A real-time, data-driven look at the vulnerability landscape for AI agents, LLMs, and MCP. Tracked continuously from CISA KEV and NVD feeds, filtered for what actually matters to teams shipping agents in production.
Data updated daily · 6:00 AM CTAI/agent-relevant CVEs broken down by category over the tracking window.
Retrieval-augmented generation vulnerabilities now dwarf every other agent-security category in our feed. If you connect an agent to a vector database or knowledge base, that retrieval layer is the most likely place an injection lands.
Model Context Protocol — the standard connecting agents to tools — is showing up as a distinct CVE category. Every tool your agent can call is a potential privilege boundary, and MCP tool-abuse vectors are the ones teams most often miss.
51 AI/agent-relevant entries sit in CISA's known-exploited catalog. When a vulnerability is in KEV, it's being actively exploited in the wild — not theoretical. That's the number to watch for urgency.
| CVE | Date | Category |
|---|---|---|
CVE-2026-70619 | 2026-08-04 | RAG |
CVE-2026-45538 | 2026-08-04 | MCP / Agent |
CVE-2026-70477 | 2026-08-04 | Prompt Injection |
CVE-2026-70478 | 2026-08-04 | LLM |
CVE-2026-70492 | 2026-08-04 | RAG |
CVE-2026-67979 | 2026-08-04 | RAG |
CVE-2026-47682 | 2026-08-04 | RAG |
CVE-2026-70474 | 2026-08-04 | RAG |
CVE-2026-70486 | 2026-08-04 | RAG |
CVE-2026-70485 | 2026-08-04 | RAG |
Full dataset tracked locally. This page shows the most recent high-signal entries.
This is the industry picture. The only way to know your own exposure is to test it — against the same attack classes driving these CVEs.
Book a Free 15-Min Audit → Or run your system prompt through the free AI System Prompt Scanner