VulnWatch VulnWatch

Today's Entries

AI/ML security vulnerabilities, advisories, and breaches from the last 24 hours, sorted by severity.

13
New entries
0
Critical
0
Actively exploited
High nvd

CVE-2026-94623: vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation tha

vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt completion request...

vllm
8.7
CVSS
18 hours ago
High nvd

CVE-2026-94624: vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configur

vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers can s...

vllm
8.7
CVSS
18 hours ago
High nvd

CVE-2026-94626: vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoi

vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory. Attackers can supply arbit...

openai vllm
8.7
CVSS
18 hours ago
High nvd

CVE-2026-94627: vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child reque

vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single transfer ID in prefill/decode disaggregated deployments. Atta...

vllm
8.7
CVSS
18 hours ago
High nvd

CVE-2026-94622: vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for pre

vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/decode disaggregated deployments. Attackers can send requests with incomple...

vllm
8.7
CVSS
18 hours ago
High nvd

CVE-2026-61647: NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content

NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content to local vault directories. Versions 1.6.0 through 2.0.2 contain a path traversa...

Agentic / MCP mcp server llm
7.1
CVSS
19 hours ago
Medium nvd

CVE-2025-14486: The PixelPlay plugin for WordPress is vulnerable to unauthorized API key deletion due to missing authorization checks in

The PixelPlay plugin for WordPress is vulnerable to unauthorized API key deletion due to missing authorization checks in all versions up to, and including, 1.0.2. This makes it possible for unauthenti...

openai
5.3
CVSS
8 hours ago
Medium nvd

CVE-2026-94625: vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests cr

vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders that are never reclaimed. Attackers can sen...

vllm
6.9
CVSS
18 hours ago
Medium nvd

CVE-2026-77518: MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal workspace user who knows anothe

MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal workspace user who knows another user's active MCP tool_id in the same workspace can retrieve the hidden tool t...

Agentic / MCP mcp server
5.0
CVSS
19 hours ago
Medium nvd

CVE-2026-61612: CKAN MCP Server is a tool for querying CKAN open data portals. Prior to version 0.4.108, the SSRF guard `validateServerU

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to version 0.4.108, the SSRF guard `validateServerUrl` (added for CVE-2026-33060, extended for CVE-2026-53509) validates only the h...

5.7
CVSS
22 hours ago
Unknown rss_thehackernews

AI Agents Are Rewriting the Rules of Lateral Movement

Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths an autonomous system can discover, given the acces...

4 hours ago
Unknown rss_huggingface

Transformers now runs llama.cpp quants

transformers llama
16 hours ago

Get the weekly digest

Top AI security stories every Monday. Free, no spam. Want it daily? See Daily Briefing.