Security researchers disclosed CVE-2026-79696, a maximum-severity (CVSS 10) unauthenticated remote code execution vulnerability in Google’s Agent Development Kit (ADK) for Python, a widely used open-source framework for building AI agents. The flaw allows an attacker to achieve arbitrary code execution by crafting malicious test session replays, without needing any authentication. The disclosure was published on September 9, 2026; no confirmed real-world exploitation had been reported at that time.