Severity: ElevatedAction: Patch

Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution

A patched Unsloth Studio vulnerability allows malicious AI models to execute arbitrary Python code during inspection, via the trust_remote_code setting.

Excerpt from the primary source: Dark Reading

Who is affected

Developers

What you should do · Patch

Apply the vendor's security update for the affected products. Check the linked advisory for affected and fixed versions, and put internet-facing systems first.

Automated guidance based on this story's classification. Check the linked advisories for specifics.

Sources

We link to original and authoritative sources. Headlines and excerpts belong to their publishers.

Original reporting

Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution Dark Reading · darkreading.com · Sep 29, 2026 · Primary source
Severity: HighAction: PatchExploitation: Suspected

Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response

One company told customers to power down its data-protection platform during a nine-hour window, while the other remained mum on reported attacks prior to releasing a patch for its product.

Why it matters

There are signs this may already be exploited, which usually shortens the time available to patch.

Patch

Apply the vendor's security update for the affected products.

Severity: HighAction: Patch

GitLab warns of critical RCE vulnerability in AI Gateway service

GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances.

Patch

Apply the vendor's security update for the affected products.

Severity: ElevatedAction: Be aware

Vulnerability Backlogs Are an Ownership Problem

Organizations don't need better vulnerability scanners; they need to know who owns their assets and has the authority and capacity to actually fix them.