Skip to content

CVE-2026-21852

CVE

Threat entity extracted from intelligence sources

Frequency
9
occurrences
First Seen
February 25, 2026
Last Seen
August 25, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

Claude Code, an agentic coding tool by Anthropic, has been found to have multiple vulnerabilities affecting various versions. CVE-2026-33068 allows attackers to bypass the trust dialog, enabling arbitrary tool execution without user consent. CVE-2026-25723 permits file write restrictions to be bypas...

Recent research highlights significant vulnerabilities in agentic AI systems, which can misclassify adversarial inputs as trusted instructions across six architectural layers. These vulnerabilities stem from trust boundary failures, allowing unauthorized actions through tools and memory. The Layered...

AI coding assistants like Claude Code and GitHub Copilot are vulnerable to prompt injection attacks that exploit unvetted external artifacts. These attacks can turn coding assistants into attackers' shells, executing unauthorized commands with developer privileges. Recent vulnerabilities, including...

In July 2026, Noma Labs discovered a prompt injection vulnerability in GitHub's Agentic Workflows, named GitLost, allowing unauthenticated attackers to access private repositories by crafting a GitHub Issue in a public repository. The vulnerability exploits the AI agent's failure to distinguish betw...

Public Exploits

Checking GitHub for proof-of-concept code…