The hidden cost of AI speed: Unmanaged cyber risk

2026-03-23T20:52:19Zb117e847d24e7831049510b7fd8a89efb9100ac9045afaa57292b0539abeb55a
AI securityAppSecCNAPPCVE-2025-61757CVE-2026-21514CVE-2026-21992Microsoft WordN-dayNERC CIP-003-9OLE bypassOracle Fusion MiddlewareTenable Researchattack surfacecomplianceexposure managementidentity and accesssupply chain riskvulnerability management

What happened

Tenable highlights a broad, high-risk landscape: rapid AI adoption has expanded the attack surface by connecting models to sensitive workflows and cloud data, creating governance gaps (over-privileged access, ghost identities, supply-chain risk) that require unified exposure management rather than siloed inventory. Notable technical incidents include CVE-2026-21992 (Oracle Identity Manager / Web Services Manager RCE, CVSS 9.8, out-of-band alert and related to prior in-the-wild exploitation) and CVE-2026-21514 (Microsoft Word OLE/Mark-of-the-Web bypass N-day, ~14 million exposed assets across 7

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
tenable_blog
Record identifier
b117e847d24e7831049510b7fd8a89efb9100ac9045afaa57292b0539abeb55a
Enrichment time
2026-03-23T20:52:19Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.