Monthly CVE disclosures doubled in 2026, and half of AI-discovered vulnerabilities lead to remote code execution.
GTIG investigated vulnerability disclosure and exploitation statistics and found that AI is measurably changing the pace of vulnerability discovery, exploitation, and the types of vulnerabilities ...
The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a case of static code injection. It has been patched in N-central 2026.3 Hotfix 4 , released on ...
GitLab Patches Critical AI Gateway RCE Vulnerability — Prompt Template Sandbox Escape Rated CVSS 9.9
The first critical remote code execution vulnerability in an AI-specific infrastructure component uses Jinja2 template injection to break out of the sandbox. Self-hosted GitLab instances are exposed; ...
Microsoft has pushed back against claims that multiple prompt injection and sandbox-related issues raised by a security engineer in its Copilot AI assistant constitute security vulnerabilities. The ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results