Security researchers at Cyera disclosed ten vulnerabilities in llama.cpp, the widely-used open-source C/C++ inference engine that underlies local AI applications including Ollama, LM Studio, Jan, and GPT4All. The flaws span use-after-free, integer overflow, and out-of-bounds memory access issues across multiple trust boundaries, including the Android JNI bindings and the llama-server HTTP request lifecycle. Two llama-server use-after-free bugs, CVE-2026-43631 and CVE-2026-43632, were each rated CVSS 9.2 and could allow unauthenticated remote code execution. As of the researchers’ most recent check, five of the ten disclosed vulnerabilities remained unpatched. No exploitation in the wild has been reported.