VulnCheck

6 items · Capability 2 · Defense 2 · Attacks 2 · all entities

A flaw in DeepSeek's agent harness let a sandboxed agent turn its own confinement off with one command

OX Research disclosed CVE-2026-82533 in DeepSeek Harness, in which the local agent-control API “read the 'Host' request header and allowed access if the value was a loopback authority” but “never compared that value with the connection's actual peer address,” so that “a sandboxed AI agent could use a single shell command to call that API and elevate its own session to 'danger-full-access' with approval prompts disabled.” The OpenCVE record, published September 8 with VulnCheck as the assigning authority, covers all versions before 0.1.2-alpha.1 and carries CVSS 9.4 under v4.0 and 9.6 under v3.1. OX says the fix shipped in 0.1.2-alpha.1 on August 27 and that it re-tested the patched build on August 30; it demonstrated the flaw on a default installation and claims no exploitation in the wild.

Reported by researchersOX Security / OpenCVE ↗ ·

Attackers move to mass exploitation of a critical Langflow flaw, harvesting AI and cloud credentials

VulnCheck reported more than 50 exploitation attempts within hours on Aug 30 against CVE-2026-0768, an input-validation flaw in the Langflow AI workflow builder that allows arbitrary Python execution in the context of the root user, rising to more than 360 by Sep 1. VulnCheck's Caitlin Condon says attackers queried environment variables including LANGFLOW_SUPERUSER and OpenAI and AWS credentials, read the cached Langflow secret key and checked SSH access and bash history, then dropped Python credential harvesters and proxy agents, deployed XMR miners and disabled audit logging.

Reported by pressVulnCheck (via The Hacker News) ↗ ·

VulnCheck logs more than 15,000 successful exploitation attempts against Langflow

VulnCheck reports its canaries recorded over 15,000 successful attempts against Langflow leveraging three CVEs, with one attacker deploying credential harvesters, proxy agents and remote-access software with IRC command and control and cron persistence, and a second deploying cryptocurrency miners, SOCKS5 tunnels and disabled audit logging before pivoting to scan further targets. It states that before 2026 only one Langflow vulnerability was known to be exploited in the wild, and that eleven more have been reported exploited during 2026.

Reported by researchersVulnCheck ↗ ·

VulnCheck says AI write-ups and placeholders now outnumber working exploits in public proof-of-concept repositories

VulnCheck reviewed about 20,000 public exploits and vulnerability analyses in 2025 and more than 17,800 proof-of-concept submissions by mid-August 2026, with its GitHub acceptance rate falling to roughly 45% from about 51% over the past couple of years. It says the leading rejection reason is a repository that “contains no exploit code to begin with,” and that “stylized AI write-ups and placeholders are more common than actual AI PoCs, fake or otherwise.”

Reported by researchersVulnCheck ↗ ·

METR finds vulnerability disclosures rising far faster than confirmed exploitation

METR reports cURL CVEs rising from 9 in 2025 to 36 through mid-2026 with 15 of the 36 AI-marked, OpenSSL from 6 to 39 through early August 2026 with 18 corroborated as AI discoveries, Firefox from 210 to 342 with 11% AI-marked, and Microsoft security-update CVEs from 1,243 to 1,927 with 26 carrying any AI marker. It reports VulnCheck known-exploited entries growing about 10% against 45% growth in CVE volume, a drop in the exploited-to-disclosed ratio.

Reported by researchersMETR ↗ ·

VulnCheck finds AI-discovered vulnerabilities are exploited in the wild at the same low rate as any other

In its State of Exploitation report for the first half of 2026, VulnCheck found that of 1,061 vulnerabilities attributed to AI-assisted discovery, 14 — about 1.3% — were confirmed exploited in the wild, matching the overall exploitation rate for the period. The firm concluded that AI is so far increasing the volume of vulnerabilities discovered rather than the share attackers actually use.

Reported by researchersVulnCheck ↗ ·