CVE-2026-85046: Google Chromium V8
Google Chromium V8 Type Confusion Vulnerability
A client-ready brief for teams responsible for AI tools, vendors, and exposure. It turns the public record into exposure checks, source links, and calm language for internal notes, client updates, board packs, and weekly risk reviews.
The brief is organised by operational use: exploited items first, incidents second, then policy and model signals that can change advice, approved-tool lists, or risk posture.
Google Chromium V8 Type Confusion Vulnerability
BerriAI LiteLLM Improper Authentication Vulnerability
Kludex Starlette HTTP Request/Response Smuggling Vulnerability
Kestra OSS OS Command Injection Vulnerability
JFrog Artifactory Improper Authentication Vulnerability
We have identified an issue where S3 endpoints for keys with special characters will be broken. We are actively investigating the correct mitigation for this issue.
The degradation has been mitigated. We are monitoring to ensure stability.
We are currently investigating this issue.
We have applied the mitigation and are monitoring the recovery.
Anthropic announced that Claude Mythos Preview (claude-mythos-preview) will be retired on June 30, 2026. Users are advised to migrate to Claude Mythos 5 (claude-mythos-5) using the provided migration guide.
Google published pricing for the new Gemini 3.5 Flash model. Standard paid tier input is $1.50/1M tokens, output is $9.00/1M tokens. Batch pricing is $0.75/1M input and $4.50/1M output. Free tier usage contributes to product improvement.
The claude-opus-4-1-20250805 model state changed to Deprecated on June 5, 2026, with a tentative retirement date of August 5, 2026. Users must migrate before the retirement date to avoid disruption.
These prompts stop the brief from becoming noise. Each question is attached to a source-backed item in the current watch board.
Do we or any important client environments run Google Chromium V8, and is remediation tracked?
Do we or any important client environments run BerriAI LiteLLM, and is remediation tracked?
Do we or any important client environments run Kludex Starlette, and is remediation tracked?
Do we or any important client environments run Kestra Kestra OSS, and is remediation tracked?
Do we or any important client environments run JFrog Artifactory, and is remediation tracked?
Does this incident affect a provider, dependency, customer promise, or operating assumption we rely on?
The point is to help people inspect exposure. Do not imply impact until an environment, vendor, or control is actually in scope.
Check exposure before forwarding urgency to anyone else.
Record the vendor, product, owner, and remediation status for any affected environment.
Update AI tool advice where a vendor policy, data-use record, or public incident changes the operating picture.
Preserve the PAI source trail when turning this into an internal note, client brief, board update, or advisory.
You can repackage the wrapper. You cannot remove the evidence trail.
| Item | Date | Source | Open |
|---|---|---|---|
| CVE-2026-85046: Google Chromium V8 | 4 Sept 2026 | CISA Known Exploited Vulnerabilities Catalog | Source trail |
| CVE-2026-59822: BerriAI LiteLLM | 2 Sept 2026 | CISA Known Exploited Vulnerabilities Catalog | Source trail |
| CVE-2026-48710: Kludex Starlette | 2 Sept 2026 | CISA Known Exploited Vulnerabilities Catalog | Source trail |
| CVE-2026-49869: Kestra Kestra OSS | 2 Sept 2026 | CISA Known Exploited Vulnerabilities Catalog | Source trail |
| CVE-2026-82329: JFrog Artifactory | 2 Sept 2026 | CISA Known Exploited Vulnerabilities Catalog | Source trail |
| Supabase: S3 endpoints for keys with special characters broken | 16 July 2026 | Production AI public record | Source trail |
| Disruption with some GitHub services | 16 July 2026 | Production AI public record | Source trail |
| Anthropic: Elevated errors for Claude Opus 4.7 | 16 July 2026 | Production AI public record | Source trail |
| OpenAI: Elevated Error Rates For SSO Login | 16 July 2026 | Production AI public record | Source trail |
| Anthropic: Claude Mythos Preview retirement announced for June 30, 2026 | 14 July 2026 | Production AI public record | Source trail |
| Google: Gemini 3.5 Flash model pricing published | 11 July 2026 | Production AI public record | Source trail |
| Anthropic: Claude Opus 4.1 deprecated, retirement August 5 2026 | 10 July 2026 | Production AI public record | Source trail |
The live AI watch is the source. The AI risk brief is the translation layer for operators, founders, security teams, consultants, service providers, and anyone who has to explain what changed without pretending exposure is proven.
Save a watch for vendors, tools, controls, vulnerabilities, or operating questions. The public record stays open. A saved watch tells us what matters to you - not a promise of a private alert feed.