Saturday, 19 September 2026
2 agent hacks today 6 vs yesterday (8)

Incident database

Structured records of AI agent security incidents: what happened, which vendor and agent type, the root cause, and every source we used. Filter, browse, or download as CSV.

Incidents by month, 2026 · 459 total · click a month to filter
Jan 2026: 23 incidents23JanFeb 2026: 26 incidents26FebMar 2026: 46 incidents46MarApr 2026: 46 incidents46AprMay 2026: 53 incidents53MayJun 2026: 51 incidents51JunJul 2026: 46 incidents46JulAug 2026: 82 incidents82AugSep 2026: 86 incidents86SepOct 2026: 0 incidents0OctNov 2026: 0 incidents0NovDec 2026: 0 incidents0Dec

Highlighted: incidents recorded on 19 September 2026, shown in place among all incidents.Clear

478 incidents

Incident dateIncidentVendorAgentRoot causeSeverityStatus
19 Sept 2026Claude Opus 5 Helped Researchers Hijack OpenAI Staff Accounts via Chained FlawsOpenAIothermisconfigurationconfirmed
18 Sept 2026Critical Orkes Conductor RCE Vulnerability Exploited in AttacksOrkesworkflowunknownconfirmed
18 Sept 2026Prompt Injection Flaw in AWS AgentCore Harness Can Leak CredentialsAWSotherprompt injectionconfirmed
18 Sept 2026ToolHive containerized MCP servers bypass isolation via host.docker.internalStacklokothermisconfigurationconfirmed
18 Sept 2026AI Agent Used to Breach Spanish Organization, Alter Personal Dataotherunknownconfirmed
18 Sept 2026Plugin4Shell Flaw Lets Attackers Swap Pinned Plugins in AI Coding AgentsAnthropic, OpenAI, GitHubcodingsupply chainconfirmed
18 Sept 2026Microsoft Patches CVSS 10.0 Azure AI Foundry Privilege Escalation FlawMicrosoftothermisconfigurationresolved
18 Sept 2026Process Compose DNS rebinding vulnerability in MCP SSEF1bonacc1workflowmisconfigurationconfirmed
17 Sept 2026Skipper OPA body-authz bypass with chunked/HTTP-2 requestsZalandoothermisconfigurationconfirmed
17 Sept 2026New RatHat Android Malware Uses AI to Automate Device Controlotherunknownconfirmed
17 Sept 2026Zero-click 'Plugin4Shell' RCE flaw found in major AI coding agentsMultiple (Anthropic, OpenAI, Google, Microsoft)codingsupply chainconfirmed
17 Sept 2026Research Shows AI Agents Can Retrain Own Models Mid-TaskIrregularothertool misuseconfirmed
16 Sept 2026Single Browser Extension Could Hijack AI Assistants in Five BrowsersGoogle, Microsoft, Opera, Anthropic, Perplexitybrowsingexcessive permissionsconfirmed
16 Sept 2026RMCP Unauthenticated Session-Table Leak DoS (CVE-2026-63128)rmcpothermisconfigurationconfirmed
16 Sept 2026Spain's AEPD Receives First AI-Powered Data Breach Reportotherunknownconfirmed
16 Sept 2026Attacker Hijacks AI Coding Assistant, Spreads Shai-Hulud Wormcodingsupply chainconfirmed
16 Sept 2026AI Agent-Driven Data Breach Reported to Spanish Regulatorotherunknownconfirmed
16 Sept 2026BragJack Attack Hijacks Browser Agentic AI Assistantsbrowsingunknownconfirmed
16 Sept 2026vLLM unauthenticated audio decompression-bomb DoS in /v1/chat/completionsvLLMothermisconfigurationconfirmed
15 Sept 2026@zereight/mcp-gitlab Multiple Safety Control Bypasseszereightotherprompt injectionconfirmed
15 Sept 2026Contentful MCP Server Prompt Injection via Network OptionsContentfulcodingprompt injectionresolved
14 Sept 2026AI agent used in first AI-aided data breach reported in Spainothertool misuseconfirmed
