Exploits and vulnerabilities in Q2 2026
This report covers statistics on vulnerabilities, exploits, and C2 frameworks in Q2 2026. For the first time ever, we aggregate data on vulnerabilities in open-source AI agents and AI frameworks.
CISA has issued a warning regarding active exploitation of CVE-2024-60004, a critical remote code execution vulnerability in Gitea (CVSS 9.8) that allows attackers with repository write access to execute arbitrary shell commands. Threat actors are actively leveraging this recently patched flaw to deploy miner-like payloads against vulnerable instances. Organizations running Gitea should prioritize patching to mitigate the risk of compromise.
Read full article at The Hacker News ↗This report covers statistics on vulnerabilities, exploits, and C2 frameworks in Q2 2026. For the first time ever, we aggregate data on vulnerabilities in open-source AI agents and AI frameworks.
CVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1.27.1. The post CISA Warns of Exploited Gitea Vulnerability appeared first on SecurityWeek.
Gartner's survey of 316 companies ranked AI-driven vulnerability discovery as the highest-impact emerging cybersecurity risk, a significant shift from the previous quarter when information integrity risk topped the list. The change reflects growing concern among risk managers and executives about AI systems' capability to identify previously unknown flaws at scale. This marks a notable reassessment of threat priorities as organizations grapple with the dual-edged nature of AI in both attack and defense scenarios.
Attackers can exploit a networking vulnerability in NVIDIA's OpenClaw tool to gain unauthenticated access to the local model server via the Ollama API, enabling persistent corruption of AI agents. The flaw allows threat actors to conduct LLM poisoning attacks by manipulating the underlying model through this unprotected interface. This attack vector poses significant risks to organizations deploying NVIDIA's AI tools in production environments.