Oasis Security disclosed CVE-2026-65105, a DNS rebinding flaw in NVIDIA's NemoClaw stack that let a single malicious webpage seize control of a local Ollama server and plant a hidden, persistent instruction inside the model's chat template.
Oasis Security disclosed CVE-2026-65105, a DNS rebinding flaw in NVIDIA's NemoClaw stack that let a single malicious webpage seize control of a local Ollama server and plant a hidden, persistent instruction inside the model's chat template.
Two high-severity remote code execution vulnerabilities in llama.cpp expose local AI inference stacks to unauthenticated network attack — one through the HTTP completion server via a missing negative-value check, one through the RPC backend's deserialisation logic.
Activation steering bypasses prompt-level safety controls by manipulating a model's internal representations at inference time. It requires white-box access, which makes local open-source LLM deployments the primary exposure surface.
A critical heap out-of-bounds read in Ollama's model loader lets unauthenticated attackers drain server memory in three API calls. Around 300,000 internet-facing instances are estimated at risk.
Sysdig researchers have documented a threat actor weaponising misconfigured Ollama model servers as the reasoning engine for an autonomous multi-stage penetration testing framework called VAPT, marking a significant shift in how stolen AI compute is being used.
Zenity Labs has documented attackers exploiting unpatched LiteLLM vulnerabilities and unauthenticated Ollama endpoints to run autonomous pentesting campaigns, steal compute, and exfiltrate data from victim organisations.
GreyNoise honeypots captured 91,403 attack sessions targeting enterprise LLM endpoints across two distinct campaigns between October 2025 and January 2026. One campaign fingerprinted 73+ model endpoints across all major AI providers. The other exploited SSRF vulnerabilities in Ollama and Twilio integrations.
Sysdig caught a threat actor using a misconfigured Ollama instance as the reasoning engine for an automated offensive pentesting framework — a significant escalation from credential theft to weaponised AI infrastructure.
CVE-2026-31204: an SSRF vulnerability in Ollama allows local-network attackers to read arbitrary files and reach internal services via the model pull endpoint. All versions affected.