At Black Hat USA 2026 on August 5, security researchers from Check Point disclosed 12 CVEs across four widely used AI agent frameworks – LangChain, CrewAI, Microsoft’s Agent Framework, and Google’s Agent Development Kit (ADK) – showing that attacker-controlled content could cross trust boundaries through the frameworks’ own memory, serialization, and orchestration logic rather than through direct tool calls. In several cases no dangerous function is invoked directly by an attacker; instead a poisoned document saved into an agent’s memory triggers the payload when the framework later reloads it, potentially enabling remote code execution or data theft. The vulnerabilities were disclosed responsibly ahead of the presentation and no active real-world exploitation was reported.