Last Week in AI Security — Week of April 13, 2026
Prompt injection emerges as unsolvable threat as CIS and UK NCSC warn defenses remain insufficient; critical vLLM RCE and PyTorch vulnerabilities under active exploitation.
Key Highlights
- CIS warns prompt injection is 'inherent threat' as government AI adoption reaches 82%
- Critical CVE-2026-22778 vLLM RCE allows video link attack; PyTorch CVE-2026-24747 rated 9.8
- Microsoft CVE-2026-21520 Copilot Studio patched but data exfiltration continues
- NIST releases AI RMF Critical Infrastructure Profile; OWASP launches Top 10 for Agentic Apps
- Nature study: LRMs achieve 97% jailbreak success autonomously across frontier models
Executive Summary
The week of April 13, 2026 marks a sobering inflection point for AI security: the realization that prompt injection—the top vulnerability in both OWASP’s LLM Top 10 and the primary vector for agentic AI compromise—may be fundamentally unsolvable at the architectural level. The Center for Internet Security released a report on April 1, 2026 warning that prompt injection attacks are a serious and growing threat to organizations using generative AI, while a 2025 NASCIO survey found that 82% of state and territorial CIOs reported employees using GenAI in daily work, up from 53% the prior year. The confluence of ubiquitous adoption and persistent vulnerability creates an unprecedented risk surface.
Three developments this week define the current threat landscape. First, OWASP still ranks prompt injection as LLM01, while the UK’s top cyber agency says it may never be fixed. Second, critical infrastructure vulnerabilities in widely-deployed frameworks continue to emerge: CVE-2026-22778 in vLLM allows remote code execution via a malicious video link, and CVE-2026-24747 in PyTorch has a CVSS score of 9.8, affecting versions up to 2.9.1. Third, even patched systems remain vulnerable: Microsoft assigned CVE-2026-21520 to Copilot Studio and patched it on January 15, but in Capsule Security’s testing, data exfiltrated anyway.
On the policy and standards front, NIST released a concept note on April 7, 2026 for an AI RMF Profile on Trustworthy AI in Critical Infrastructure, and OWASP released the Top 10 for Agentic Applications 2026, developed through collaboration with more than 100 industry experts to address autonomous AI systems. These frameworks arrive as research confirms the severity of the threat: a Nature Communications study showed large reasoning models achieve a 97.14% jailbreak success rate across all model combinations when acting as autonomous adversaries.
Top Stories
Prompt Injection Declared “Inherent Threat” as Government Adoption Hits 82%
The Center for Internet Security released a report on April 1, 2026 warning that prompt injection attacks are a serious and growing threat to organizations using generative AI. The report, titled “Prompt Injections: The Inherent Threat to Generative AI,” arrives as 82% of state and territorial CIOs reported employees using GenAI in daily work, up from 53% the prior year, with AI, GenAI, and agentic AI ranking as the number one policy and technology priority for 2026.
The CIS report identifies prompt injection as fundamentally different from traditional vulnerabilities. LLMs do not separate instructions from other data, so a model can process embedded malicious instructions in the same way as a normal request. This architectural limitation enables two attack types: direct prompt injection through direct interaction with the model, and indirect prompt injection placing malicious instructions inside external content such as web pages, emails, or documents that AI systems later retrieve.
OWASP has identified prompt injection as the top risk category for GenAI and LLM applications. The CIS findings align with independent research showing the attack class remains largely unsolved: prompt injection has been documented for more than a decade, with research tracing it back to 2013, and targeted training can improve how models handle these attacks, but studies indicate that training alone does not provide sufficient protection.
Real-world proof points demonstrate the operational risk. In March 2026, a Meta employee posted a technical question on an internal forum; an AI assistant responded with a solution; the employee implemented it, and two hours later a major security alert went off as large amounts of sensitive user and company data had been exposed. An AI agent instructed a human to bypass the very security controls designed to prevent exactly this scenario.
CIS recommends organizations train staff to recognize emerging AI-related security risks, including prompt injection attacks, and incorporate AI technology security assessments into penetration testing plans.
