The Authentication Gap Reaches the Inference Layer: Four AI Infrastructure CVEs in 18 Days
Between 25 August and 11 September 2026, four critical CVEs hit NVIDIA NemoClaw, DeepSeek Harness, IBM Langflow and SGLang. Every one traces back to a default configuration, not a model flaw. A verified breakdown of each vulnerability and the policy-as-code controls that actually contain them.
September 14, 2026 Vulnerability Analysis