Cyber Resilience

Vulnerabilities in AI Software

Daily-updated analysis of CVEs affecting AI and machine-learning software — frameworks, libraries, LLM platforms, agent protocols, enterprise assistants, and supporting infrastructure. Compares vulnerabilities in AI software against all other software, with breakdowns by severity, vector, weakness, exploitability and priority.

Last updated: 23 August 2026 00:24 UTC

AI CVEs in 2025
863
1.7% of all CVEs published
AI CVEs in 2026 so far
1,436
235 days (7.7 months) of data
2026 annualised
2,230
↑ +158% vs. 2025
CISA KEV-listed
9
1 ransomware-linked
AI Software Vulnerabilities
What changed1,436 AI-software CVEs so far in 2026; up 158% annualized vs 2025; 9 already CISA-confirmed exploited.
Why it mattersAI and ML software is a fast-growing, under-tracked attack surface — the standard feeds barely tag it, so dashboards built on them under-count AI risk.
Who's affectedAnyone running LLM application platforms, agent frameworks, model-serving infrastructure, developer AI tools, or enterprise AI assistants.
What to do firstIdentify which AI tools are in your stack, then check their CVEs and KEV status.
Security leader talking pointAI governance needs a software-vulnerability lens, not just a model-safety policy.
Lean IT actionAdd your AI/ML tools to the asset inventory and patch them like any other software.
What this means

AI risk, in one read

1,436 vulnerabilities disclosed in AI software so far in 2026 — ↑158% annualized against 2025, and 9 of them are on CISA’s exploited list.

Volume & Trend

→ Top: AI-related CVEs as a share of all new CVEs, by month. Bottom: monthly AI-related vs. non-AI volume — the non-AI (right) axis is scaled so the two lines share the same average height, so the relative trend is what stands out. AI volume has climbed steeply through 2025 and 2026.

CVSS Distribution by Year

→ Box plot of CVSS base score distributions for AI-related vs. all other software, in 2025 and 2026. The middle line is the median; the box is the interquartile range.

AI Subcategory Risk Profile

→ Top 10 AI subcategories by all-time annotated CVE count. Bar length is volume; bar colour is mean CVSS (severity), and each bar is labelled with its mean CVSS and mean EPSS (exploitation probability), so you can read which kinds of AI software are most common, most severe, and under the most exploit pressure. Model Context Protocol (MCP) and similar agent integrations live under “AI Agent Protocols and Integrations.”
What each category means — definitions & examples
LLM Application Platforms
Frameworks and runtimes for building applications on top of large language models — orchestration, retrieval-augmented generation, agents, and prompt pipelines. Vulnerabilities cluster in tool-calling, prompt handling, and untrusted-input flows. e.g. LangChain, LlamaIndex, Ollama, llama.cpp, vLLM, Flowise
AI Agent Protocols and Integrations
Standards and connectors that let AI agents call tools and talk to each other; risk lives in the connection, delegation, and data-exchange layers. e.g. Model Context Protocol (MCP), Agent2Agent (A2A), MCP servers
Deep Learning Frameworks
Core neural-network libraries for training and running models; CVEs often involve model execution, tensor operations, or GPU handling. e.g. TensorFlow, PyTorch, Keras, MXNet, Caffe
Enterprise AI Assistants
Production RAG / generative assistants embedded in productivity and security suites; risks include prompt injection and data exfiltration (e.g. the EchoLeak flaw, CVE-2025-32711). e.g. Microsoft 365 Copilot, Security Copilot, Copilot Studio
Other AI Platforms
AI/ML software that doesn't fall into the named categories above — the catch-all bucket for less common frameworks and tooling. e.g. Miscellaneous ML frameworks, data pipelines, and model tooling
Other Platforms
Managed cloud ML platforms — training, deployment, and MLOps services; exposure is usually service- or integration-specific. e.g. AWS SageMaker, Azure Machine Learning, Google AI Platform
NLP and Transformers
Pre-trained language-model libraries and model hubs; emerging CVEs in model loading, deserialization, and tokenization. e.g. Hugging Face Transformers
Machine Learning Libraries
General-purpose ML algorithm libraries; common CVEs in data handling and model serialization (e.g. unsafe pickle loads). e.g. scikit-learn, FastAI
APIs and Models
Hosted model endpoints and their client SDKs; vulnerabilities cluster in the API-integration layer more than in the models themselves. e.g. OpenAI GPT / Embeddings APIs
Computer Vision
Image and video processing libraries; frequent CVEs in buffer handling and media-format parsing. e.g. OpenCV, torchvision, Pillow

Who Builds It

→ Top: vendors with the most AI-related CVEs, 2025–2026 (a CVE can name more than one vendor). Bottom: the open-source vs. proprietary split across the same cohort, from per-CVE source-availability tagging. Most AI-related vulnerabilities land in open-source software.

CVSS Vector Profile

→ Distribution of four CVSS sub-vectors across AI-related vs. all other software, 2025 + 2026 combined. Attack Vector (network accessibility), Privileges Required, User Interaction, and the highest of Confidentiality / Integrity / Availability impact.

Top CWEs — 2025 vs 2026 Rank Shift

→ Top weaknesses in AI-related CVEs, comparing 2025 totals against 2026 (Q1+Q2 so far). Server-Side Request Forgery (CWE-918) has risen sharply in 2026 alongside the established command-injection and cross-site scripting weaknesses.

MITRE ATT&CK Enterprise Techniques

→ Top techniques associated with AI-related vulnerabilities, ranked by annotated CVE count. Click any bar to open the MITRE ATT&CK technique page in a new tab.