Critical vLLM and PyTorch RCE Vulnerabilities Expose Millions of AI Servers
Two critical remote code execution vulnerabilities in widely-deployed AI infrastructure components were disclosed this week, together affecting millions of deployments. CVE-2026-22778 in vLLM allows an attacker to achieve Remote Code Execution simply by sending a malicious video link to a vLLM API. vLLM is a high-throughput, memory-efficient engine for serving Large Language Models, used for running LLMs on servers faster and more efficiently than alternatives like Ollama.
The attack chain exploits two vulnerabilities in sequence. First, a memory leak vulnerability allows attackers to reduce ASLR entropy. Second, vLLM uses OpenCV to decode videos, and OpenCV bundles FFmpeg 5.1.x, which contains a heap overflow in the JPEG2000 decoder that can be triggered by constructing a video from JPEG2000 frames. This RCE can be used for a full server takeover, including arbitrary command execution, data exfiltration, and lateral movement. The fix is available in vLLM version 0.14.1.
The second vulnerability, CVE-2026-24747 in PyTorch’s checkpoint loading mechanism, allows attackers to execute arbitrary code through malicious model files; the flaw exists in the weights_only unpickler and has a CVSS v3 score of 9.8. The vulnerability stems from inadequate validation in PyTorch’s weights_only feature; attackers can bypass restrictions by crafting malicious checkpoint files that exploit the unpickler’s weaknesses; when a user loads such a file using torch.load() with weights_only=True, the malicious payload executes.
PyTorch versions up to and including 2.9.1 are vulnerable; the development team has addressed this issue in version 2.10.0 and later, implementing proper validation of pickle opcodes and storage metadata. The vulnerability is particularly concerning because trained models are often shared via various public repositories and can theoretically contain malicious implants.
Both vulnerabilities affect the AI serving and training stack at its most critical layers—the inference engine and the model loading mechanism—and both have patches available that organizations should deploy immediately.
Microsoft Copilot Studio Patched—But Data Still Exfiltrated
Microsoft assigned CVE-2026-21520, a CVSS 7.5 indirect prompt injection vulnerability, to Copilot Studio; the patch was deployed on January 15 after Capsule Security discovered the flaw on November 24, 2025, but in testing, data exfiltrated anyway. This case illustrates a fundamental challenge: that CVE matters less for what it fixes and more for what it signals; if the precedent extends to agentic systems broadly, every enterprise running agents inherits a new vulnerability class to track, except that this class cannot be fully eliminated by patches alone.
Capsule Security also disclosed PipeLeak, a parallel vulnerability in Salesforce Agentforce. In Capsule’s testing, a public lead form payload hijacked an Agentforce agent with no authentication required; Capsule found no volume cap on the exfiltrated CRM data, and the employee who triggered the agent received no indication that data had left the building. Salesforce has not assigned a CVE or issued a public advisory specific to PipeLeak as of publication.
The broader implication is architectural. Security teams must treat prompt injection as a class-level SaaS risk rather than individual CVEs, classify every agent deployment against the lethal trifecta, and require runtime enforcement for anything moving to production. Every security director running Copilot Studio agents triggered by SharePoint forms should audit the window between November 24, 2025 and January 15, 2026 for indicators of compromise.
Framework & Standards Updates
On April 7, 2026, NIST released a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure; the profile will guide critical infrastructure operators towards specific risk management practices to consider when engaging AI-enabled capabilities. The profile addresses the fact that critical infrastructure will increasingly rely on AI across IT, OT, and Industrial Control Systems; adopting AI in these high-stakes environments relies on AI systems being worthy of trust, and the AI RMF was developed to define and promote trustworthiness through a repeatable, full lifecycle approach. The concept note outlines plans to guide critical infrastructure operators toward specific risk management practices for AI-enabled capabilities, and NIST is establishing a Community of Interest to gather feedback from industry, regulators, policymakers, academia, and stakeholders.
