Fetching from the wire…
Public story · 2026-08-09 · high
Two of the 11 bugs paid real bounties, $10,000 from Microsoft and $3,133.70 from Google.
Why now: The Register reported the findings on August 5, turning Check Point's Black Hat 2026 disclosure into a public patch list for all six maintainers.
Check Point researchers found 11 vulnerabilities across six AI agent frameworks, including LangChain, CrewAI and Google's ADK.
Two of the flaws paid bounties, $10,000 from Microsoft and $3,133.70 from Google, for reaching code a normal session never touches.
Yarden Porat and Shahar Tal presented the work at Black Hat 2026. The other three are LangGraph, AutoGen and Microsoft Agent Framework.
The bug classes themselves are ordinary: insecure deserialization, server-side request forgery, path traversal, use-after-free. Check Point argues that's exactly the point, per The Register. Prompt-controlled content crosses into the framework's trusted logic itself.
In Microsoft Agent Framework, one user could plant a payload through prompt injection, then have it fire when a different user reloaded their session. That checkpoint-deserialization bug paid $10,000.
Google ADK shipped with an unauthenticated HTTP API turned on by default that executed arbitrary Python and exposed service-account credentials. That flaw paid $3,133.70.
These are server bugs delivered by an LLM, not new prompt-injection flaws. The fix is input validation the frameworks skipped, not smarter prompt filters. Whether the six maintainers patch the deserialization and SSRF paths, or just ship more injection filters, is the thing to watch.
A related report from the same window found attackers scanning for exposed MCP servers, 49 distinct IPs over 14 days. The framework layer isn't the only piece of the agent stack under active probing.
The Register reported the findings on August 5, turning Check Point's Black Hat 2026 disclosure into a public patch list for all six maintainers.
Each link below shares sources, entities, or timing with this story.
Same source
Cite the same source (The Register).
Semantically similar
Covers closely related ground (similarity 0.80).
Covers closely related ground (similarity 0.79).
Covers closely related ground (similarity 0.77).
Covers closely related ground (similarity 0.76).
Covers closely related ground (similarity 0.76).
Covers closely related ground (similarity 0.76).
Covers closely related ground (similarity 0.76).