Production AI Institute · Public record
AI risk brief - Generated 28 July 2026

AI risk brief: CVE-2025-68686: Fortinet FortiOS

A client-ready brief for teams responsible for AI tools, vendors, and exposure. It turns the public record into exposure checks, source links, and calm language for internal notes, client updates, board packs, and weekly risk reviews.

Brief body

What responsible teams should hear this week.

The brief is organised by operational use: exploited items first, incidents second, then policy and model signals that can change advice, approved-tool lists, or risk posture.

Known exploited items to check first

CVE-2025-68686: Fortinet FortiOS

Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

27 July 2026CISA Known Exploited Vulnerabilities Catalogknown exploitedAI stack
Review any AI workload, notebook, model-serving, or developer-tool exposure before relying on the affected component.

CVE-2026-16812: Arista VeloCloud Orchestrator

Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

27 July 2026CISA Known Exploited Vulnerabilities Catalogknown exploitedAI stack
Review any AI workload, notebook, model-serving, or developer-tool exposure before relying on the affected component.

CVE-2026-16232: Check Point SmartConsole

Check Point SmartConsole Improper Authentication Vulnerability

22 July 2026CISA Known Exploited Vulnerabilities Catalogknown exploitedAI stack
Review any AI workload, notebook, model-serving, or developer-tool exposure before relying on the affected component.

CVE-2026-50522: Microsoft SharePoint

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

22 July 2026CISA Known Exploited Vulnerabilities Catalogknown exploitedAI stack
Review any AI workload, notebook, model-serving, or developer-tool exposure before relying on the affected component.

CVE-2026-60137: WordPress Core

WordPress Core SQL Injection Vulnerability

21 July 2026CISA Known Exploited Vulnerabilities Catalogknown exploitedAI stack
Review any AI workload, notebook, model-serving, or developer-tool exposure before relying on the affected component.

AI service incidents and outages

Supabase: S3 endpoints for keys with special characters broken

We have identified an issue where S3 endpoints for keys with special characters will be broken. We are actively investigating the correct mitigation for this issue.

16 July 2026Production AI public recordincident92%
Check dependency exposure, fallback plans, customer commitments, and incident communications tied to this provider or service.

Disruption with some GitHub services

The degradation has been mitigated. We are monitoring to ensure stability.

16 July 2026Production AI public recordincident92%
Check dependency exposure, fallback plans, customer commitments, and incident communications tied to this provider or service.

Anthropic: Elevated errors for Claude Opus 4.7

We are currently investigating this issue.

16 July 2026Production AI public recordincident92%
Check dependency exposure, fallback plans, customer commitments, and incident communications tied to this provider or service.

OpenAI: Elevated Error Rates For SSO Login

We have applied the mitigation and are monitoring the recovery.

16 July 2026Production AI public recordincident92%
Check dependency exposure, fallback plans, customer commitments, and incident communications tied to this provider or service.

Model, Lab, and evaluation signals

Anthropic: Claude Mythos Preview retirement announced for June 30, 2026

Anthropic announced that Claude Mythos Preview (claude-mythos-preview) will be retired on June 30, 2026. Users are advised to migrate to Claude Mythos 5 (claude-mythos-5) using the provided migration guide.

14 July 2026Production AI public recordrelease95%
Inspect the source trail and decide whether this record changes a control, vendor, or operational assumption.

Google: Gemini 3.5 Flash model pricing published

Google published pricing for the new Gemini 3.5 Flash model. Standard paid tier input is $1.50/1M tokens, output is $9.00/1M tokens. Batch pricing is $0.75/1M input and $4.50/1M output. Free tier usage contributes to product improvement.

11 July 2026Production AI public recordrelease90%
Inspect the source trail and decide whether this record changes a control, vendor, or operational assumption.

Anthropic: Claude Opus 4.1 deprecated, retirement August 5 2026

The claude-opus-4-1-20250805 model state changed to Deprecated on June 5, 2026, with a tentative retirement date of August 5, 2026. Users must migrate before the retirement date to avoid disruption.

10 July 2026Production AI public recordrelease95%
Inspect the source trail and decide whether this record changes a control, vendor, or operational assumption.
Exposure questions

Use these before writing advice.

These prompts stop the brief from becoming noise. Each question is attached to a source-backed item in the current watch board.

Question 1

Do we or any important client environments run Fortinet FortiOS, and is remediation tracked?

Question 2

Do we or any important client environments run Arista VeloCloud Orchestrator, and is remediation tracked?

Question 3

Do we or any important client environments run Check Point SmartConsole, and is remediation tracked?

Question 4

Do we or any important client environments run Microsoft SharePoint, and is remediation tracked?

Question 5

Do we or any important client environments run WordPress Core, and is remediation tracked?

Question 6

Does this incident affect a provider, dependency, customer promise, or operating assumption we rely on?

Action discipline

How to send it without hype.

The point is to help people inspect exposure. Do not imply impact until an environment, vendor, or control is actually in scope.

Rule 1

Check exposure before forwarding urgency to anyone else.

Rule 2

Record the vendor, product, owner, and remediation status for any affected environment.

Rule 3

Update AI tool advice where a vendor policy, data-use record, or public incident changes the operating picture.

Rule 4

Preserve the PAI source trail when turning this into an internal note, client brief, board update, or advisory.

Source trail

Every claim keeps its record link.

You can repackage the wrapper. You cannot remove the evidence trail.

ItemDateSourceOpen
CVE-2025-68686: Fortinet FortiOS27 July 2026CISA Known Exploited Vulnerabilities CatalogSource trail
CVE-2026-16812: Arista VeloCloud Orchestrator27 July 2026CISA Known Exploited Vulnerabilities CatalogSource trail
CVE-2026-16232: Check Point SmartConsole22 July 2026CISA Known Exploited Vulnerabilities CatalogSource trail
CVE-2026-50522: Microsoft SharePoint22 July 2026CISA Known Exploited Vulnerabilities CatalogSource trail
CVE-2026-60137: WordPress Core21 July 2026CISA Known Exploited Vulnerabilities CatalogSource trail
Supabase: S3 endpoints for keys with special characters broken16 July 2026Production AI public recordSource trail
Disruption with some GitHub services16 July 2026Production AI public recordSource trail
Anthropic: Elevated errors for Claude Opus 4.716 July 2026Production AI public recordSource trail
OpenAI: Elevated Error Rates For SSO Login16 July 2026Production AI public recordSource trail
Anthropic: Claude Mythos Preview retirement announced for June 30, 202614 July 2026Production AI public recordSource trail
Google: Gemini 3.5 Flash model pricing published11 July 2026Production AI public recordSource trail
Anthropic: Claude Opus 4.1 deprecated, retirement August 5 202610 July 2026Production AI public recordSource trail
Keep the brief current

Use the record, not a stale newsletter.

The live AI watch is the source. The AI risk brief is the translation layer for operators, founders, security teams, consultants, service providers, and anyone who has to explain what changed without pretending exposure is proven.

Saved watches

Tell us what to keep current.

Save a watch for vendors, tools, controls, vulnerabilities, or operating questions. The public record stays open. A saved watch tells us what matters to you - not a promise of a private alert feed.