OWASP: excessive agent authority is now a top LLM risk
OWASP’s 2026 Top 10 for LLM apps moved excessive agent authority from sixth to third, using 6,639 incidents in its weighting; the EU Cyber Resilience Act now requires 24‑hour reports for actively exploited vulnerabilities.