Production AI Institute · Public record
Live production AI watch - 11 Sept 2026

Know what changed in AI this week.

The live AI watch joins incidents, exploited vulnerabilities, vendor changes, model and tool releases, and public evidence into one place to check before surprises become problems.

Priority read

The first six checks.

These are not recommendations to panic. They are the records and exploited items most likely to change an operator conversation this week.

security

CVE-2026-86060: MikroTik RouterOS

MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

Operator read: Review any AI workload, notebook, model-serving, or developer-tool exposure before relying on the affected component.
Open source trail ->
security

CVE-2026-67277: MikroTik RouterOS

MikroTik RouterOS Missing Authentication for Critical Function Vulnerability

Operator read: Review any AI workload, notebook, model-serving, or developer-tool exposure before relying on the affected component.
Open source trail ->
security

CVE-2026-19490: Citrix NetScaler

Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability

Operator read: Review any AI workload, notebook, model-serving, or developer-tool exposure before relying on the affected component.
Open source trail ->
security

CVE-2025-25249: Fortinet Multiple Products

Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

Operator read: Review any AI workload, notebook, model-serving, or developer-tool exposure before relying on the affected component.
Open source trail ->
security

CVE-2026-87491: Google Chromium V8

Google Chromium V8 Out of Bounds Write Vulnerability

Operator read: Review any AI workload, notebook, model-serving, or developer-tool exposure before relying on the affected component.
Open source trail ->
security

CVE-2026-20079: Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management

Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

Operator read: Review any AI workload, notebook, model-serving, or developer-tool exposure before relying on the affected component.
Open source trail ->

Incidents and outages

Service failures, degraded AI systems, and operational events with a source trail.

incident
16 July 2026

Supabase: S3 endpoints for keys with special characters broken

We have identified an issue where S3 endpoints for keys with special characters will be broken. We are actively investigating the correct mitigation for this issue.

incident92%2 sourcesD4
Open the incident record and confirm affected services.
incident
16 July 2026

Disruption with some GitHub services

The degradation has been mitigated. We are monitoring to ensure stability.

incident92%2 sourcesD4
Open the incident record and confirm affected services.
incident
16 July 2026

Anthropic: Elevated errors for Claude Opus 4.7

We are currently investigating this issue.

incident92%2 sourcesD4
Open the incident record and confirm affected services.
incident
16 July 2026

OpenAI: Elevated Error Rates For SSO Login

We have applied the mitigation and are monitoring the recovery.

incident92%1 sourceD4
Open the incident record and confirm affected services.
incident
14 July 2026

Replicate: H100 GPU shortage resulting in high queue times

We pushed a fix and are monitoring Impact: minor. Status: monitoring.

incident92%1 sourceD4
Open the incident record and confirm affected services.
incident
13 July 2026

Pinecone: [Serverless][AWS][us-east-1] Increase in freshness lag for some namespaces

The issue has been identified and a fix is being implemented.

incident92%2 sourcesD4
Open the incident record and confirm affected services.
incident
10 July 2026

Supabase: Degraded log ingestion

We are continuing to investigate the issue affecting log ingestion across all regions. Logs may be delayed or unavailable. We will provide another update as soon as more information becomes available.

incident92%2 sourcesD4
Open the incident record and confirm affected services.
incident
9 July 2026

Pinecone: Serverless Azure eastus2 experiencing 5xx errors on some indexes

Pinecone reported an active incident affecting Serverless indexes in Azure eastus2. Some requests to certain indexes are returning 5xx errors. The incident began on 2026-07-09 at 09:50 UTC and is under investigation.

incident95%2 sourcesD4
Open the incident record and confirm affected services.

Known exploited vulnerabilities

CISA KEV items that intersect AI delivery, remote access, managed environments, or operator security.

security
10 Sept 2026

CVE-2026-86060: MikroTik RouterOS

MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

known exploitedAI stackDue 13 Sept 2026
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
security
10 Sept 2026

CVE-2026-67277: MikroTik RouterOS

MikroTik RouterOS Missing Authentication for Critical Function Vulnerability

known exploitedAI stackDue 13 Sept 2026
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
security
9 Sept 2026

CVE-2026-19490: Citrix NetScaler

Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability

known exploitedAI stackDue 12 Sept 2026
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
security
9 Sept 2026

CVE-2025-25249: Fortinet Multiple Products

Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

known exploitedAI stackDue 12 Sept 2026
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
security
9 Sept 2026

CVE-2026-87491: Google Chromium V8

Google Chromium V8 Out of Bounds Write Vulnerability

known exploitedAI stackDue 23 Sept 2026
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
security
9 Sept 2026

CVE-2026-20079: Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management

Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

known exploitedAI stackDue 12 Sept 2026
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
security
8 Sept 2026

CVE-2026-75650: Adobe Commerce and Magento

Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

known exploitedAI stackDue 11 Sept 2026
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
security
8 Sept 2026

CVE-2026-81963: Microsoft Windows

Microsoft Windows Link Following Vulnerability

known exploitedAI stackDue 22 Sept 2026
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Vendor and policy changes

Data-use disclosures, desk Policy Change Watch editions, and autonomous vendor diffs when verified. Desk editions are not the fleet moat metric.

No current item

No source-backed item in this lane.

The lane remains visible so absence is explicit rather than hidden.

Keep watching the source trail.

Models, Lab, and evaluation

Model releases, Lab scorecards, Compass results, and production-readiness assessments.

Record method and source trail

Records that explain how the public memory layer is being strengthened.

No current item

No source-backed item in this lane.

The lane remains visible so absence is explicit rather than hidden.

Keep watching the source trail.
Brief-ready view

Turn the watch board into an AI risk brief.

The risk brief is generated from the same records. It preserves the source trail and converts operator signals into questions a team can use in an internal note, client update, board pack, or vendor review.

Saved watches

Tell us what to keep current.

Save a watch for vendors, tools, controls, vulnerabilities, or operating questions. The public record stays open. A saved watch tells us what matters to you - not a promise of a private alert feed.