Articles
Daily digests summarizing the vulnerabilities and incidents tracked by VulnWatch.
-
· 60 entries · daily · Subscribers only
VulnWatch Daily: Critical Auth Bypasses in Langflow & Cognee; vLLM RCE Surge
Today's digest highlights critical authentication failures in Langflow and Cognee, alongside a significant cluster of RCE and DoS vulnerabilities in vLLM and MLflow affecting model serving and pipeline integrity.
-
· 33 entries · daily · Subscribers only
VulnWatch Daily: Critical Agent Escapes and Platform Instability Surge
33 new vulnerabilities reported today, including critical RCE in Langroid and Crawl4AI, plus extensive authentication flaws in Coder. Immediate patching recommended for AI inference and agent frameworks.
-
· 79 entries · weekly
VulnWatch Weekly: Langflow Cascade & MCP Ecosystem Risks
Langflow faces a critical week with 10+ CVEs including RCE and secret leakage. MCP servers show systemic auth flaws. Action required on model loading.
-
· 2 entries · daily · Subscribers only
VulnWatch Daily: Keras RCE and Kong MCP Injection Risks
Today's digest covers critical RCE in Keras deserialization and indirect prompt injection in Kong MCP servers. Immediate patching recommended for ML pipelines and agentic gateways.
-
· 10 entries · daily · Subscribers only
VulnWatch Daily: Critical MCP Auth Flaws and Azure OpenAI SSRF Lead July 2nd Digest
Today's digest highlights critical authentication bypasses in MCP servers and agent frameworks, alongside a severe SSRF in Azure OpenAI. Security teams should prioritize patching MLflow, Weaviate, and reviewing agent tool permissions immediately.
-
· 18 entries · daily · Subscribers only
VulnWatch Daily: Langflow Critical Cluster and AI Supply Chain Risks
Critical Langflow vulnerabilities dominate today's digest alongside RCE risks in LLaMA-Factory and MCP auth bypasses. Immediate patching recommended for AI orchestration layers.
-
· 33 entries · daily · Subscribers only
VulnWatch Daily: Claude Code Sandbox Escapes and Serving RCE
Today's digest highlights critical sandbox escapes in Claude Code and a wave of RCE vulnerabilities in model serving frameworks like vLLM and MLflow. LiteLLM and LangChain also show significant auth and injection flaws requiring immediate patching.
-
· 120 entries · weekly
VulnWatch Weekly: Agentic RCE & Supply Chain Risks Surge
Critical vulnerabilities in Langflow, vLLM, and MCP servers highlight severe risks in AI tooling. Immediate patching required for agentic platforms and inference engines to prevent RCE and supply chain compromise.
-
· 29 entries · daily · Subscribers only
VulnWatch Daily: Critical vLLM & Langflow Compromises Dominate June 22 Digest
29 new vulnerabilities reported today, including critical RCE in Langflow and multiple auth bypasses in vLLM. Immediate patching recommended for inference stacks.
-
· 120 entries · weekly
VulnWatch Weekly: PraisonAI Auth Collapse & MCP Server Exposure
This week saw a cascade of critical vulnerabilities in PraisonAI agents and widespread authentication failures in Model Context Protocol servers. Oracle Coherence and Langflow also shipped critical RCEs requiring immediate patching.
-
· 4 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in Flowise, vLLM Inference Risks
Today's digest covers a critical RCE in Flowise orchestration, multiple vLLM inference vulnerabilities, and a Cap-go pagination logic flaw. Immediate patching recommended for exposed services.
-
· 28 entries · daily · Subscribers only
VulnWatch Daily: MCP Server Risks Surge & Langflow Critical Flaws
28 new vulnerabilities reported today, highlighting critical risks in Model Context Protocol servers, Langflow platform integrity, and supply chain attacks via model loading.
-
· 43 entries · daily · Subscribers only
VulnWatch Daily: PraisonAI Critical RCE Cluster & MCP Auth Failures
Over 40 AI vulnerabilities disclosed today, led by critical RCE chains in PraisonAI and unauthenticated MCP servers. Immediate patching recommended for agentic frameworks.
-
· 29 entries · daily · Subscribers only
VulnWatch Daily: Critical Oracle Coherence RCE and Agent Control Plane Exposures
29 new vulnerabilities reported today including CVSS 10.0 Oracle Coherence flaws, widespread MCP agent misconfigurations, and inference engine robustness issues in vLLM and Open WebUI.
-
· 25 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in Langflow & Crawl4AI Docker APIs
25 new vulnerabilities reported today. Critical RCE risks in Langflow and Crawl4AI demand immediate patching. Model serving engines and web frameworks also affected.