Live AI Security Brief for July 27, 2026: Agents, Prompt Injection, and Model Risk

Live AI Security Brief for July 27, 2026: Agents, Prompt Injection, and Model Risk

Verified AI security news and advisories covering agent frameworks, prompt injection, tool access, sandboxing, model evaluation, and sensitive data boundaries.

Live verification: This briefing was assembled from public CISA, NIST NVD, GitHub, Ubuntu, Microsoft, and other official publisher feeds checked on July 27, 2026 at 6:30 pm IST. Existing posts are preserved and repeated source IDs are deduplicated.

Executive summary

The current source set produced 8 relevant updates for this briefing. It includes 2 CISA Known Exploited Vulnerabilities, 3 critical records, 0 high-severity records, and 2 official publisher updates. Severity alone is not treated as proof of exposure: teams should verify products, versions, reachability, privileges, and available mitigations.

AI security incidents increasingly cross the boundary between model output and real tools. The key review is not only what a model can say, but what its agent harness, connectors, credentials, network access, and execution environment allow it to do.

Top verified developments

CVE-2026-55255: Langflow cross-user flow authorization bypass

NIST NVD and CISA KEV | July 7, 2026 | Known Exploited | CVSS 8.4 | Langflow Langflow before 1.9.1

Source summary: Before version 1.9.1, an authenticated attacker could specify another user's flow ID and execute that flow. The CNA rates the…

CISA lists this issue in the Known Exploited Vulnerabilities catalog, which makes confirmed exploitation the leading prioritization signal. Review the catalog due date and required action, then identify exposed assets before normal severity-only backlog work.

CISA due date: 2026-07-10. Apply the current Langflow fix and follow CISA KEV remediation guidance.

AI Security review: Inventory tool permissions, connector access, stored credentials, and network reach available to the agent.

Read the current source record

CVE-2026-0770: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

CISA Known Exploited Vulnerabilities | July 21, 2026 | Known Exploited | Langflow Langflow

Source summary: Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on…

CISA lists this issue in the Known Exploited Vulnerabilities catalog, which makes confirmed exploitation the leading prioritization signal. Review the catalog due date and required action, then identify exposed assets before normal severity-only backlog work.

CISA due date: 2026-07-24. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance…

AI Security review: Treat repository text, retrieved documents, web pages, and user prompts as untrusted input.

Read the current source record

CVE-2026-66012: SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp…

NIST National Vulnerability Database | July 25, 2026 | CRITICAL | CVSS 10.0

Source summary: SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a…

This record is a current vulnerability or package advisory. Confirm the affected version range and vendor fix before deployment, then prioritize instances that are public, privileged, or connected to sensitive data and production workflows.

AI Security review: Require approvals and durable logs before an agent changes data or invokes sensitive tools.

Read the current source record

CVE-2026-63732: 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded…

NIST National Vulnerability Database | July 24, 2026 | CRITICAL | CVSS 9.9

Source summary: 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation,…

This record is a current vulnerability or package advisory. Confirm the affected version range and vendor fix before deployment, then prioritize instances that are public, privileged, or connected to sensitive data and production workflows.

AI Security review: Inventory tool permissions, connector access, stored credentials, and network reach available to the agent.

Read the current source record

CVE-2026-65700: H2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files…

NIST National Vulnerability Database | July 23, 2026 | CRITICAL | CVSS 9.8

Continue reading the full briefing.

Corrections and tips

Need to add context to this briefing?

Send corrections, security tips, source updates, or collaboration notes through the contact page so the editorial team can review them properly.

Contact InfoSecNexus