14 Sept 2026ESPHome Device Builder: Auth env vars rename silently disables dashboard authenticationESPHomeothermisconfigurationconfirmed
12 Sept 2026MCPHub OAuth 2.0 authentication bypass vulnerabilityMCPHubothermisconfigurationconfirmed
11 Sept 2026CVE-2026-59973: SSRF fix bypass in FrontMCP and mcp-from-openapi OpenAPI $ref handlingFrontMCPothersupply chainconfirmed
11 Sept 2026MySQL MCP Server SSE transport allows unauthenticated SQL execution (CVE-2026-59971)mysql-mcp-serverworkflowmisconfigurationresolved
11 Sept 2026Threat actors abused Anthropic's Claude to extract secrets from 1.8M Android appsAnthropicothertool misuseconfirmed
11 Sept 2026Multiple vulnerabilities in IBM Langflow OSS 1.0.0-1.11.5IBMworkflowexcessive permissionsconfirmed
10 Sept 2026Path Injection in n8n Elasticsearch and ElasticSecurity Nodesn8nworkflowtool misuseresolved
10 Sept 2026OmniRoute RCE via unauthenticated POST /api/acp/agents endpointOmniRouteotherexcessive permissionsconfirmed
10 Sept 2026n8n Multiple Vulnerabilities in Workflow Execution and Access Controln8nworkflowmisconfigurationconfirmed
10 Sept 2026AWS Security Agent MCP Server S3 Bucket Ownership Verification MissingAWSothermisconfigurationconfirmed
10 Sept 2026Command injection in Tianxi AI Agent PC ApplicationLenovoothertool misuseconfirmed
9 Sept 2026functype-mcp-server RCE via unsanitized pnpm installfunctype-mcp-serverworkflowprompt injectionconfirmed
9 Sept 2026Open WebUI vulnerabilities allow DoS and message tamperingOpen WebUIothermisconfigurationresolved
8 Sept 2026Covert channel in ChatGPT's internal Artifactory enabled cross-account Gmail data theftOpenAIotherprompt injectionresolved
8 Sept 2026Okta Hyperdrive agent plugin authentication and logging vulnerabilitiesOktaothermisconfigurationconfirmed
8 Sept 2026Roo-Code auto-approve bypass vulnerabilities in shell command parsingRoo-Codecodingexcessive permissionsconfirmed
8 Sept 2026ASUS Control Center Express Agent missing authentication vulnerabilityASUSothermisconfigurationconfirmed
8 Sept 2026Command injection and credential exposure in GitHub Copilot and Visual Studio CodeMicrosoftcodingprompt injectionconfirmed
7 Sept 2026knowns path traversal vulnerabilities in MCP tool argumentsknowns-devcodingtool misuseconfirmed
7 Sept 2026Eclipse Ankaios wildcard authorization bypass in Control InterfaceEclipse Ankaiosothermisconfigurationconfirmed
5 Sept 2026AVideo API rate limit bypass via bot User-Agent headerAVideoothermisconfigurationreported
5 Sept 2026Rowboat fails to validate custom MCP server and webhook URLsRowboat Labsworkflowmisconfigurationreported
4 Sept 2026git-mcp-server argument injection in git toolsgit-mcp-servercodingprompt injectionreported
4 Sept 2026Postgres MCP Pro 0.3.0 restricted-mode bypass via RangeFunctionPostgres MCP Procodingmisconfigurationreported
4 Sept 2026Arbitrary local file read in firecrawl-mcp-server 3.20.2firecrawlcodingexcessive permissionsreported
4 Sept 2026xiaobei webhook endpoint lacks authentication, allows SSRF attacksxiaobeiworkflowmisconfigurationreported
4 Sept 2026LaVague 0.2.35 Remote Code Execution via Prompt InjectionLaVaguecodingprompt injectionreported
4 Sept 2026Multiple vulnerabilities in Amazon AWS Labs MCP serversAmazonworkflowprompt injectionconfirmed