Threat reportThreat IntelligenceTL-2026-1913

OWASP GenAI LLM Top 10 2026 — Community-Driven Security Guidance for AI Applications

mediumASSESSING

OWASP GenAI LLM Top 10 2026 (TL-2026-1913), also tracked as OWASP Top 10 for LLM Applications 2026, is a medium-severity tracked intrusion set, first published 2026-08-06. It has no confirmed attribution, affects Microsoft 365 Copilot, references 2 CVEs (CVE-2025-32711, CVE-2025-8217), maps to 18 MITRE ATT&CK / ATLAS techniques (AML.T0034, AML.T0051, AML.T0051.000), and is covered by 9 detection rules and 4 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
2Referenced vulnerabilities
Techniques
18MITRE ATT&CK / ATLAS
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
4Indicators of compromise

Key facts for TL-2026-1913

Threat ID
TL-2026-1913
Also known as
OWASP Top 10 for LLM Applications 2026, OWASP GenAI LLM Top 10 v1.0
Severity
MEDIUM
Status
ASSESSING
Category
THREAT_INTEL
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, health, finance, legal, government administration, education, defense, energy
Target regions
Global
Detection rules
9
Indicators of compromise
4

Malware and tooling in OWASP GenAI LLM Top 10 2026

Malware and tooling: Amazon Q Developer VS Code Extension, Microsoft 365 Copilot

How OWASP GenAI LLM Top 10 2026 works

OWASP published the 2026 update of the GenAI LLM Top 10, grounded in a curated dataset of 7,714 real-world AI security incidents (6,639 classified) and weighted 75% community expert voting / 25% incident data. The ranking introduces a hybrid evidence-based methodology, major positional shifts (Unbounded Consumption rose 4 positions, Improper Output Handling fell from 5th to 10th), and expands from 10 standalone risks to a cross-mapped framework spanning OWASP ASI/DSGAI, MITRE ATLAS/ATT&CK/CWE, NIST AI 600-1/RMF, and CSA AI Controls Matrix. Prompt Injection retains the top spot; Excessive Agency escalates as agentic systems see production incidents.

The OWASP GenAI LLM Top 10 2026 (v1.0, published August 3, 2026) represents a fundamental methodological upgrade over the 2025 edition. For the first time, the ranking is not solely based on expert judgment but on a hybrid methodology weighting community practitioner voting at approximately 75% and real-world incident data analysis at 25%. The incident data was drawn from the genai_incidents v2.0.0 dataset (Emmanuel G. Junior Rodrigues, May 2026), which consolidates 7,714 publicly disclosed AI security incidents from sources including the OECD AI Incidents Monitor (~2,900 entries), AIAAIC (~1,500), and MIT FutureTech AI Risk Navigator (~400 new entries), normalized onto OWASP LLM, OWASP ASI, NIST AI RMF, and MITRE ATLAS taxonomies.

Led by Steve Wilson (Exabeam Chief AI Officer) and Rock Lambros (Zenity Director of AI Security), the 2026 edition features a top-10 list anchored by Prompt Injection (LLM01) at the top, followed by Sensitive Information Disclosure (LLM02), and Excessive Agency (LLM03) — the latter escalating significantly as production incidents cluster around agentic systems. Unbounded Consumption (LLM10 in 2025) rose four positions to LLM06, reflecting financial denial-of-service risks from extended-thinking models and shared compute environments. Misinformation (LLM07) climbed two positions after incident records showed extensive real-world harm from confident but incorrect model outputs triggering automated business workflows. Improper Output Handling dropped from 5th to 10th, not because the flaw is resolved, but because input-boundary prompt injections and cross-pipeline data disclosures now dominate incident records.

The 2026 edition documents 9 detailed attack scenarios for Prompt Injection alone, including direct injection, indirect injection via retrieved web content, unintentional injection, RAG repository poisoning (PoisonedRAG, USENIX Security 2025 — 5 injected documents achieving >95% attack success), payload splitting, multimodal steganographic injection (Clusmann et al., Nature Communications 2024), zero-click document-borne agentic exfiltration (CVE-2025-32711 EchoLeak, CVSS 9.3 Critical), agentic destructive command execution (AWS-2025-015, Amazon Q VS Code extension compromise reaching ~1 million installs), and trusted-backend indirect injection through MCP (Invariant Labs, General Analysis Supabase MCP, postmark-mcp package).

Each risk is characterized along anatomical axes (delivery surface, propagation behavior, encoding) and mapped to multiple industry frameworks. Hidden Context Exposure (LLM08) was broadened from the 2025 edition's System Prompt Leakage to cover all non-user-visible context including system prompts, policy logic, tool schemas, and guardrails. Vector and Embedding Weaknesses (LLM09) addresses RAG-specific broken access control, embedding inversion, cross-tenant leakage, and residual embeddings persisting after source data deletion (GDPR/CCPA compliance risk).

The project's guiding philosophy, articulated by the project leads, shifts focus from perfect prevention to blast-radius control: 'Stop trying to build a model that cannot be fooled. Build the system around it, so that when the model is fooled, and it will be, nothing important breaks.' This reframes AI security as an architectural and operational discipline rather than a model-alignment problem alone.

