The most vulnerable AI products are also some of the most commonly exposed online

Cybersecurity researchers have identified a surge in internet-exposed AI tools and industrial control systems that contain high-severity vulnerabilities. These exposures leave critical infrastructure, including energy grids and hospitals, increasingly susceptible to exploitation by hackers.
Why it matters
The rapid adoption of AI tools without adequate security measures creates significant risks for both corporate data and essential public infrastructure.
It is becoming increasingly easy for hackers to target vulnerable AI tools on companies’ networks, even as those companies come to depend on them for more tasks.
Not only are AI services increasingly appearing on the public internet, but the products with the most significant vulnerabilities are the ones popping up most frequently. Censys detected 169% more instances of the AI agent-building tool Langflow over the past nine months, even as the software has accumulated 18 vulnerabilities (14 of them scored as high-severity, four of them seeing exploitation) since 2024.
“Multiple unauthenticated remote code execution (RCE) vulnerabilities make any Internet-exposed instance a critical finding,” Censys said.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in