Articles
Daily digests summarizing the vulnerabilities and incidents tracked by VulnWatch.
-
· 89 entries · weekly
VulnWatch Weekly: The Agentic Apocalypse & The Langflow Meltdown
This week marks a turning point for AI security as critical RCEs plague agentic frameworks like Mistral Vibe and Langflow. With 89 new entries, the dominant theme is the collapse of trust boundaries in autonomous agents and model serving pipelines.
-
· 43 entries · daily · Subscribers only
Langflow Catastrophe: 14 Critical Flaws Expose AI Orchestration to RCE
A massive cluster of vulnerabilities in IBM Langflow enables unauthenticated RCE and session hijacking. Additional critical issues affect mistral.rs, vLLM, and agentic frameworks via SSRF and path traversal.
-
· 17 entries · daily · Subscribers only
VulnWatch Daily: Critical GitPython RCE, DeepSeek Auth Bypass, and vLLM Data Leaks
Today's digest highlights a critical config corruption flaw in GitPython enabling RCE, an authentication bypass in DeepSeek Harness, and cross-user data leakage in vLLM inference kernels.
-
· 101 entries · weekly
VulnWatch Weekly: The Agentic Explosion & The LiteLLM Emergency
This week marks a turning point for AI security as agentic frameworks become the primary attack surface. With a known-exploited vulnerability in LiteLLM and critical RCEs in MCP hubs, immediate patching is required.
-
· 18 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in Claude Code, SSRF in Unstructured, and Auth Bypasses
Today's digest highlights critical remote code execution in Claude Code Studio, full-read SSRF in the ubiquitous Unstructured library, and severe authentication bypasses in MISP and Copilot Studio affecting AI supply chains.
-
· 13 entries · daily · Subscribers only
VulnWatch Daily: Critical Agentic RCE and LiteLLM Auth Bypasses
Today's digest highlights critical vulnerabilities in agentic frameworks allowing shared bundle overwrites and RCE, alongside active exploitation of LiteLLM authentication flaws and supply-chain risks in model training data handlers.
-
· 7 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in Elasticsearch ML and Supply Chain Risks
Today's digest highlights a critical deserialization flaw in Elasticsearch ML enabling RCE, a recursion DoS in llama.cpp, and supply chain vulnerabilities in Scrapy and pnpm affecting AI data pipelines.
-
· 93 entries · weekly
VulnWatch Weekly: The MCP Security Crisis & Langflow RCE
This week marks a turning point for AI security with critical RCEs in Langflow and a systemic collapse of authentication in the Model Context Protocol (MCP) ecosystem. Immediate patching is required for Kubeflow, Langflow, and all exposed MCP servers.
-
· 46 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE and Auth Bypasses in MCP Ecosystem
August 25, 2026: A surge of critical vulnerabilities targets the Model Context Protocol (MCP) ecosystem, featuring unauthenticated RCE via command injection, unsafe math parsing, and widespread authentication bypasses in agentic frameworks.
-
· 98 entries · weekly
VulnWatch Weekly: The Week of Unsafe Eval, Agent RCE, and Active SSRF
This week's digest highlights a critical wave of Remote Code Execution (RCE) vulnerabilities in LLM inference servers, driven by unsafe deserialization and dynamic code evaluation. Most urgently, CISA has added an actively exploited MLflow SSRF flaw to its KEV catalog, demanding immediate patching for all exposed instances.
-
· 16 entries · daily · Subscribers only
VulnWatch Daily: Critical RCE in LangBot MCP and Supply Chain Risks
Today's digest highlights a critical command injection in LangBot's MCP server, unsafe deserialization in Hugging Face models, and SSRF flaws in LangChain and Microsoft Copilot requiring immediate mitigation.
-
· 25 entries · daily · Subscribers only
VulnWatch Daily: Critical Agent Supply-Chain Poisoning and CodeWhale RCE
Today's digest highlights critical vulnerabilities in agentic workflows, including Kraken cache poisoning and CodeWhale auto-execution flaws. NVIDIA Triton and MONAI also require immediate attention for DoS and RCE risks.
-
· 68 entries · weekly
VulnWatch Weekly: Critical RCE in MindsDB & Agentic Supply Chain Risks
This week's digest highlights a CVSS 10.0 RCE in MindsDB allowing unauthenticated command execution via LLM prompts. We also analyze critical prototype pollution in Trigger.dev, template injection in Prompty, and widespread SSRF/RCE risks in the emerging Model Context Protocol (MCP) ecosystem.
-
· 28 entries · daily · Subscribers only
VulnWatch Daily: Critical Agentic RCE and Supply Chain Flaws in Trigger.dev, vLLM, and Flowise
Today's digest highlights critical remote code execution risks in agentic frameworks like Trigger.dev and AgenticSeek, alongside severe prompt injection bypasses in Flowise and SSRF vulnerabilities in MCP servers. Immediate patching is required for multi-tenant isolation failures.
-
· 116 entries · weekly
VulnWatch Weekly: The Flowise Apocalypse & Active Langflow Exploitation
This week marks a critical turning point for AI platform security with a massive cluster of RCE vulnerabilities in Flowise and active exploitation of IBM Langflow. Immediate patching is required for model serving stacks and agentic frameworks.