Articles
Daily digests summarizing the vulnerabilities and incidents tracked by VulnWatch.
-
· 45 entries · daily · Subscribers only
VulnWatch Digest: Critical RCE in AI Agents and Widespread SSRF in Model Serving
Today's digest highlights critical remote code execution flaws in CodeWhale and LaVague agents, alongside a wave of SSRF vulnerabilities in OpenAI-compatible APIs. Immediate patching is required for multiple high-severity issues affecting Langflow, vLLM, and Hugging Face tokenizers.
-
· 18 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in Claude Code, SSRF in Unstructured, and Auth Bypasses
Today's digest highlights critical remote code execution in Claude Code Studio, full-read SSRF in the ubiquitous Unstructured library, and severe authentication bypasses in MISP and Copilot Studio affecting AI supply chains.
-
· 13 entries · daily · Subscribers only
VulnWatch Daily: Critical Agentic RCE and LiteLLM Auth Bypasses
Today's digest highlights critical vulnerabilities in agentic frameworks allowing shared bundle overwrites and RCE, alongside active exploitation of LiteLLM authentication flaws and supply-chain risks in model training data handlers.
-
· 13 entries · daily · Subscribers only
MCPHub Critical Flaws and Agentic RCE Risks Dominate August 31 Vulnerability Landscape
A surge of critical vulnerabilities in MCPHub and Eclipse Theia exposes agentic systems to RCE, SSRF, and prompt injection attacks, demanding immediate patching and architectural review.
-
· 93 entries · weekly
VulnWatch Weekly: The MCP Security Crisis & Langflow RCE
This week marks a turning point for AI security with critical RCEs in Langflow and a systemic collapse of authentication in the Model Context Protocol (MCP) ecosystem. Immediate patching is required for Kubeflow, Langflow, and all exposed MCP servers.
-
· 24 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in Langflow, Kubeflow SSRF, and Agent Supply Chain Risks
Today's digest highlights a catastrophic command execution chain in IBM Langflow, a CVSS 10.0 SSRF in Kubeflow Pipelines, and emerging risks in AI agent orchestration and LLM proxy authentication bypasses.
-
· 9 entries · daily · Subscribers only
Critical MCP Server Exposure and Supply Chain Risks in AI Agents
A wave of critical vulnerabilities exposes Model Context Protocol (MCP) servers to unauthenticated access and credential theft, while supply chain flaws threaten mobile AI integrations and data integrity.
-
· 46 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE and Auth Bypasses in MCP Ecosystem
August 25, 2026: A surge of critical vulnerabilities targets the Model Context Protocol (MCP) ecosystem, featuring unauthenticated RCE via command injection, unsafe math parsing, and widespread authentication bypasses in agentic frameworks.
-
· 98 entries · weekly
VulnWatch Weekly: The Week of Unsafe Eval, Agent RCE, and Active SSRF
This week's digest highlights a critical wave of Remote Code Execution (RCE) vulnerabilities in LLM inference servers, driven by unsafe deserialization and dynamic code evaluation. Most urgently, CISA has added an actively exploited MLflow SSRF flaw to its KEV catalog, demanding immediate patching for all exposed instances.
-
· 13 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in Xinference & Omnigent Agent Risks
Today's digest highlights critical remote code execution flaws in Xinference and llama.cpp, alongside severe logic vulnerabilities in the Omnigent agent framework and Headroom proxy that enable privilege escalation and data leakage.
-
· 16 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in LangBot MCP and Supply Chain Risks
Today's digest highlights a critical command injection in LangBot's MCP server, unsafe deserialization in Hugging Face models, and SSRF flaws in LangChain and Microsoft Copilot requiring immediate mitigation.
-
· 21 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in LMDeploy, MCP Supply Chain Risks, and Splunk Escalations
Today's digest highlights a critical pickle deserialization flaw in LMDeploy enabling RCE, widespread path traversal and SSRF issues in the emerging MCP ecosystem, and severe privilege escalation vectors in Splunk's AI tooling.
-
· 25 entries · daily · Subscribers only
VulnWatch Daily: Critical Agent Supply-Chain Poisoning and CodeWhale RCE
Today's digest highlights critical vulnerabilities in agentic workflows, including Kraken cache poisoning and CodeWhale auto-execution flaws. NVIDIA Triton and MONAI also require immediate attention for DoS and RCE risks.
-
· 23 entries · daily · Subscribers only
VulnWatch Daily: Critical Auth Bypasses in MLflow & MemOS; RCE in UpTrain
Today's digest highlights critical authentication bypasses in MLflow and MemOS, severe RCE vulnerabilities in UpTrain, and logic flaws in LLM gateways allowing billing fraud and privilege escalation.
-
· 68 entries · weekly
VulnWatch Weekly: Critical RCE in MindsDB & Agentic Supply Chain Risks
This week's digest highlights a CVSS 10.0 RCE in MindsDB allowing unauthenticated command execution via LLM prompts. We also analyze critical prototype pollution in Trigger.dev, template injection in Prompty, and widespread SSRF/RCE risks in the emerging Model Context Protocol (MCP) ecosystem.