6 min read
Vulnerabilities Sand Security Research disclosed a critical cross-tenant vulnerability in Writer's agent preview feature that let attackers steal session tokens and take over enterprise accounts with a single malicious link.
Sand Security Research disclosed a critical cross-tenant vulnerability in Writer's agent preview feature that let attackers steal session tokens and take over enterprise accounts with a single malicious link.
CISA added CVE-2026-55255 to the Known Exploited Vulnerabilities catalog on July 7, 2026, after confirming active exploitation of an insecure direct object reference in Langflow that let authenticated users execute workflows belonging to other tenants.
Palo Alto Networks Unit 42 disclosed a Vertex AI SDK vulnerability where predictable staging bucket names let attackers hijack model uploads and achieve code execution across tenant boundaries. Patched in April 2026, disclosed June 16.