<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://exploit-radar.com/en/flux/categories/ia.xml</id>
  <title>Exploit Radar: AI and automation</title>
  <subtitle>The latest additions to CISA’s catalog of exploited vulnerabilities in the “AI and automation” category (indicative classification).</subtitle>
  <link rel="self" type="application/atom+xml" href="https://exploit-radar.com/en/flux/categories/ia.xml"/>
  <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/produits/ia/"/>
  <updated>2026-09-02T00:00:00Z</updated>
  <author><name>Exploit Radar</name></author>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-49869/</id>
    <title>CVE-2026-49869 — Kestra OSS</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-49869/"/>
    <updated>2026-09-02T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Kestra; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 2, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-59822/</id>
    <title>CVE-2026-59822 — BerriAI LiteLLM</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-59822/"/>
    <updated>2026-09-02T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from BerriAI; if none are available, stop using the product. Start with internet-facing devices. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on September 2, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-64849/</id>
    <title>CVE-2026-64849 — MLflow</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-64849/"/>
    <updated>2026-08-19T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from MLflow; if none are available, stop using the product. Start with internet-facing devices. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on August 19, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-62593/</id>
    <title>CVE-2025-62593 — Ray</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-62593/"/>
    <updated>2026-08-17T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Ray; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on August 17, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-9198/</id>
    <title>CVE-2026-9198 — Langflow</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-9198/"/>
    <updated>2026-08-04T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Langflow; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on August 4, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-0770/</id>
    <title>CVE-2026-0770 — Langflow</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-0770/"/>
    <updated>2026-07-21T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Langflow; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on July 21, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-55255/</id>
    <title>CVE-2026-55255 — Langflow</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-55255/"/>
    <updated>2026-07-07T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Langflow; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on July 7, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-42271/</id>
    <title>CVE-2026-42271 — BerriAI LiteLLM</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-42271/"/>
    <updated>2026-06-08T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from BerriAI; if none are available, stop using the product. For cloud services, follow the guidance from BerriAI. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on June 8, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-34291/</id>
    <title>CVE-2025-34291 — Langflow</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-34291/"/>
    <updated>2026-05-21T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Langflow; if none are available, stop using the product. For cloud services, follow the guidance from Langflow. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on May 21, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-42208/</id>
    <title>CVE-2026-42208 — BerriAI LiteLLM</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-42208/"/>
    <updated>2026-05-08T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from BerriAI; if none are available, stop using the product. For cloud services, follow the guidance from BerriAI. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on May 8, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-39987/</id>
    <title>CVE-2026-39987 — Marimo</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-39987/"/>
    <updated>2026-04-23T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Marimo; if none are available, stop using the product. For cloud services, follow the guidance from Marimo. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on April 23, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-33017/</id>
    <title>CVE-2026-33017 — Langflow</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-33017/"/>
    <updated>2026-03-25T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Langflow; if none are available, stop using the product. For cloud services, follow the guidance from Langflow. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on March 25, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-68613/</id>
    <title>CVE-2025-68613 — n8n</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-68613/"/>
    <updated>2026-03-11T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from n8n; if none are available, stop using the product. For cloud services, follow the guidance from n8n. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on March 11, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-3248/</id>
    <title>CVE-2025-3248 — Langflow</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-3248/"/>
    <updated>2025-05-05T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Langflow; if none are available, stop using the product. For cloud services, follow the guidance from Langflow. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on May 5, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2020-13927/</id>
    <title>CVE-2020-13927 — Apache Airflow</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2020-13927/"/>
    <updated>2022-01-18T00:00:00Z</updated>
    <summary type="text">Apply the security update from Apache. CISA deadline: 181 days. Added to CISA’s catalog of exploited vulnerabilities on January 18, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2020-11978/</id>
    <title>CVE-2020-11978 — Apache Airflow</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2020-11978/"/>
    <updated>2022-01-18T00:00:00Z</updated>
    <summary type="text">Apply the security update from Apache. CISA deadline: 181 days. Added to CISA’s catalog of exploited vulnerabilities on January 18, 2022.</summary>
  </entry>
</feed>
