Articles
Daily digests summarizing the vulnerabilities and incidents tracked by VulnWatch.
-
· 33 entries · daily · Subscribers only
Langflow Catastrophe: 15 Critical Flaws Enable Unauthenticated RCE
A massive cluster of critical vulnerabilities in IBM Langflow allows unauthenticated remote code execution via default configurations. Additional risks identified in AI IDEs, MCP servers, and inference engines require immediate attention.
-
· 60 entries · daily · Subscribers only
VulnWatch Daily: Critical Auth Bypasses in Langflow & Cognee; vLLM RCE Surge
Today's digest highlights critical authentication failures in Langflow and Cognee, alongside a significant cluster of RCE and DoS vulnerabilities in vLLM and MLflow affecting model serving and pipeline integrity.
-
· 79 entries · weekly
VulnWatch Weekly: Langflow Cascade & MCP Ecosystem Risks
Langflow faces a critical week with 10+ CVEs including RCE and secret leakage. MCP servers show systemic auth flaws. Action required on model loading.
-
· 4 entries · daily · Subscribers only
VulnWatch Daily: Critical Pickle Scanning Flaws and ONNX Runtime Risks
Today's digest highlights critical bypasses in model safety scanning and pickle detection, alongside runtime stability issues in ONNX and agentic memory handlers. Immediate patching is advised for serialization tools.
-
· 10 entries · daily · Subscribers only
VulnWatch Daily: MCP Servers Face Injection Risks; Triton DoS Patched
Today's digest highlights critical injection flaws in Model Context Protocol servers, alongside denial-of-service vectors in NVIDIA Triton and supply-chain risks in AI development tools.
-
· 120 entries · weekly
VulnWatch Weekly: Agentic RCE & Supply Chain Risks Surge
Critical vulnerabilities in Langflow, vLLM, and MCP servers highlight severe risks in AI tooling. Immediate patching required for agentic platforms and inference engines to prevent RCE and supply chain compromise.
-
· 23 entries · daily · Subscribers only
VulnWatch Daily: Critical MCP Agent Flaws and Supply Chain Compromises
23 new vulnerabilities reported today including CVSS 10.0 MCP server flaws, compromised litellm wheels, and critical Incus RCEs. Immediate patching recommended for agent frameworks and container infrastructure.
-
· 21 entries · daily · Subscribers only
VulnWatch Daily: Critical Agentic RCE in ToolJet, Flowise, and Cursor
Today's digest highlights critical RCE vulnerabilities in AI agent platforms including ToolJet and Flowise, alongside supply chain risks in model loading and authentication bypasses in LibreChat.
-
· 20 entries · daily · Subscribers only
VulnWatch Daily: Agentic Terminal Flood & Critical CLI RCEs
20 new vulnerabilities disclosed today, including a critical Gemini CLI RCE and 10 high-severity flaws in Warp. Immediate patching recommended for AI development environments.
-
· 29 entries · daily · Subscribers only
VulnWatch Daily: Critical vLLM & Langflow Compromises Dominate June 22 Digest
29 new vulnerabilities reported today, including critical RCE in Langflow and multiple auth bypasses in vLLM. Immediate patching recommended for inference stacks.
-
· 120 entries · weekly
VulnWatch Weekly: PraisonAI Auth Collapse & MCP Server Exposure
This week saw a cascade of critical vulnerabilities in PraisonAI agents and widespread authentication failures in Model Context Protocol servers. Oracle Coherence and Langflow also shipped critical RCEs requiring immediate patching.
-
· 28 entries · daily · Subscribers only
VulnWatch Daily: MCP Server Risks Surge & Langflow Critical Flaws
28 new vulnerabilities reported today, highlighting critical risks in Model Context Protocol servers, Langflow platform integrity, and supply chain attacks via model loading.
-
· 19 entries · daily · Subscribers only
VulnWatch Daily: Critical Agent Control Bypasses and Twig RCE Cluster
19 new vulnerabilities reported today including active Langflow exploitation, critical MCP auth bypasses, and a massive cluster of Twig RCEs affecting AI rendering pipelines.
-
· 17 entries · daily · Subscribers only
VulnWatch Daily: MCP RCE, Supply Chain Worms, and MLflow Risks
Critical MCP RCEs and a renewed npm worm campaign dominate today's digest. MLflow and AutoGPT users must patch immediately to prevent agent compromise.
-
· 17 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in SGLangs and ChromaDB; Mistral Supply Chain
Today's digest highlights critical RCE vulnerabilities in SGLangs and ChromaDB, alongside a confirmed malicious dropper in the Mistral AI PyPI package. Immediate patching and supply chain verification are required.