Articles
Daily digests summarizing the vulnerabilities and incidents tracked by VulnWatch.
-
· 46 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE and Auth Bypasses in MCP Ecosystem
August 25, 2026: A surge of critical vulnerabilities targets the Model Context Protocol (MCP) ecosystem, featuring unauthenticated RCE via command injection, unsafe math parsing, and widespread authentication bypasses in agentic frameworks.
-
· 4 entries · daily · Subscribers only
VulnWatch Daily: RCE in Xinference, CLI Shell Escapes, and SSRF Gaps
Today's digest covers critical RCE risks in Xinference's model loading, shell command bypasses in Continue CLI, incomplete SSRF fixes in BentoML, and a DoS vector in llama.cpp RPC servers.
-
· 98 entries · weekly
VulnWatch Weekly: The Week of Unsafe Eval, Agent RCE, and Active SSRF
This week's digest highlights a critical wave of Remote Code Execution (RCE) vulnerabilities in LLM inference servers, driven by unsafe deserialization and dynamic code evaluation. Most urgently, CISA has added an actively exploited MLflow SSRF flaw to its KEV catalog, demanding immediate patching for all exposed instances.
-
· 1 entry · daily · Subscribers only
VulnWatch Digest: Critical Deserialization Flaw in llama.cpp RPC
A new medium-severity RCE vulnerability (CVE-2026-78147) targets the ggml-RPC server in llama.cpp, exploiting unsafe deserialization of tensor parameters. Immediate patching is required for distributed inference deployments.
-
· 13 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in Xinference & Omnigent Agent Risks
Today's digest highlights critical remote code execution flaws in Xinference and llama.cpp, alongside severe logic vulnerabilities in the Omnigent agent framework and Headroom proxy that enable privilege escalation and data leakage.
-
· 16 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in LangBot MCP and Supply Chain Risks
Today's digest highlights a critical command injection in LangBot's MCP server, unsafe deserialization in Hugging Face models, and SSRF flaws in LangChain and Microsoft Copilot requiring immediate mitigation.
-
· 21 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in LMDeploy, MCP Supply Chain Risks, and Splunk Escalations
Today's digest highlights a critical pickle deserialization flaw in LMDeploy enabling RCE, widespread path traversal and SSRF issues in the emerging MCP ecosystem, and severe privilege escalation vectors in Splunk's AI tooling.
-
· 25 entries · daily · Subscribers only
VulnWatch Daily: Critical Agent Supply-Chain Poisoning and CodeWhale RCE
Today's digest highlights critical vulnerabilities in agentic workflows, including Kraken cache poisoning and CodeWhale auto-execution flaws. NVIDIA Triton and MONAI also require immediate attention for DoS and RCE risks.
-
· 23 entries · daily · Subscribers only
VulnWatch Daily: Critical Auth Bypasses in MLflow & MemOS; RCE in UpTrain
Today's digest highlights critical authentication bypasses in MLflow and MemOS, severe RCE vulnerabilities in UpTrain, and logic flaws in LLM gateways allowing billing fraud and privilege escalation.
-
· 68 entries · weekly
VulnWatch Weekly: Critical RCE in MindsDB & Agentic Supply Chain Risks
This week's digest highlights a CVSS 10.0 RCE in MindsDB allowing unauthenticated command execution via LLM prompts. We also analyze critical prototype pollution in Trigger.dev, template injection in Prompty, and widespread SSRF/RCE risks in the emerging Model Context Protocol (MCP) ecosystem.
-
· 1 entry · daily · Subscribers only
VulnWatch Daily: SQLi in WordPress ERP Plugin Impacts AI Data Pipelines
A medium-severity SQL injection in a popular WordPress education plugin threatens data integrity for AI systems ingesting school records. Immediate patching to version 5.5+ is required to prevent unauthorized data exfiltration.
-
· 1 entry · daily · Subscribers only
Critical Auth Bypass in WordPress Plugin Highlights AI Function Calling Risks
A critical type confusion vulnerability in the User Profile Builder plugin allows authentication bypass via malformed usernames, exposing risks in AI-driven function calling chains.
-
· 6 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in MindsDB and MCP Supply Chain Risks
Today's digest highlights a CVSS 10.0 unauthenticated RCE in MindsDB, command injection in Token Optimizer MCP, and a cluster of cache poisoning and SSRF issues in CKAN MCP Server affecting AI agent integrity.
-
· 28 entries · daily · Subscribers only
VulnWatch Daily: Critical Agentic RCE and Supply Chain Flaws in Trigger.dev, vLLM, and Flowise
Today's digest highlights critical remote code execution risks in agentic frameworks like Trigger.dev and AgenticSeek, alongside severe prompt injection bypasses in Flowise and SSRF vulnerabilities in MCP servers. Immediate patching is required for multi-tenant isolation failures.
-
· 6 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in Prompty Templates and MCP Supply Chain Risks
Today's digest highlights a critical template injection flaw in Prompty allowing host RCE, alongside severe command injection and path traversal vulnerabilities in emerging Model Context Protocol (MCP) servers affecting Stata and Atlassian integrations.