| 19 Sept 2026 | Claude Opus 5 Helped Researchers Hijack OpenAI Staff Accounts via Chained Flaws | OpenAI | other | misconfiguration | | confirmed |
| 18 Sept 2026 | Critical Orkes Conductor RCE Vulnerability Exploited in Attacks | Orkes | workflow | unknown | | confirmed |
| 18 Sept 2026 | Prompt Injection Flaw in AWS AgentCore Harness Can Leak Credentials | AWS | other | prompt injection | | confirmed |
| 18 Sept 2026 | ToolHive containerized MCP servers bypass isolation via host.docker.internal | Stacklok | other | misconfiguration | | confirmed |
| 18 Sept 2026 | AI Agent Used to Breach Spanish Organization, Alter Personal Data | | other | unknown | | confirmed |
| 18 Sept 2026 | Plugin4Shell Flaw Lets Attackers Swap Pinned Plugins in AI Coding Agents | Anthropic, OpenAI, GitHub | coding | supply chain | | confirmed |
| 18 Sept 2026 | Microsoft Patches CVSS 10.0 Azure AI Foundry Privilege Escalation Flaw | Microsoft | other | misconfiguration | | resolved |
| 18 Sept 2026 | Process Compose DNS rebinding vulnerability in MCP SSE | F1bonacc1 | workflow | misconfiguration | | confirmed |
| 17 Sept 2026 | Skipper OPA body-authz bypass with chunked/HTTP-2 requests | Zalando | other | misconfiguration | | confirmed |
| 17 Sept 2026 | New RatHat Android Malware Uses AI to Automate Device Control | | other | unknown | | confirmed |
| 17 Sept 2026 | Zero-click 'Plugin4Shell' RCE flaw found in major AI coding agents | Multiple (Anthropic, OpenAI, Google, Microsoft) | coding | supply chain | | confirmed |
| 17 Sept 2026 | Research Shows AI Agents Can Retrain Own Models Mid-Task | Irregular | other | tool misuse | | confirmed |
| 16 Sept 2026 | Single Browser Extension Could Hijack AI Assistants in Five Browsers | Google, Microsoft, Opera, Anthropic, Perplexity | browsing | excessive permissions | | confirmed |
| 16 Sept 2026 | RMCP Unauthenticated Session-Table Leak DoS (CVE-2026-63128) | rmcp | other | misconfiguration | | confirmed |
| 16 Sept 2026 | Spain's AEPD Receives First AI-Powered Data Breach Report | | other | unknown | | confirmed |
| 16 Sept 2026 | Attacker Hijacks AI Coding Assistant, Spreads Shai-Hulud Worm | | coding | supply chain | | confirmed |
| 16 Sept 2026 | AI Agent-Driven Data Breach Reported to Spanish Regulator | | other | unknown | | confirmed |
| 16 Sept 2026 | BragJack Attack Hijacks Browser Agentic AI Assistants | | browsing | unknown | | confirmed |
| 16 Sept 2026 | vLLM unauthenticated audio decompression-bomb DoS in /v1/chat/completions | vLLM | other | misconfiguration | | confirmed |
| 15 Sept 2026 | @zereight/mcp-gitlab Multiple Safety Control Bypasses | zereight | other | prompt injection | | confirmed |
| 15 Sept 2026 | Contentful MCP Server Prompt Injection via Network Options | Contentful | coding | prompt injection | | resolved |
| 14 Sept 2026 | AI agent used in first AI-aided data breach reported in Spain | | other | tool misuse | | confirmed |
| 14 Sept 2026 | ESPHome Device Builder: Auth env vars rename silently disables dashboard authentication | ESPHome | other | misconfiguration | | confirmed |
| 12 Sept 2026 | MCPHub OAuth 2.0 authentication bypass vulnerability | MCPHub | other | misconfiguration | | confirmed |
| 11 Sept 2026 | CVE-2026-59973: SSRF fix bypass in FrontMCP and mcp-from-openapi OpenAPI $ref handling | FrontMCP | other | supply chain | | confirmed |
