Agentic AI & MCP Vulnerability Dashboard
Report v4.11 · Last refreshed:
July 21, 2026
· Weekly refresh (July 20 → 21) · Lead (v4.11):
+5 §8 rows
(roster 244 → 249; all human/no-AI, AI-discovered unchanged at 24). New:
LightRAG
auth-bypass (Critical),
Network-AI ApprovalInbox
missing-auth,
Android AI-agent invisible-text → host RCE
(5 OSS frameworks),
vLLM M-RoPE DoS
+
NVIDIA TensorRT
deser (§8.GPU). Enriched:
JADEPUFFER→ENCFORGE
(AI-model-destroying ransomware) + Bit2Watt. ⭐ Week's signal:
AI-VR cost-curve convergence
(VRL/Quantro $2.83·11min, Aikido 88.5%+GLM-5.2, Tenzai $225, NVIDIA 30B-OSS). Use the
Lane:
filter to slice · Source:
Agentic-AI-MCP-Security-Research-Report.md
Built by
Zubair Ashraf
Latest run (July 13–19 — v4.3/v4.4 + v4.6 fold + v4.7 lanes)
Cumulative (all findings)
Themes & Watchlist
People & Orgs
New Critical
—
CVSS 9.0+
New High
—
CVSS 7.0–8.9
New Medium
—
CVSS 4.0–6.9
New Low/Info
—
CVSS <4.0
New Tools
—
Defense + scanners
Researcher Posts
—
Tracked sources
Headline findings — May 8 PM → May 12, 2026
New vulnerabilities this cycle
Severity
ID / Title
Component
Class
Date
Notes
New tools released this cycle
Tool
Maintainer
Date
What it does
Researcher / org activity this cycle
Source
Date
Title
All Critical
—
All High
—
All Medium
—
All Low/Info
—
Total tracked
—
Tracked tools
—
Severity distribution
Findings by month
AI-Discovery Roster — CVE counts per AI system
Tally of catalog entries credited to each AI system. Click a chip below to filter the table. Source: Section 8.99 of the report.
All vulnerabilities tracked
Sev
ID / Title
Component
Class
Discoverer
AI Discovery
Refs
Date
Cross-cutting themes (active)
Watchlist — uncorroborated this cycle
Organic research gaps (cumulative)
Tracked researchers & organizations