Articles
Daily digests summarizing the vulnerabilities and incidents tracked by VulnWatch.
-
· 93 entries · weekly
VulnWatch Weekly: The MCP Security Crisis & Langflow RCE
This week marks a turning point for AI security with critical RCEs in Langflow and a systemic collapse of authentication in the Model Context Protocol (MCP) ecosystem. Immediate patching is required for Kubeflow, Langflow, and all exposed MCP servers.
-
· 24 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in Langflow, Kubeflow SSRF, and Agent Supply Chain Risks
Today's digest highlights a catastrophic command execution chain in IBM Langflow, a CVSS 10.0 SSRF in Kubeflow Pipelines, and emerging risks in AI agent orchestration and LLM proxy authentication bypasses.
-
· 46 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE and Auth Bypasses in MCP Ecosystem
August 25, 2026: A surge of critical vulnerabilities targets the Model Context Protocol (MCP) ecosystem, featuring unauthenticated RCE via command injection, unsafe math parsing, and widespread authentication bypasses in agentic frameworks.
-
· 98 entries · weekly
VulnWatch Weekly: The Week of Unsafe Eval, Agent RCE, and Active SSRF
This week's digest highlights a critical wave of Remote Code Execution (RCE) vulnerabilities in LLM inference servers, driven by unsafe deserialization and dynamic code evaluation. Most urgently, CISA has added an actively exploited MLflow SSRF flaw to its KEV catalog, demanding immediate patching for all exposed instances.
-
· 16 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in LangBot MCP and Supply Chain Risks
Today's digest highlights a critical command injection in LangBot's MCP server, unsafe deserialization in Hugging Face models, and SSRF flaws in LangChain and Microsoft Copilot requiring immediate mitigation.
-
· 25 entries · daily · Subscribers only
VulnWatch Daily: Critical Agent Supply-Chain Poisoning and CodeWhale RCE
Today's digest highlights critical vulnerabilities in agentic workflows, including Kraken cache poisoning and CodeWhale auto-execution flaws. NVIDIA Triton and MONAI also require immediate attention for DoS and RCE risks.
-
· 23 entries · daily · Subscribers only
VulnWatch Daily: Critical Auth Bypasses in MLflow & MemOS; RCE in UpTrain
Today's digest highlights critical authentication bypasses in MLflow and MemOS, severe RCE vulnerabilities in UpTrain, and logic flaws in LLM gateways allowing billing fraud and privilege escalation.
-
· 68 entries · weekly
VulnWatch Weekly: Critical RCE in MindsDB & Agentic Supply Chain Risks
This week's digest highlights a CVSS 10.0 RCE in MindsDB allowing unauthenticated command execution via LLM prompts. We also analyze critical prototype pollution in Trigger.dev, template injection in Prompty, and widespread SSRF/RCE risks in the emerging Model Context Protocol (MCP) ecosystem.
-
· 1 entry · daily · Subscribers only
Critical Auth Bypass in WordPress Plugin Highlights AI Function Calling Risks
A critical type confusion vulnerability in the User Profile Builder plugin allows authentication bypass via malformed usernames, exposing risks in AI-driven function calling chains.
-
· 116 entries · weekly
VulnWatch Weekly: The Flowise Apocalypse & Active Langflow Exploitation
This week marks a critical turning point for AI platform security with a massive cluster of RCE vulnerabilities in Flowise and active exploitation of IBM Langflow. Immediate patching is required for model serving stacks and agentic frameworks.
-
· 3 entries · daily · Subscribers only
VulnWatch Daily: Critical WP Plugin Flaw & MCP Command Injection Risks
Today's digest highlights a critical authorization bypass in a WordPress AI plugin enabling full site takeover, alongside two command injection vulnerabilities in emerging Model Context Protocol (MCP) gateways affecting Claude and local LLM memory tools.
-
· 19 entries · daily · Subscribers only
Critical RCE Wave Hits llama.cpp and MCP Frameworks
A surge of critical vulnerabilities targets core AI infrastructure, including sandbox escapes in Model Context Protocol and multiple memory corruption flaws in llama.cpp enabling remote code execution.
-
· 33 entries · daily · Subscribers only
Langflow Catastrophe: 20+ RCEs, Supply Chain Risks, and Agentic Flaws
A historic wave of vulnerabilities hits IBM Langflow with 20+ CVEs including unauthenticated RCE. Critical issues also found in PraisonAI CI/CD, Hugging Face PEFT deserialization, and Milvus DoS.
-
· 43 entries · daily · Subscribers only
Critical Flowise RCE Wave and Langflow Injection Compromise AI Supply Chain
A massive cluster of vulnerabilities in Flowise and a critical CISA-listed flaw in Langflow expose AI platforms to unauthenticated RCE, credential theft, and supply-chain compromise. Immediate patching and network isolation are required.
-
· 58 entries · weekly
VulnWatch Weekly: The Agentic Apocalypse & Supply Chain Meltdown
This week marks a turning point for AI security with critical RCEs in Langflow, Flyto2, and sentence-transformers. The dominant theme is the collapse of trust boundaries in agentic workflows, demanding immediate patching of model serving and orchestration layers.