OWASP's August 3 edition added no categories and removed none, yet eight of the ten entries changed rank, with Unbounded Consumption up four places and Improper Output Handling down five. Prompt Injection still holds first.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+12
- Incentives70
- Confidence55
A dev.to post argues MCP's attack surface follows from point-to-point model-to-server links and belongs behind an inline gateway. The tool-poisoning path it documents runs through description text that a gateway may forward unchanged.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+35
- Incentives75
- Confidence45
Forcepoint X-Labs hid instructions in zero-pixel white HTML and watched a summarizer repeat them as fact. The measurement is new; two named practitioners say the design flaw it measures has been documented since 2023.
Reality
- Evidence58
- Adoption22
- Hype gap+27
- Incentives72
- Confidence60
OWASP's refreshed list names hidden context exposure and vector weaknesses, maps all ten risks to nine external frameworks, and moves the identifiers that older policy documents cite.
Reality
- Evidence58
- Adoption20
- Hype gap+5
- Incentives40
- Confidence52
The 2026 GenAI LLM Top 10 leaves the first two entries untouched and promotes Excessive Agency three places. The list increasingly reads as guidance for containing damage rather than preventing it.
Reality
- Evidence38
- Adoption34
- Hype gap+14
- Incentives82
- Confidence44