
Why AI agent security becomes mandatory by the end of 2026 CVE-2026-25592 and CVE-2026-26030 Two confirmed RCEs in Semantic Kernel (SK). One prompt escalates to host-level code execution. SK is a widely deployed agent framework. If you build on it, audit tool-call permissions now. DryRun Security study: 26 of 30 agent pull requests introduced a real vulnerability. Broken access control appeared in every model tested. Claude Code, OpenAI Codex, Gemini — all of them. Shipping agent-generated code without inline scanning introduces a near-certain vulnerability. OWASP Top 10 for Agentic Applications First peer-reviewed taxonomy for agentic risk. Covers goal hijacking, tool misuse, identity abuse, and memory poisoning. Enterprise buyers will require this checklist. Architects should already be mapping to it. HashiCorp on why legacy identity and access management (IAM) breaks for agents - Agents have no login, no static role, no human session. They invoke other agents dynamically. 97% of orgs that had an AI security incident lacked dedicated AI access controls. Human-centric IAM does not port. Gravitee survey: 52% of production agents run with zero security monitoring - Only 14.4% of orgs have full IT or security approval for their agent fleet. Most deployed agents are invisible to the security team. That is not a gap. That is an open door. IBM's Agent-to-Agent Security (A2AS) framework Behaviour certificates, authenticated prompts, and defined security boundaries. IBM is positioning A2AS as the HTTPS equivalent for an agentic runtime. If it gets traction, it becomes a compliance floor. Track it.
Post summary
The post discloses two confirmed RCE CVEs (CVE‑2026‑25592 and CVE‑2026‑26030) in Semantic Kernel, emphasizing the need for immediate security audits of AI agent deployments.








