Researchers disclosed multiple vulnerabilities in enterprise AI agent frameworks that allowed attackers to bypass model authorization, trigger tools directly, and in some cases achieve remote code execution. Check Point reported 11 flaws across LangChain, LangGraph, CrewAI, AutoGen, Microsoft Agent Framework, and Google ADK, spanning insecure deserialization, SSRF, path traversal, and use-after-free. One critical issue in Microsoft Agent Framework let untrusted state data reach insecure checkpoint deserialization, enabling RCE; Microsoft fixed the bug and said no CVE was assigned because the product was not generally available.
A separate disclosure described a cross-platform pattern dubbed CoreBreak, where execution layers in Amazon Bedrock AgentCore, Google ADK, and Vercel AI SDK harnesses accepted tool-call-shaped data without confirming that a legitimate model turn had authorized the action. AWS assigned CVE-2026-18830 and automatically patched the managed service, Google fixed CVE-2026-18236 in ADK for Python version 2.5.0, and Vercel patched @ai-sdk/harness-codex 1.0.29 and @ai-sdk/harness-opencode 1.0.28. Researchers said the findings show that the main risk lies in insecure agent orchestration and tool-execution logic, not prompt injection alone, with Google ADK also exposed to abuse that could write and run malicious Python code and leak API keys or cloud service account credentials.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
AWS said the managed Bedrock AgentCore InvokeHarness API was affected before July 31, 2026, and added server-side validation to reject caller-supplied tool-use blocks before they reached the event loop. AWS assigned CVE-2026-18830 and applied the mitigation automatically.
Google released ADK for Python version 2.5.0 with fixes for the continuation-forgery issue tracked as CVE-2026-18236. On July 16, 2026, it also shipped a second 2.5.0 fix for resumable-mode flows that accepted user-authored function_call events.
The pull request warning about externally injected toolUse blocks in Strands was closed without being merged.
An April pull request warned that externally injected toolUse blocks in Strands could reach tool execution without model invocation. The pull request was later closed unmerged.
At Black Hat USA 2026, Shahar Tal and Yarden Porat presented research on post-injection exploitation in AI agent frameworks, arguing that attacker-controlled content can reach internals such as serialization, caching, and file parsers. They reported 12 CVEs across LangChain, Google ADK, Microsoft Agent Framework, and CrewAI, including scenarios where poisoned agent memory could trigger payload execution during save-and-reload flows.
Hedi Ingber and Aviyam Ivgi of Stealth presented CoreBreak at Black Hat USA 2026 as a cross-platform agent security pattern. They said AWS, Google, and Vercel agent frameworks accepted tool-call-shaped data without verifying that a legitimate model turn had authorized execution.
Vercel patched @ai-sdk/harness-codex in version 1.0.29 and @ai-sdk/harness-opencode in version 1.0.28 for flaws tracked as CVE-2026-64650 and CVE-2026-64651. The fixes removed the process-path fallback and required exact short-lived one-time authorization tied to a model event.
Check Point reported that Google ADK exposed a built-in development assistant and unauthenticated HTTP API that could be abused to write and execute malicious Python code, exposing secrets and the container service account. Google initially did not consider it a bug, later paid a $3,133.70 bounty, and issued only a partial fix.
Microsoft fixed a critical Agent Framework vulnerability in which prompt-injected untrusted checkpoint data could be deserialized and lead to remote code execution. Microsoft also paid a $10,000 bounty and said it released protections and documentation updates, but did not assign a CVE because the product was not generally available.
Check Point disclosed 11 vulnerabilities across LangChain, LangGraph, CrewAI, AutoGen, Microsoft Agent Framework, and Google ADK. The researchers said the issues went beyond prompt injection and included insecure deserialization, SSRF, path traversal, and use-after-free in framework logic and orchestration layers.
Check Point researchers Yarden Porat and Shahar Tal studied enterprise AI agent frameworks for about a year before disclosing their findings.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcethehackernews.com
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.