View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

CVE-2026-77956: CVSS 10.0 RCE in AshAi via prompt template evaluation

🔓 CVEs & KEV

  • CVE-2026-77956 — CVSS 10.0 — EEx template evaluation of prompt content in AshAi enables remote code execut...

  • CVE-2026-75759 — CVSS 7.6 — Encrypted ID token or JARM response accepted without a nested signature in er...

  • CVE-2026-81315 — CVSS 7.4 — MCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-...

  • CVE-2026-75760 — CVSS 7.1 — AshAi vectorize change leaks raw embedding-provider errors, including credent...

  • CVE-2026-82564 — CVSS 7.1 — Identity tool filter in AshAi accepts operator maps, allowing update or destr...

  • CVE-2026-82579 — CVSS 6.0 — AshAi tool loop never terminates when all tool calls are filtered out, enabli...

📋 ADVISORIES

  • 📄 Source for Critical Buffer Overflow Hits D-Link DIR-825M Firmware 1.1.8github.com

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check