Research · curated 8 Aug 2026
AI-related Vulnerabilities within CVEs: Are We Ready Yet? A Study of Vulnerability Disclosure in AI Products | Proceedings of the 18th ACM Workshop on Artificial Intelligence and Security
First reported acm.org
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
The study exposes gaps in how the CVE program captures AI-specific and adversarial-AI vulnerabilities, which affects defenders' ability to track and prioritize emerging risks in AI software supply chains.
A research paper, 'AI-related Vulnerabilities within CVEs: Are We Ready Yet?', presents a large-scale analysis of ~128,000 CVEs disclosed from 2021 to 2025 using a multi-agent actor-critic system that classifies entries as Non-AI, AI Supply Chain, or Adversarial AI, mapping the latter to the NIST AI 100-2e2025 taxonomy. The study finds ~1.57% of CVEs are AI-relevant (1.05% AI supply chain, 0.52% adversarial AI) and argues current CVE disclosure practices inadequately capture the adversarial AI threat landscape.