⚠️ LiveThreat Vulnerability Brief — Apr 21, 2026
📊 5 vulnerabilities & exploits tracked impacting the supply chain
━━━━━━━━━━━━━━━━━━━━━━
⚠️ AI Supply Chain Vulnerability in MCP Exposes Enterprises to Open‑Redirect Attacks
A newly disclosed open‑redirect flaw in the Model Control Plane (MCP) used by many AI SaaS platforms enables attackers to hijack model‑inference traffic, threat…
🔗 https://www.livethreat.ai/intelligence/the-mcp-disclosure-is-the-ai-era-s-open-redirect-moment-16700
💥 Exploited Microsoft Defender Flaws Leave Windows 10/11 Systems Partially Unprotected
Active exploitation of three Microsoft Defender vulnerabilities on Windows 10/11 has been confirmed. While Microsoft patched the BlueHammer issue, two additiona…
🔗 https://www.livethreat.ai/intelligence/microsoft-defender-flaws-exploited-on-windows-two-left-unpatched-16701
⚠️ Critical RCE in SGLang (CVE-2026-5760) Threatens AI Model‑Serving Platforms
A newly disclosed CVE‑2026‑5760 in the open‑source SGLang library allows remote code execution when malicious GGUF model files are processed. The flaw, scored 9…
🔗 https://www.livethreat.ai/intelligence/sglang-cve-2026-5760-cvss-9-8-enables-rce-via-malicious-gguf-model-files-16660
⚠️ Thousands of Vulnerabilities Discovered in Serial‑to‑IP OT Devices Threaten Industrial Networks
Researchers have uncovered thousands of known and new vulnerabilities in serial‑to‑IP converters that bridge legacy machine protocols to Ethernet. The flaws ena…
🔗 https://www.livethreat.ai/intelligence/serial-to-ip-devices-hide-thousands-of-old-and-new-bugs-16683
💥 Active Exploitation Attempts on High‑Severity TP‑Link Router Command Injection (CVE‑2023‑33538) Remain Unsuccessful
A command‑injection flaw (CVE‑2023‑33538) affecting several legacy TP‑Link routers is being probed by threat actors for over a year. Although proof‑of‑concept c…
🔗 https://www.livethreat.ai/intelligence/cve-2023-33538-under-attack-for-a-year-but-exploitation-still-unsuccessful-16647
━━━━━━━━━━━━━━━━━━━━━━
🛡️ How many of your vendors are running these affected systems?
📖 View all → https://www.livethreat.ai/vulnerabilities
🔔 Follow LiveThreat for daily TPRM intelligence
#Cybersecurity #ThreatIntel #TPRM #InfoSec #VendorRisk #BreachWatch #DoNotBeLarry #VerisqAI #LiveThreat