Scope: what this does not show
Affected versions of named products, some only under specific configurations (an allowlisted benign command in Gemini CLI; particular Semantic Kernel plugins exposed to the model). Most were patched after disclosure, but OX reports some MCP-related projects unpatched or rejected as by design. None is reported as exploited in the wild.
Corroborated: Supported by at least two independent sources.
Evidence
Jul 28, 2025
Aug 1, 2025
Apr 15, 2026
May 7, 2026
Jul 1, 2026
Key questions that rely on this finding
- Where are deployed AI agents actually being exploited?Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.