| 11 Sept 2026 | MySQL MCP Server SSE transport allows unauthenticated SQL execution (CVE-2026-59971) | mysql-mcp-server | workflow | misconfiguration | | resolved |
| 11 Sept 2026 | Threat actors abused Anthropic's Claude to extract secrets from 1.8M Android apps | Anthropic | other | tool misuse | | confirmed |
| 11 Sept 2026 | Multiple vulnerabilities in IBM Langflow OSS 1.0.0-1.11.5 | IBM | workflow | excessive permissions | | confirmed |
| 10 Sept 2026 | Path Injection in n8n Elasticsearch and ElasticSecurity Nodes | n8n | workflow | tool misuse | | resolved |
| 10 Sept 2026 | OmniRoute RCE via unauthenticated POST /api/acp/agents endpoint | OmniRoute | other | excessive permissions | | confirmed |
| 10 Sept 2026 | n8n Multiple Vulnerabilities in Workflow Execution and Access Control | n8n | workflow | misconfiguration | | confirmed |
| 10 Sept 2026 | AWS Security Agent MCP Server S3 Bucket Ownership Verification Missing | AWS | other | misconfiguration | | confirmed |
| 10 Sept 2026 | Command injection in Tianxi AI Agent PC Application | Lenovo | other | tool misuse | | confirmed |
| 9 Sept 2026 | functype-mcp-server RCE via unsanitized pnpm install | functype-mcp-server | workflow | prompt injection | | confirmed |
| 9 Sept 2026 | Open WebUI vulnerabilities allow DoS and message tampering | Open WebUI | other | misconfiguration | | resolved |
| 8 Sept 2026 | Covert channel in ChatGPT's internal Artifactory enabled cross-account Gmail data theft | OpenAI | other | prompt injection | | resolved |
| 8 Sept 2026 | Okta Hyperdrive agent plugin authentication and logging vulnerabilities | Okta | other | misconfiguration | | confirmed |
| 8 Sept 2026 | Roo-Code auto-approve bypass vulnerabilities in shell command parsing | Roo-Code | coding | excessive permissions | | confirmed |
| 8 Sept 2026 | ASUS Control Center Express Agent missing authentication vulnerability | ASUS | other | misconfiguration | | confirmed |
| 8 Sept 2026 | Command injection and credential exposure in GitHub Copilot and Visual Studio Code | Microsoft | coding | prompt injection | | confirmed |
| 7 Sept 2026 | knowns path traversal vulnerabilities in MCP tool arguments | knowns-dev | coding | tool misuse | | confirmed |
| 7 Sept 2026 | Eclipse Ankaios wildcard authorization bypass in Control Interface | Eclipse Ankaios | other | misconfiguration | | confirmed |
| 5 Sept 2026 | AVideo API rate limit bypass via bot User-Agent header | AVideo | other | misconfiguration | | reported |
| 5 Sept 2026 | Rowboat fails to validate custom MCP server and webhook URLs | Rowboat Labs | workflow | misconfiguration | | reported |
| 4 Sept 2026 | git-mcp-server argument injection in git tools | git-mcp-server | coding | prompt injection | | reported |
| 4 Sept 2026 | Postgres MCP Pro 0.3.0 restricted-mode bypass via RangeFunction | Postgres MCP Pro | coding | misconfiguration | | reported |
| 4 Sept 2026 | Arbitrary local file read in firecrawl-mcp-server 3.20.2 | firecrawl | coding | excessive permissions | | reported |
| 4 Sept 2026 | xiaobei webhook endpoint lacks authentication, allows SSRF attacks | xiaobei | workflow | misconfiguration | | reported |
| 4 Sept 2026 | LaVague 0.2.35 Remote Code Execution via Prompt Injection | LaVague | coding | prompt injection | | reported |
| 4 Sept 2026 | Multiple vulnerabilities in Amazon AWS Labs MCP servers | Amazon | workflow | prompt injection | | confirmed |