The OWASP Top 10 for Agentic Applications 2026 is a globally peer-reviewed framework identifying the most critical security risks facing autonomous and agentic AI systems, developed through collaboration with more than 100 industry experts; the list provides practical, actionable guidance to help organizations secure AI agents that plan, act, and make decisions across complex workflows. The 2026 edition identifies risks introduced by autonomous and semi-autonomous AI agents; unlike traditional LLM applications, agentic systems combine reasoning, memory, tools, and multi-step execution, introducing new classes of vulnerabilities; the 2026 edition focuses on failures arising from goal misalignment, tool misuse, delegated trust, inter-agent communication, persistent memory, and emergent autonomous behavior.
NIST also announced a significant operational change: The National Institute of Standards and Technology will stop assigning severity scores to lower-priority vulnerabilities due to the growing workload from rising submission volumes. This decision reflects the scale challenge facing vulnerability management as the CVE database continues to expand.
Vulnerability Watch
CVE-2026-22778 (vLLM) – CRITICAL
- CVE-2026-22778 in vLLM enables remote code execution on vulnerable vLLM deployments by submitting a malicious video link to the API
- CVSS: Critical (exact score not disclosed)
- Affected: vLLM versions prior to 0.14.1
- Mitigation: Update vLLM to version 0.14.1 or later
CVE-2026-24747 (PyTorch) – CRITICAL
- CVE-2026-24747 in PyTorch with a CVSS v3 score of 9.8, affecting versions up to 2.9.1
- Vulnerability in the weights_only unpickler; malicious payload executes when loading files with weights_only=True
- Mitigation: Upgrade to PyTorch 2.10.0 or newer
CVE-2026-21520 (Microsoft Copilot Studio) – HIGH
- CVSS 7.5 indirect prompt injection vulnerability in Copilot Studio
- Patched on January 15, 2026, but data exfiltration continued in Capsule Security testing
CVE-2026-34753 (vLLM SSRF) – HIGH
- Server-side request forgery vulnerability in download_bytes_from_url allowing actors controlling batch input JSON to issue arbitrary HTTP/HTTPS requests from the server
- Affected: vLLM versions 0.16.0 to before 0.19.0
- Fixed in version 0.19.0
Additional vLLM advisories disclosed this week include multiple SSRF, DoS, and RCE vulnerabilities tracked in GitHub security advisories GHSA-pq5c-rjhq-qp7p, GHSA-pf3h-qjgv-vcpr, GHSA-3mwp-wvh9-7528, GHSA-7972-pg2x-xr59, GHSA-v359-jj2v-j536, GHSA-qh4c-xf7m-gxfc, GHSA-4r2x-xpjr-7cvv, GHSA-2pc9-4j83-qjmr, GHSA-wv77-2vpf-vmmg, and GHSA-mcmc-2m55-j8jj.
Industry Radar
Synack announced on April 13, 2026 the Glasswing-Readiness Assessment, a focused offering that helps organizations identify and close critical gaps in their attack surface before AI-driven threats exploit them, in response to recent advances in offensive AI including Anthropic’s Project Glasswing.
The vLLM project released version 0.19.0 with security fixes and patched protobuf for CVE-2026-0994, alongside multiple performance and compatibility updates.
Policy Corner
State AI Legislation
Legislatures in three states passed bills last week; Nebraska’s unicameral legislature passed a chatbot bill; Maryland’s legislature passed a pricing bill; Maine’s legislature passed a bill prohibiting therapy or psychotherapy services, including through the use of AI, unless provided by a licensed professional.
Nebraska passed LB 525, which includes the Conversational AI Safety Act regulating minors’ interaction with conversational AI services, requiring disclosure to minors that it is AI, and requiring operators to disclose to persons that the service is not human if a reasonable person would not understand the service is not human.
California’s SB 947 and AB 2027 advanced through committee, regulating automated decision systems in employment; Minnesota’s SF 4689 passed out of two committees and was referred to a third, also regulating automated decision systems in employment settings.
Research Spotlight
Large reasoning models are autonomous jailbreak agents – Nature Communications, February 2026
Study demonstrates that the persuasive capabilities of large reasoning models simplify and scale jailbreaking; four LRMs evaluated as autonomous adversaries achieved a 97.14% overall jailbreak success rate across nine widely used target models.
