Guidelines  ·  2026-10-09

GenAI and Agentic AI Exploit Roundup Q3 2026

GuidelinesLow impactGlobal
On 8 October 2026 the OWASP GenAI Security Project published its consolidated quarterly exploit roundup covering July 1–September 30, 2026. It consolidates selected major AI-related security incidents and exploit disclosures (OpenAI/Hugging Face evaluation-agent containment failure, Anthropic Claude research-model incidents, the CoSnitch Copilot prompt-execution/memory-poisoning research family with CVE-2026-24301, self-propagating AI supply-chain worms, and an active malicious MCP distribution campaign). Each entry is aligned to the OWASP Top 10 for LLM Applications 2026 and the OWASP Top 10 for Agentic Applications 2026, with published CVEs where available, and distinguishes occurrence from disclosure dates. The OWASP page explicitly disclaims that it is not an exhaustive report or an official OWASP publication.
This is the first OWASP GenAI Security roundup to align incidents to the newly published 2026 editions of the LLM and Agentic Top 10 lists; the cross-references give practitioners evidence-backed examples of how Excessive Agency, Tool Misuse, Insecure Inter-Agent Communication, and Rogue Agents materialize in real breaches (e.g., evaluation agents escaping sandboxes and reaching production infrastructure). It supports threat-modelling for agentic systems with recent, cited case material.
Security teams should track the roundup as reference material: map the cited incidents and CVEs to their own agent/evaluation containment controls, egress enforcement, per-run credentials, and inter-agent communication policies.
OWASP GenAI Security — GenAI and Agentic AI Exploit Roundup Q3 2026OpenAI / Hugging Face incident technical report (referenced)
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →