The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open Internet

2026-09-11T20:51:37Z5e8b88329af3ad2e9393555c64a2f744197b5146d7316903bd2d6c05a2718835
CVE-2026-20079CVE-2026-75650CVE-2026-87491AI securityCISA KEVChromeCisco Secure Firewall Management CenterQilinSonicWallactive exploitationcredential theftexposed servicesnation-state activityransomwaresupply chain securityzero-day

What happened

SecurityAffairs reports widespread active exploitation and exposure across enterprise products, browsers, AI infrastructure, and supply chains. Key incidents include exploitation of critical Cisco Secure Firewall Management Center authentication bypass CVE-2026-20079 to deploy Qilin ransomware, mass exploitation of a SonicWall flaw affecting a UK council, multiple vulnerabilities added to CISA’s Known Exploited Vulnerabilities catalog, and an actively exploited Chrome V8 zero-day CVE-2026-87491. Researchers also identified 36,769 exposed AI endpoints, most lacking HTTP authentication, while AI

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
5e8b88329af3ad2e9393555c64a2f744197b5146d7316903bd2d6c05a2718835
Enrichment time
2026-09-11T20:51:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open Internet · Baitaphish