An assessment of more than 1,250 AI-related CVEs found measurable exploitation evidence for only 33 vulnerabilities—about 4.2%—using threat intelligence, vendor advisories, public proof-of-concept activity, EPSS changes, and CISA Known Exploited Vulnerabilities entries. The findings caution that CVE counts and alarming headlines alone do not establish widespread real-world exploitation of AI products.
The highest-priority risks affect AI workflow, agent, and model-serving platforms, including Langflow, LiteLLM, n8n, Flowise, Ollama, and Claude Code. Reported impact patterns include unauthenticated access, remote code execution, injection, unsafe deserialization, and data exposure; research into Claude Code project-file flaws, including CVE-2025-59536 and CVE-2026-21852, highlights the potential for code execution and API-token theft. Organizations should inventory exposed AI services, patch prioritized flaws, enforce authentication and least privilege, segment networks, sandbox workloads, and secure credentials, while accounting for uneven scanner coverage.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
CISA added CVE-2026-42271, a LiteLLM command-injection vulnerability with reported active exploitation, to the KEV catalog. The issue is fixed in LiteLLM 1.83.7.
CISA added CVE-2026-42208, a pre-authentication SQL-injection vulnerability in LiteLLM, to the KEV catalog. LiteLLM 1.83.7 fixes the vulnerability.
CISA added CVE-2026-33634, an embedded-malicious-code issue associated with Aqua Security Trivy components, to the KEV catalog.
CISA added CVE-2026-33017, a Langflow code-injection vulnerability, to the KEV catalog. Langflow 1.9.0 fixes the issue.
CISA added CVE-2025-68613, an n8n remote-code-execution vulnerability, to the KEV catalog. The vulnerability was associated with a public exploit, Zerobot malware reporting, and the Ni8mare exploitation chain.
CISA added CVE-2025-3248, a Langflow missing-authentication vulnerability, to its Known Exploited Vulnerabilities catalog. The issue is fixed in Langflow 1.3.0 and later.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
expel.com
Open sourceresearch.checkpoint.com
Open sourcerapid7.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.