Production AI Institute · Public record
Live production AI watch - 28 July 2026

Know what changed in AI this week.

The live AI watch joins incidents, exploited vulnerabilities, vendor changes, model and tool releases, and public evidence into one place to check before surprises become problems.

Priority read

The first six checks.

These are not recommendations to panic. They are the records and exploited items most likely to change an operator conversation this week.

security

CVE-2025-68686: Fortinet FortiOS

Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

Operator read: Review any AI workload, notebook, model-serving, or developer-tool exposure before relying on the affected component.
Open source trail ->
security

CVE-2026-16812: Arista VeloCloud Orchestrator

Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

Operator read: Review any AI workload, notebook, model-serving, or developer-tool exposure before relying on the affected component.
Open source trail ->
security

CVE-2026-16232: Check Point SmartConsole

Check Point SmartConsole Improper Authentication Vulnerability

Operator read: Review any AI workload, notebook, model-serving, or developer-tool exposure before relying on the affected component.
Open source trail ->
security

CVE-2026-50522: Microsoft SharePoint

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Operator read: Review any AI workload, notebook, model-serving, or developer-tool exposure before relying on the affected component.
Open source trail ->
security

CVE-2026-60137: WordPress Core

WordPress Core SQL Injection Vulnerability

Operator read: Review any AI workload, notebook, model-serving, or developer-tool exposure before relying on the affected component.
Open source trail ->
security

CVE-2026-63030: WordPress Core

WordPress Core Interpretation Conflict Vulnerability

Operator read: Review any AI workload, notebook, model-serving, or developer-tool exposure before relying on the affected component.
Open source trail ->

Incidents and outages

Service failures, degraded AI systems, and operational events with a source trail.

incident
16 July 2026

Supabase: S3 endpoints for keys with special characters broken

We have identified an issue where S3 endpoints for keys with special characters will be broken. We are actively investigating the correct mitigation for this issue.

incident92%2 sourcesD4
Open the incident record and confirm affected services.
incident
16 July 2026

Disruption with some GitHub services

The degradation has been mitigated. We are monitoring to ensure stability.

incident92%2 sourcesD4
Open the incident record and confirm affected services.
incident
16 July 2026

Anthropic: Elevated errors for Claude Opus 4.7

We are currently investigating this issue.

incident92%2 sourcesD4
Open the incident record and confirm affected services.
incident
16 July 2026

OpenAI: Elevated Error Rates For SSO Login

We have applied the mitigation and are monitoring the recovery.

incident92%1 sourceD4
Open the incident record and confirm affected services.
incident
14 July 2026

Replicate: H100 GPU shortage resulting in high queue times

We pushed a fix and are monitoring Impact: minor. Status: monitoring.

incident92%1 sourceD4
Open the incident record and confirm affected services.
incident
13 July 2026

Pinecone: [Serverless][AWS][us-east-1] Increase in freshness lag for some namespaces

The issue has been identified and a fix is being implemented.

incident92%2 sourcesD4
Open the incident record and confirm affected services.
incident
10 July 2026

Supabase: Degraded log ingestion

We are continuing to investigate the issue affecting log ingestion across all regions. Logs may be delayed or unavailable. We will provide another update as soon as more information becomes available.

incident92%2 sourcesD4
Open the incident record and confirm affected services.
incident
9 July 2026

Pinecone: Serverless Azure eastus2 experiencing 5xx errors on some indexes

Pinecone reported an active incident affecting Serverless indexes in Azure eastus2. Some requests to certain indexes are returning 5xx errors. The incident began on 2026-07-09 at 09:50 UTC and is under investigation.

incident95%2 sourcesD4
Open the incident record and confirm affected services.

Known exploited vulnerabilities

CISA KEV items that intersect AI delivery, remote access, managed environments, or operator security.

security
27 July 2026

CVE-2025-68686: Fortinet FortiOS

Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

known exploitedAI stackDue 10 Aug 2026
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
security
27 July 2026

CVE-2026-16812: Arista VeloCloud Orchestrator

Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

known exploitedAI stackDue 30 July 2026
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
security
22 July 2026

CVE-2026-16232: Check Point SmartConsole

Check Point SmartConsole Improper Authentication Vulnerability

known exploitedAI stackDue 25 July 2026
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
security
22 July 2026

CVE-2026-50522: Microsoft SharePoint

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

known exploitedAI stackDue 25 July 2026
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
security
21 July 2026

CVE-2026-60137: WordPress Core

WordPress Core SQL Injection Vulnerability

known exploitedAI stackDue 4 Aug 2026
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
security
21 July 2026

CVE-2026-63030: WordPress Core

WordPress Core Interpretation Conflict Vulnerability

known exploitedAI stackDue 24 July 2026
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
security
21 July 2026

CVE-2026-0770: Langflow Langflow

Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

known exploitedAI stackDue 24 July 2026
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
security
21 July 2026

CVE-2021-27137: DD-WRT DD-WRT

DD-WRT Stack-Based Buffer Overflow Vulnerability

known exploitedAI stackDue 24 July 2026
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Vendor and policy changes

Data-use disclosures, desk Policy Change Watch editions, and autonomous vendor diffs when verified. Desk editions are not the fleet moat metric.

No current item

No source-backed item in this lane.

The lane remains visible so absence is explicit rather than hidden.

Keep watching the source trail.

Models, Lab, and evaluation

Model releases, Lab scorecards, Compass results, and production-readiness assessments.

Record method and source trail

Records that explain how the public memory layer is being strengthened.

No current item

No source-backed item in this lane.

The lane remains visible so absence is explicit rather than hidden.

Keep watching the source trail.
Brief-ready view

Turn the watch board into an AI risk brief.

The risk brief is generated from the same records. It preserves the source trail and converts operator signals into questions a team can use in an internal note, client update, board pack, or vendor review.

Saved watches

Tell us what to keep current.

Save a watch for vendors, tools, controls, vulnerabilities, or operating questions. The public record stays open. A saved watch tells us what matters to you - not a promise of a private alert feed.