ASR AI Security Radar
Back to homepage

Recent AI Security Incidents

This archive includes all published incident pages. Page 18 of 18.

Each page is intended to help a security team answer three questions quickly: why the issue is AI-relevant, what part of the workflow may be exposed, and what actions should happen first.

Selection criteria and correction policy are documented in Methodology & Editorial Policy.

AI security incident: VU#420440: Vulnerable Python version used in Forcepoint One DLP Client

Incident date: January 6, 2026 | Published: February 25, 2026

Overview A vulnerability in the Forcepoint One DLP Client allows bypass of the vendor-implemented Python restrictions designed to prevent arbitrary code execution.

Read details

AI security incident: CVE-2025-67732 (NVD)

Incident date: January 5, 2026 | Published: February 14, 2026

Dify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the frontend, allowing non-administrator users to view and reuse it.

Read details

AI security incident: CVE-2025-68669 (NVD)

Incident date: December 23, 2025 | Published: February 14, 2026

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. In versions 0.15.2 and prior, an RCE vulnerability exists in useMarkdown.

Read details

AI security incident: CVE-2025-66580 (NVD)

Incident date: December 19, 2025 | Published: February 14, 2026

Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. A critical Stored Cross-Site Scripting (XSS) vulnerability exists in versions prior to 0.11.

Read details