vulnerability GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure A critical vulnerability (CVE-2026-19478) in GitLab, allowing unauthenticated code injection and data manipulation, has been actively exploited shortly after its disclosure. This poses a significant risk to organizations using GitLab, potentially leading to data deletion, fake merge records, and compromised project mai… The Hacker News · Aug 21, 2026 Critical CVE-2026-19478vulnerabilitycode-injectiongraphql
vulnerability Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code Three high-severity vulnerabilities have been discovered in Hugging Face's Diffusers library, allowing attackers to execute arbitrary code within AI model repositories. These flaws bypass the existing security mechanism,… The Hacker News · Aug 3, 2026 High CVE-2026-44827CVE-2026-45804CVE-2026-44513aisecuritypython
threat-intel Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It Researchers at AI Now Institute have demonstrated a significant vulnerability in AI coding agents like Anthropic's Claude Code and OpenAI's Codex. By inserting a seemingly harmless binary disguised within a README file,… The Hacker News · Jul 9, 2026 High CVE-2026-39861aicode-injectionsecurity
vulnerability Siemens Mendix Studio Pro Siemens has issued an advisory regarding a critical file parsing vulnerability in Mendix Studio Pro. Versions prior to V10.24.21 and V11.6.7 are susceptible to code execution if a user opens and runs a maliciously crafte… CISA Advisories · Jul 7, 2026 Critical CVE-2026-48192code-injectionindustrial-control-systemics