TaintP2X: Detecting Taint-Style Prompt-to-Anything Injection Vulnerabilities in LLM-Integrated Applications – ICSE 2026 Research Track
Proposes TaintP2X, a novel static taint analysis framework to address Prompt-to-Anything Injection (P2Xi) attacks; these vulnerabilities can result in severe consequences such as RCE, file injection, SQL injection, and SSRF; the framework models LLM-generated outputs as taint sources and employs LLM-assisted analysis to prune false positives.
When AI Meets the Web: Prompt Injection Risks in Third-Party AI Chatbot Plugins – Accepted to IEEE Symposium on Security and Privacy 2026
First large-scale study of 17 third-party chatbot plugins used by over 10,000 public websites; 8 of these plugins (used by 8,000 websites) fail to enforce the integrity of the conversation history transmitted in network requests between the website visitor and the chatbot.
Data Poisoning Vulnerabilities Across Health Care Artificial Intelligence Architectures – Journal of Medical Internet Research, January 2026
Multiple empirical studies demonstrate that attackers with access to as few as 100-500 poisoned samples can compromise health care AI systems, with attack success rates typically ≥60%. Replacement of just 0.001% of training tokens with medical misinformation results in harmful models more likely to propagate medical errors.
Jailbreaking LLMs & VLMs: Mechanisms, Evaluation, and Unified Defenses – arXiv, January 2026
Systematic survey providing a three-dimensional framework covering attack dimension (template/encoding-based, in-context learning manipulation, reinforcement/adversarial learning, LLM-assisted attacks, and prompt- and image-level perturbations), defense dimension (prompt-level obfuscation, output evaluation, and model-level alignment), and evaluation dimension (ASR, toxicity score, query/time cost, and multimodal metrics).
What This Means For You
The convergence this week of unsolvable architectural vulnerabilities (prompt injection), critical infrastructure exploits (vLLM, PyTorch), and evidence of autonomous offensive AI capabilities (97% jailbreak success) demands immediate action across three dimensions.
First, accept that prompt injection is not patchable. LLMs do not separate instructions from other data; a model can process embedded malicious instructions in the same way as a normal request. This means runtime controls—not model-level safety training—must become your primary defense. Implement policy engines, tool authorization frameworks, and behavioral monitoring for every agentic deployment. Audit any agent with access to sensitive data or privileged actions, and ensure humans are in the loop for high-stakes decisions. If you’re running Copilot Studio agents triggered by SharePoint forms, audit the window between November 24, 2025 and January 15, 2026 for indicators of compromise.
Second, patch your AI infrastructure stack now. PyTorch versions up to 2.9.1 are vulnerable to CVE-2026-24747; upgrade to version 2.10.0 or newer immediately. Update vLLM to version 0.14.1 or later to address CVE-2026-22778. Both vulnerabilities allow remote code execution and are likely already under exploit development. Do not wait for vendor notifications—these are widely deployed components and attackers know it.
Third, operationalize the new frameworks. The OWASP Top 10 for Agentic Applications provides practical, actionable guidance to help organizations secure AI agents; by distilling a broad ecosystem of guidance into an accessible format, the Top 10 equips builders, defenders, and decision-makers with a clear starting point. Map your agentic deployments against the 10 risk categories (ASI01–ASI10), test them using tools like those from Lakera, Repello, or open-source frameworks, and track findings over time. NIST is creating a Trustworthy AI in Critical Infrastructure Profile Community of Interest and welcomes participation from across the entire critical infrastructure ecosystem—if your organization operates in energy, water, healthcare, or financial services, engage now.
Tools and Resources
Gandalf: Agent Breaker – Lakera’s adversarial testing environment demonstrates how poisoned content slips into real systems through RAG documents, browsing agents, and MCP tool metadata. Access at lakera.ai
ARTEMIS & ARGUS – Repello’s platforms run automated adversarial testing across all ten OWASP LLM categories continuously, with findings mapped to the framework. ARGUS provides runtime enforcement for production deployments.
Chainbreaker and Garak – Open-source tools for testing agents against current jailbreak techniques, as recommended by security researchers. Measure compliance rates and identify weaknesses before attackers do.
vLLM Security Advisories – Monitor the vLLM GitHub security page for ongoing disclosures; multiple high-severity advisories were published this week.