Synced 02 Aug 2026 16:36 UTC Account
← Home

AI & ML software vulnerabilities

Known CVEs, active exploitation and end-of-life across the AI/ML software stack · 19 tools · 267 tracked CVEs · updated August 2026

The tools behind AI — model servers, training frameworks, orchestration, vector databases and LLM gateways — are software with dependencies, and they get CVEs like anything else (including critical RCE and unsafe-deserialization flaws). This is the independently-verified picture: vulnerabilities, exploitation and support status across the AI/ML stack, from the same sources as the rest of IsItPatched (NVD · CISA KEV · EPSS · endoflife.date).

19
AI/ML tools tracked
267
known CVEs
3
actively exploited (KEV)
ProductTypeScoreCriticalHighCVEsExploited
LiteLLMLiteLLM AI / LLM Gateway 0 5 19 37 ⚡ 3
OpenClawOpenClaw AI / LLM Gateway 5 4 64 119
Claude CodeAnthropic AI / Coding assistant 11 12 10 26
vLLMvLLM AI / ML 20 2 11 24
MLflowMLflow AI / ML 14 6 7 17
NVIDIA Triton Inference ServerNVIDIA AI / ML 44 1 6 10
JupyterLabProject Jupyter AI / ML 32 2 4 8
KerasKeras AI / ML 53 1 4 5
LangChainLangChain AI / ML 66 1 2 4
Microsoft 365 CopilotMicrosoft AI / LLM Gateway 86 1 3
OllamaOllama AI / ML 76 3 3
GradioGradio AI / ML 89 1 3
LlamaIndexLlamaIndex AI / ML 84 2 2
Hugging Face TransformersHugging Face AI / ML 77 1 1 2
RayAnyscale AI / ML 84 2 2
MilvusZilliz AI / ML 82 1 2
TensorFlowGoogle AI / ML
StreamlitSnowflake AI / ML
KubeflowKubeflow AI / ML

Open any product for its full CVE history, the safe version to upgrade to, and a per-version verdict. Scores are scoped to the latest supported release.

Software vulnerabilities vs agentic risk — secure both

This page is the software-composition layer: known vulnerabilities in the AI/ML tools you run. The other half of AI security is agentic runtime risk — how autonomous agents behave (goal hijack, tool misuse, the Lethal Trifecta). They’re complementary:

Frequently asked questions

Does AI/ML software have security vulnerabilities like other software?

Yes. AI and ML tools — model-serving runtimes, training frameworks, orchestration layers, vector databases and LLM gateways — are software with dependencies, and they accrue CVEs like anything else. Some have had critical remote-code-execution and unsafe-deserialization flaws. This page tracks the known, published vulnerabilities across the AI/ML stack.

Which AI/ML tools does IsItPatched track?

As of August 2026 we track 19 AI/ML products — including model servers (vLLM, Triton, Ollama), frameworks (TensorFlow, Keras, Transformers), orchestration (LangChain, LlamaIndex, Ray, MLflow, Kubeflow), apps (Gradio, Streamlit, JupyterLab) and vector/data layers (Milvus) — with 267 tracked CVEs between them.

How is this different from agentic AI security?

This page covers the software-composition layer: known CVEs, active exploitation and end-of-life in the AI/ML tools you run. Agentic AI security covers the runtime behaviour of autonomous agents (goal hijack, tool misuse, the Lethal Trifecta) — scored with AIVSS on our agentic edition. They are complementary: secure the software, and secure the agent behaviour.

How do I check my own AI/ML stack?

Scan your dependency manifest or SBOM with the IsItPatched SBOM scanner for a per-component verdict, monitor specific tools in My Stack for alerts, or open any product below for its full vulnerability history and the safe version to upgrade to.

Independently sourced from public vulnerability data (NVD, CISA KEV, EPSS, endoflife.date). This is the known software-vulnerability picture for these tools — not an assessment of model safety, bias or data governance. See our disclaimer and methodology.