All articles

Bugflation Editorial auditevidencemethodology

August 2026 Source Audit: The Ledger Passes 500 Public CVEs

A primary-source reconciliation adds 134 unique CVE IDs, eight accepted no-CVE campaigns, eleven system profiles, and explicit caveats for unresolved tracker evidence.


The August audit brings Bugflation to 135 grouped finding pages, 517 unique CVE IDs, and 35 system profiles. This pass adds 37 finding pages: 29 carry 134 CVE IDs that did not overlap the previous ledger, and eight cover accepted public campaigns with no CVE mapping.

Those figures preserve three different units. A campaign can group many CVEs, one CVE can credit more than one AI system, and an accepted no-CVE issue is a finding without increasing the unique-CVE counter.

The direct-credit record widened

The largest new affected-project credit is Bouncy Castle’s 29-CVE Claude-assisted campaign. Additional direct Claude credits appear in JFrog Artifactory, Caliptra, Gitea, Apple, and PostgreSQL, bringing 43 new CVEs into the broader Claude profile.

Several July and August release trains independently name AI systems:

Direct credit does not imply exclusive discovery. Where an advisory names other reporters, the finding says so rather than turning participation into a solo claim.

Operator claims remain a separate evidence class

The audit also reconciles public operator disclosures against affected-project records. AISLE contributes a 45-CVE late-July/August wave; Rapid7’s agentic research contributes a two-CVE SharePoint exploit chain; XBREACH contributes nine Microsoft CVEs; and A Security contributes two Zoom CVEs chained into a zero-click meeting-client compromise.

These entries remain self-reported when the vendor or CVE record confirms the vulnerability but does not independently name the AI system. That rule also applies to the new Argus, Fluid AI SAST, pwn.ai, BynarIO, Aretiq, and V12 operator-attributed records.

One exclusion is especially important: A Security discusses CVE-2026-53415 in its Zoomsday report but states that Zoom had already found and fixed it. Bugflation therefore counts only CVE-2026-53413 and CVE-2026-53414 for that campaign.

Accepted no-CVE work is visible

Eight new pages cover public accepted work without a CVE mapping:

The acceptance bar is unchanged: public technical detail alone is not enough. The issue must also have an upstream advisory, merged repair, security release, vendor acknowledgment, or similarly auditable acceptance signal.

Tracker totals are still not ledger totals

AISLE’s registry currently reports 323 assigned CVEs while its paginator exposes 312 public disclosures. Bugflation has reconciled 98 AISLE CVEs into exact campaign records so far and treats the remainder as a staged source queue, not as an automatic import.

Argus exposes 18 public disclosures alongside 159 under-embargo reports. Only the public, disclosed subset is eligible, and reports marked Won’t Fix are held out. The Xint tracker remains at 51 rows with its latest Signal item under embargo. Striga’s now-21-row CVE list is fully represented.

Other large historical queues—including older AISLE rows and vendor trackers whose exact identifiers or acceptance state have not yet been reconciled—also remain outside the count. Headline totals are useful leads, not evidence substitutes.

Six records need continued monitoring

The final registry check found public CVE JSON for 128 of the 134 new IDs. RabbitMQ’s own security page independently lists CVE-2026-67418 through CVE-2026-67421, all published on August 18, even though those four records had not yet reached the public CVE JSON corpus. They remain included with that publication-sync caveat.

Two IDs have only an operator-side public record at this cutoff. AISLE publishes a detailed page for RabbitMQ CVE-2026-67416, but neither the CVE JSON corpus nor RabbitMQ’s security page exposed that ID. Argus publicly maps its OpenBSD TKIP countermeasure report to CVE-2026-56101, but no retrievable CVE.org record was available. Both entries retain explicit source caveats and should be rechecked. The three OP-TEE identifiers in the Argus campaign have public CNA records.

All profile totals are still derived from the finding ledger at build time. The audit scripts also confirmed that the 134 new CVEs have no overlap with the previous 383-ID baseline; known historical duplicates are shared-credit cases and remain deduplicated in the site-wide total.


Published August 19, 2026 by Bugflation Editorial. Follow new articles and findings through the RSS feed.