AI & ML
4,501 CVEs tracked since 2001. In the last 12 months, 2,052, +145% on the 12 before.
AI & ML by subsector, Sep 2026 so far
- Agent tooling12465% · 16 vendors
- LLM serving & inference4524% · 18 vendors
- ML frameworks137% · 11 vendors
Also: Notebooks & MLOps 7, Vector DBs & RAG 1.
Month by month
Every monthly snapshot of AI & ML. A column is the CVEs published that month.
| Month | CVEs |
|---|---|
| 2021-08 | 63 |
| 2021-09 | 8 |
| 2021-10 | 8 |
| 2021-11 | 45 |
| 2021-12 | 11 |
| 2022-01 | 9 |
| 2022-02 | 38 |
| 2022-03 | 9 |
| 2022-04 | 0 |
| 2022-05 | 26 |
| 2022-06 | 14 |
| 2022-07 | 13 |
| 2022-08 | 4 |
| 2022-09 | 64 |
| 2022-10 | 9 |
| 2022-11 | 39 |
| 2022-12 | 9 |
| 2023-01 | 6 |
| 2023-02 | 9 |
| 2023-03 | 0 |
| 2023-04 | 14 |
| 2023-05 | 20 |
| 2023-06 | 31 |
| 2023-07 | 23 |
| 2023-08 | 27 |
| 2023-09 | 40 |
| 2023-10 | 14 |
| 2023-11 | 21 |
| 2023-12 | 31 |
| 2024-01 | 50 |
| 2024-02 | 43 |
| 2024-03 | 34 |
| 2024-04 | 96 |
| 2024-05 | 51 |
| 2024-06 | 171 |
| 2024-07 | 43 |
| 2024-08 | 26 |
| 2024-09 | 51 |
| 2024-10 | 72 |
| 2024-11 | 44 |
| 2024-12 | 30 |
| 2025-01 | 50 |
| 2025-02 | 21 |
| 2025-03 | 315 |
| 2025-04 | 43 |
| 2025-05 | 53 |
| 2025-06 | 41 |
| 2025-07 | 72 |
| 2025-08 | 44 |
| 2025-09 | 79 |
| 2025-10 | 57 |
| 2025-11 | 49 |
| 2025-12 | 80 |
| 2026-01 | 113 |
| 2026-02 | 99 |
| 2026-03 | 202 |
| 2026-04 | 249 |
| 2026-05 | 274 |
| 2026-06 | 272 |
| 2026-07 | 300 |
| 2026-08 | 278 |
| 2026-09 | 190 |
Vendors
Who shipped the most AI & ML CVEs in Sep 2026 so far, with their rank across all vendors.
Weaknesses
The weakness classes behind AI & ML CVEs in Sep 2026 so far.
Latest CVEs
The 15 most recently published vulnerabilities in AI & ML.
- CVE-2026-100846MONAI before 1.5.2 Remote Code Execution via Pickle Deserialization7.6
- CVE-2026-100845MONAI before 1.6.0 Remote Code Execution via NumpyReader7.8
- CVE-2026-100844MONAI before 1.6.0 OS Command Injection via dataset_name_or_id8.4
- CVE-2026-100842MONAI through 1.6.0 _get_fake_spatial_shape eval() Sandbox Bypass via Attribute Chains7.0
- CVE-2026-100843MONAI before 1.6.0 Remote Code Execution via algo_from_pickle7.8
- CVE-2026-100841MONAI 1.6.0 PersistentDataset Remote Code Execution via Pickle Cache7.8
- CVE-2026-100840MONAI through 1.6.0 Remote Code Execution via bundle configuration7.8
- CVE-2026-100654vLLM before 0.29.0 Denial of Service via out-of-range stop_token_ids6.5
- CVE-2026-100653vLLM 0.22.1 before 0.28.0 Incomplete Artifact Pin Propagation6.5
- CVE-2026-100651vllm before 0.29.0 Denial of Service via Decoder Prompt Length Bypass6.5
- CVE-2026-100652vLLM 0.22.0 through 0.23.0 Denial of Service via stop_token_ids5.9
- CVE-2026-100650vLLM before 0.29.0 Resource Exhaustion via Unbounded Media Materialization6.5
- CVE-2026-100649vLLM before 0.29.0 Resource Limit Bypass via Sampler Subclass3.7
- CVE-2026-100648vllm before 0.29.0 Uncontrolled Resource Consumption via Audio Decoding5.3
- CVE-2026-100647vLLM before 0.29.0 CPU Exhaustion via unbounded cache_salt5.3
The record
- Busiest month
- Mar 2025, 315 CVEs
- Sep 2026 so far
- 190 CVEs from 53 vendors
- Deployment
- SaaS, 50%
- Monthly snapshots
- 119 since 2001
Is your business exposed to threats like these?
Discuss a security assessment of your internet-facing systems. Scope, price and timing agreed before testing.
Request an assessment