The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open Internet
2026-09-11T20:51:37Z•5e8b88329af3ad2e9393555c64a2f744197b5146d7316903bd2d6c05a2718835
CVE-2026-20079CVE-2026-75650CVE-2026-87491AI securityCISA KEVChromeCisco Secure Firewall Management CenterQilinSonicWallactive exploitationcredential theftexposed servicesnation-state activityransomwaresupply chain securityzero-day
What happened
SecurityAffairs reports widespread active exploitation and exposure across enterprise products, browsers, AI infrastructure, and supply chains. Key incidents include exploitation of critical Cisco Secure Firewall Management Center authentication bypass CVE-2026-20079 to deploy Qilin ransomware, mass exploitation of a SonicWall flaw affecting a UK council, multiple vulnerabilities added to CISA’s Known Exploited Vulnerabilities catalog, and an actively exploited Chrome V8 zero-day CVE-2026-87491. Researchers also identified 36,769 exposed AI endpoints, most lacking HTTP authentication, while AI
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 5e8b88329af3ad2e9393555c64a2f744197b5146d7316903bd2d6c05a2718835
- Enrichment time
- 2026-09-11T20:51:37Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.