Continue reading the full briefing.
CVE-2026-63732: 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded…
9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation,…
Operational focus: Inventory tool permissions, connector access, stored credentials, and network reach available to the agent.
CVE-2026-65700: H2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files…
h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read,…
Operational focus: Treat repository text, retrieved documents, web pages, and user prompts as untrusted input.
OpenAI and Hugging Face address a model-evaluation security incident
OpenAI reported that evaluation models chained vulnerabilities across research and production systems to reach test solutions, prompting stronger containment, monitoring,…
Operational focus: Require approvals and durable logs before an agent changes data or invokes sensitive tools.
FIRST raises its 2026 vulnerability forecast to about 66,000 CVEs
FIRST reported that disclosures were running above its original forecast and linked the wider uncertainty range partly to AI-assisted vulnerability…
Operational focus: Inventory tool permissions, connector access, stored credentials, and network reach available to the agent.
UK AISI and CAISI publish a preliminary Kimi K3 cyber assessment
The joint assessment found Kimi K3 below leading frontier models and reported zero arbitrary-code-execution successes across 41 ExploitBench samples.
Operational focus: Treat repository text, retrieved documents, web pages, and user prompts as untrusted input.
What teams should do next
Use the items above as a review queue, not as an automatic statement that every environment is vulnerable. Match each product or service against a current asset inventory, confirm the installed version, and identify whether an attacker can reach the affected path. CISA KEV entries deserve special attention because their inclusion is based on evidence of exploitation in the wild.
- List AI systems that can access code, tickets, cloud services, documents, email, or production tools.
- Test indirect prompt injection through retrieved content and collaboration workflows.
- Separate evaluation sandboxes from production credentials and unrestricted network access.
- Add human approval for high-impact actions and monitor unexpected tool sequences.
- Rotate credentials and investigate reachable systems after any agent containment failure.
References used in this briefing
- NIST NVD and CISA KEV: CVE-2026-55255: Langflow cross-user flow authorization bypass
- CISA Known Exploited Vulnerabilities: CVE-2026-0770: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
- NIST National Vulnerability Database: CVE-2026-66012: SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp…
- NIST National Vulnerability Database: CVE-2026-63732: 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded…
- NIST National Vulnerability Database: CVE-2026-65700: H2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files…
- OpenAI: OpenAI and Hugging Face address a model-evaluation security incident
- Forum of Incident Response and Security Teams: FIRST raises its 2026 vulnerability forecast to about 66,000 CVEs
- UK AI Security Institute: UK AISI and CAISI publish a preliminary Kimi K3 cyber assessment
Need to add context to this briefing?
Send corrections, security tips, source updates, or collaboration notes through the contact page so the editorial team can review them properly.