MITRE ATT&CK / ATLAS techniques used in TL-2026-1913

Impact

AML.T0034 Cost Harvesting; T1485 Data Destruction; T1565 Data Manipulation

execution

AML.T0051 LLM Prompt Injection; AML.T0051.000 Direct; AML.T0051.001 Indirect

defense-evasion

AML.T0054 LLM Jailbreak

Exfiltration

AML.T0056 Extract LLM System Prompt; T1048 Exfiltration Over Alternative Protocol

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Discovery

T1087 Account Discovery

Initial Access

T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise

Collection

T1213 Data from Information Repositories; T1530 Data from Cloud Storage

defense-impairment

T1553 Subvert Trust Controls; T1685 Disable or Modify Tools

Affected products and versions in OWASP GenAI LLM Top 10 2026

  • Microsoft — 365 Copilot
    Vulnerable versions: Pre-patch (before May 2025)
    Fixed in: May 2025 server-side patch (CVE-2025-32711)
  • Amazon Web Services — Amazon Q Developer VS Code Extension
    Vulnerable versions: 1.84.0
    Fixed in: 1.85.0
  • Cursor (Anysphere) — Cursor IDE
    Vulnerable versions: Pre-patch (July 2025 MCP injection incident)
    Fixed in: Patched post-disclosure
  • Various — LLM Application Frameworks
    Vulnerable versions: All versions with agentic capabilities without blast-radius controls
    Fixed in: N/A - requires architectural hardening

Remediation for OWASP GenAI LLM Top 10 2026

Immediate actions

  • Review OWASP GenAI LLM Top 10 2026 for updated risk taxonomy and apply to existing AI application threat models
  • Audit agentic AI systems for Excessive Agency (LLM03): limit tool permissions, implement least-privilege OAuth scopes, enforce human-in-the-loop for high-impact actions
  • Deploy input/output guardrails for all LLM-facing interfaces, including prompt injection detection and output sanitization
  • Implement rate limiting and circuit breakers on LLM API consumption to mitigate Unbounded Consumption (LLM06) Denial-of-Wallet attacks

Workarounds

  • For existing systems: apply read-only scopes to all LLM-connected data tools until agentic permissions are reviewed
  • Use separate, permission-scoped service accounts per AI application rather than generic high-privilege credentials
  • Implement strict content security policies (CSP) to prevent data exfiltration via markdown images and auto-fetched resources

Longer-term hardening

  • Adopt architectural blast-radius controls: minimize tool functionality, enforce complete mediation at the authorization layer rather than relying on LLM judgment
  • Establish AI incident response playbooks aligned with the OWASP GenAI LLM risk taxonomy
  • Implement monitoring and logging for all LLM-invoked tool actions, with graduated enforcement (audit → warn → block → escalate)
  • Integrate framework mappings (NIST AI RMF, MITRE ATLAS, CWE) into AI application security assessments

CVEs associated with OWASP GenAI LLM Top 10 2026

CVE-2025-32711, CVE-2025-8217

Weaknesses (CWE) in OWASP GenAI LLM Top 10 2026

CWE-20, CWE-74, CWE-77, CWE-79, CWE-89, CWE-78, CWE-200, CWE-201, CWE-269, CWE-272

Timeline of OWASP GenAI LLM Top 10 2026

  • NIST AI 600-1 Generative AI Profile published, establishing cross-sectoral AI risk management guidance later referenced by the OWASP GenAI LLM Top 10 2026 framework mappings
  • EchoLeak (CVE-2025-32711) discovered by Aim Labs in Microsoft 365 Copilot — the first documented zero-click AI prompt injection vulnerability in a production system, chaining multiple bypasses (XPIA classifier evasion, reference-style Markdown, auto-fetched images, Teams proxy)
  • Microsoft patches EchoLeak (CVE-2025-32711) server-side — no user action required. Vulnerability classified as LLM Scope Violation, mapping to LLM01, LLM02, and LLM10
  • CVE-2025-32711 published via MSRC with Microsoft-assigned CVSS 9.3 Critical (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N). NVD assigns 7.5 High. CWE-74 Injection
  • AWS-2025-015: threat actor 'lkmanka58' compromises Amazon Q Developer VS Code Extension release pipeline via an inappropriately scoped GitHub token, publishing v1.84.0 with destructive prompt injection (wipe home directory, discover/delete AWS resources). Payload contained syntax error preventing actual execution
  • Amazon Q v1.85.0 released, malicious code removed. AWS revokes compromised credentials and removes v1.84.0 from all distribution channels. CVE-2025-8217 assigned
  • postmark-mcp npm package compromised for approximately 8 days — BCC'd email to an attacker-controlled address, demonstrating trusted-backend indirect injection through MCP
  • NIST AI 600-1 updated for comprehensive cross-sectoral AI risk management, referenced by OWASP GenAI LLM Top 10 2026 as a mapped framework
  • genai_incidents v2.0.0 dataset released by Emmanuel G. Junior Rodrigues — 7,714 consolidated AI security incidents normalized onto OWASP LLM, OWASP ASI, NIST AI RMF, and MITRE ATLAS taxonomies. Sources include OECD AI Incidents Monitor (~2,900), AIAAIC (~1,500), MIT FutureTech (~400 new). DOI: 10.5281/zenodo.20248675
  • OWASP GenAI LLM Top 10 2026 v1.0 published. Hybrid methodology (75% expert voting / 25% incident data). Key shifts: Unbounded Consumption rises 4 positions to LLM06, Improper Output Handling drops from 5th to 10th, Misinformation climbs 2 positions. Project leads: Steve Wilson and Rock Lambros
  • Public announcement of OWASP GenAI LLM Top 10 2026 via Cyber Security News and OWASP GenAI Security Project channels. Framework maps to 5+ industry standards: OWASP ASI, OWASP DSGAI, MITRE ATLAS, MITRE ATT&CK, CWE, NIST AI 600-1/RMF, CSA AI Controls Matrix

Sources cited for OWASP GenAI LLM Top 10 2026

Detection coverage for TL-2026-1913

As of 2026-08-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1913 across Splunk SPL, Microsoft KQL and Sigma, covering 4 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
4 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats