNS rebinding attacks. Immediate patching of GitLab, MySQL, and Context Forge integrations is required.
-
· 36 entries · daily · Subscribers only
VulnWatch Digest: Critical Storm RCEs, Langflow SSRF, and Agentic Path Traversal Risks
A massive cluster of vulnerabilities hits Apache Storm with critical RCE and auth bypass flaws. IBM Langflow, PraisonAI, and MCP servers face severe SSRF and path traversal risks enabling credential theft and data exfiltration.
-
· 89 entries · weekly
VulnWatch Weekly: The Agentic Apocalypse & The Langflow Meltdown
This week marks a turning point for AI security as critical RCEs plague agentic frameworks like Mistral Vibe and Langflow. With 89 new entries, the dominant theme is the collapse of trust boundaries in autonomous agents and model serving pipelines.
-
· 14 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in Mistral Vibe & Agentic Supply Chain Risks
Today's digest highlights a cluster of critical RCE vulnerabilities in Mistral Vibe allowing full command bypass, alongside severe agentic supply chain flaws in MySQL MCP and Shopper frameworks requiring immediate remediation.
-
· 43 entries · daily · Subscribers only
Langflow Catastrophe: 14 Critical Flaws Expose AI Orchestration to RCE
A massive cluster of vulnerabilities in IBM Langflow enables unauthenticated RCE and session hijacking. Additional critical issues affect mistral.rs, vLLM, and agentic frameworks via SSRF and path traversal.
-
· 17 entries · daily · Subscribers only
VulnWatch Daily: Critical GitPython RCE, DeepSeek Auth Bypass, and vLLM Data Leaks
Today's digest highlights a critical config corruption flaw in GitPython enabling RCE, an authentication bypass in DeepSeek Harness, and cross-user data leakage in vLLM inference kernels.
-
· 101 entries · weekly
VulnWatch Weekly: The Agentic Explosion & The LiteLLM Emergency
This week marks a turning point for AI security as agentic frameworks become the primary attack surface. With a known-exploited vulnerability in LiteLLM and critical RCEs in MCP hubs, immediate patching is required.
-
· 2 entries · daily · Subscribers only
Axolotl RCE and Rowboat SSRF: Critical Risks in AI Tooling
New vulnerabilities in Axolotl and Rowboat expose AI pipelines to remote code execution and server-side request forgery, demanding immediate patching and configuration audits for ML platforms.
-
· 45 entries · daily · Subscribers only
VulnWatch Digest: Critical RCE in AI Agents and Widespread SSRF in Model Serving
Today's digest highlights critical remote code execution flaws in CodeWhale and LaVague agents, alongside a wave of SSRF vulnerabilities in OpenAI-compatible APIs. Immediate patching is required for multiple high-severity issues affecting Langflow, vLLM, and Hugging Face tokenizers.
-
· 18 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in Claude Code, SSRF in Unstructured, and Auth Bypasses
Today's digest highlights critical remote code execution in Claude Code Studio, full-read SSRF in the ubiquitous Unstructured library, and severe authentication bypasses in MISP and Copilot Studio affecting AI supply chains.
-
· 13 entries · daily · Subscribers only
VulnWatch Daily: Critical Agentic RCE and LiteLLM Auth Bypasses
Today's digest highlights critical vulnerabilities in agentic frameworks allowing shared bundle overwrites and RCE, alongside active exploitation of LiteLLM authentication flaws and supply-chain risks in model training data handlers.