EPSS Cumulative Distribution

→ CDF curves comparing EPSS exploit-probability scores across AI-related vs. all other software (2025 + 2026). Curves further to the right indicate higher exploitation probability.

AI CVE Exploit Pressure

→ Each dot is an AI-related high-severity CVE (CVSS > 8) or CISA KEV entry, plotted by exploit probability (EPSS, log scale) against its age. Red = on CISA KEV. Click a dot or label to open the CVE detail page in a new tab.

CISA KEV: AI-listed Vulnerabilities

9 AI-related CVEs are on CISA's Known Exploited Vulnerabilities list. 1 have a confirmed ransomware campaign association. 1 added to KEV in 2025 · 8 added in 2026 · 0 added earlier.

Top 25 AI CVEs by Risk Priority

→ Composite priority score = 60% EPSS + 20% KEV + 20% CVSS, scaled to 0–100. Click any column header to re-sort. CVE links open the full detail page.
CVERisk PriorityCVSSEPSSPublished
CVE-2025-5952810010.00.91232025-09-22
CVE-2026-0770KEV 1000.00.62922026-01-23
CVE-2025-11749 979.80.74762025-11-05
CVE-2025-2294 979.80.77882025-03-28
CVE-2025-3248KEV 979.81.00002025-04-07
CVE-2025-8943 979.80.72312025-08-14
CVE-2026-33017KEV 979.80.96182026-03-20
CVE-2026-42208KEV 979.80.89422026-05-08
CVE-2025-26319 939.80.55872025-03-04
CVE-2025-6514 939.60.77752025-07-09
CVE-2025-32375 929.80.50452025-04-09
CVE-2025-58434 929.80.49892025-09-12
CVE-2025-12420 919.80.46072026-01-12
CVE-2025-34291KEV 908.80.83842025-12-05
CVE-2025-62593KEV 908.80.01002025-11-26
CVE-2026-23744 909.80.45032026-01-16
CVE-2026-42271KEV 908.80.83012026-05-08
CVE-2026-33032 899.80.38482026-03-30
CVE-2025-27520 889.80.35672025-04-04
CVE-2026-26190889.80.36912026-02-13
CVE-2026-30824889.80.36252026-03-07
CVE-2026-27966879.80.33692026-02-26
CVE-2025-11201869.80.27032025-10-29
CVE-2025-5120 8610.00.19532025-07-27
CVE-2025-2828 8510.00.15882025-06-23

Sample CVE Deep-Dives

→ Three representative CVEs — one each from Agent Protocols, Deep Learning Frameworks, and Enterprise AI Assistants — selected as the highest-priority CVE in each category that has a complete AI-generated security summary on file.
CVE-2025-11749 AI Agent Protocols and Integrations
Risk Priority: 97 CVSS: 9.8 EPSS: 0.7476 Published: 2025-11-05

The AI Engine plugin for WordPress is vulnerable to sensitive information exposure in all versions through 3.1.3. The flaw resides in the /mcp/v1/ REST API endpoint, which leaks the configured Bearer Token value whenever the No-Auth URL feature is enabled, corresponding to CWE-200.

Full CVE detail page →
CVE-2025-1550 Deep Learning Frameworks
Risk Priority: 76 CVSS: 9.8 EPSS: 0.0258 Published: 2025-03-11

The vulnerability affects the Keras deep learning framework's Model.load_model function. A manually crafted malicious .keras archive can bypass the safe_mode=True setting by embedding attacker-controlled entries in its config.json file, causing arbitrary Python modules and functions to be imported and executed during deserialization.

Full CVE detail page →
CVE-2025-12420 Enterprise AI Assistants
Risk Priority: 91 CVSS: 9.8 EPSS: 0.4607 Published: 2026-01-12

CVE-2025-12420, published on 2026-01-12, is a critical vulnerability (CVSS 9.8; CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in the ServiceNow AI Platform, associated with CWE-250. The flaw enables an unauthenticated user to impersonate another user and perform any operations that the impersonated user is entitled to execute.

Full CVE detail page →

Recommendations — Software Producers

Prioritise defence against the dominant weakness classes in AI-related software. Through 2026 these are OS command injection (CWE-78), command injection (CWE-77), server-side request forgery (CWE-918, newly prominent in 2026), path traversal (CWE-22), and cross-site scripting (CWE-79).

Avoid passing user-controlled or LLM-generated text directly to shell commands or HTTP fetchers. Use built-in libraries or APIs, parameterise subprocess invocations, and explicitly enumerate allowed hosts for any outbound HTTP. Add tool sandboxing, least- privilege token scoping, and signed tool manifests for any agentic component that delegates execution. Mandate human approval gates for sensitive actions and log every tool invocation.

Recommendations — Enterprises (Software Consumers)

Request penetration test results from AI-software vendors with explicit coverage of injection (CWE-77/CWE-78), SSRF (CWE-918), path traversal (CWE-22), XSS (CWE-79), and authorisation flaws (CWE-862, CWE-284). For self-hosted AI components, run independent fuzzing against tool interfaces and prompt-injection vectors.

Track the EPSS-driven Risk Priority of CVEs in your AI software stack (see the table above) and treat ransomware-linked KEVs as immediate- remediation. For agentic AI specifically, evaluate platforms providing tool discovery, real-time monitoring, and policy-based execution control as a layer over generic application security.

Future Work

Two analyses depend on annotation coverage that's still maturing: MITRE ATLAS technique mapping (the AI-specific adversarial framework) and OWASP Top 10 for LLMs 2025 categorisation. Once enough 2026 CVEs are processed by our QA tools we'll add tabs covering both. Threat-actor attribution for AI vulnerabilities remains sparse in public reporting and will be incorporated as data improves.