Agentic AI & MCP Vulnerability Dashboard

Report v4.11 · Last refreshed: July 21, 2026 · Weekly refresh (July 20 → 21) · Lead (v4.11): +5 §8 rows (roster 244 → 249; all human/no-AI, AI-discovered unchanged at 24). New: LightRAG auth-bypass (Critical), Network-AI ApprovalInbox missing-auth, Android AI-agent invisible-text → host RCE (5 OSS frameworks), vLLM M-RoPE DoS + NVIDIA TensorRT deser (§8.GPU). Enriched: JADEPUFFER→ENCFORGE (AI-model-destroying ransomware) + Bit2Watt. ⭐ Week's signal: AI-VR cost-curve convergence (VRL/Quantro $2.83·11min, Aikido 88.5%+GLM-5.2, Tenzai $225, NVIDIA 30B-OSS). Use the Lane: filter to slice · Source: Agentic-AI-MCP-Security-Research-Report.md
Built by Zubair Ashraf
Latest run (July 13–19 — v4.3/v4.4 + v4.6 fold + v4.7 lanes)
Cumulative (all findings)
Themes & Watchlist
People & Orgs
New Critical
CVSS 9.0+
New High
CVSS 7.0–8.9
New Medium
CVSS 4.0–6.9
New Low/Info
CVSS <4.0
New Tools
Defense + scanners
Researcher Posts
Tracked sources

Headline findings — May 8 PM → May 12, 2026

    New vulnerabilities this cycle

    SeverityID / TitleComponentClassDateNotes

    New tools released this cycle

    ToolMaintainerDateWhat it does

    Researcher / org activity this cycle

    SourceDateTitle