Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

AgenticMail Multiple Vulnerabilities Allowing Agent Impersonation and Prompt Injection

Multiple vulnerabilities in AgenticMail packages allow AI agents to impersonate other agents, enumerate tasks, and execute prompt injection attacks. Fixes have been released in versions 0.9.32 and later.

Disclosed 20 July 2026 · Record updated 13 September 2026

Impact

Authenticated agents can enumerate and hijack tasks assigned to other agents; external emails can trigger prompt injection into fully-privileged operator sessions with email sender/subject/preview embedded verbatim in prompts.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-47255
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-57494
  3. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-57495