AI-attributed disclosures, source-first.
This ledger includes public findings where an AI system or AI-driven security platform is named by a primary source or where self-reported attribution is corroborated by a public CVE/vendor record. See the methodology for evidence labels.
ID Title System Disclosed Severity
CVE-2026-65048 + 44 more AISLE's late-July and August stream adds forty-five public CVE IDs Memory corruption, authentication and authorization, injection, information disclosure, and denial-of-service flaws - Ninja Forms, FFmpeg, rpcbind, libsolv, libssh, Saleor, libheif, cJSON, redhat-leapp, yggdrasil, GNOME Remote Desktop, stunnel, libkcapi, p11-kit, RabbitMQ, openvt, mrtg, iperf3, Wireshark, and sblim AISLE (self-reported) Aug 18, 2026 critical CVE-2026-15903, CVE-2026-17658, CVE-2026-76045 Chrome directly credits Codex Security on three new high-severity CVEs Out-of-bounds access and use-after-free in browser execution and graphics engines - Chromium V8 and WebGL OpenAI Aardvark / Codex Security (direct) Aug 18, 2026 high No CVE V12 turns a Redis sibling-eviction use-after-free into remote code execution Heap use-after-free leading to remote code execution - Redis V12 (self-reported) Aug 17, 2026 high CVE-2026-13229, CVE-2026-18403, CVE-2026-63361 Fluid Attacks' AI SAST adds three August CVEs Improper authorization, authenticated SQL injection, and reflected XSS - Zammad and LimeSurvey Community Edition Fluid Attacks AI SAST (direct) Aug 14, 2026 high CVE-2026-58435 Gitea directly credits Claude-assisted research on LFS deploy-key escalation Deploy-key privilege escalation in Git LFS access control - Gitea Git LFS authorization Claude / Anthropic Research (direct) Aug 13, 2026 high CVE-2026-14676 + 3 more PostgreSQL directly credits Claude-assisted research on four RCE-class CVEs Heap overflow, SQL injection, arbitrary-address writes, and type confusion - PostgreSQL core server and contrib modules Claude / Anthropic Research (direct) Aug 13, 2026 high CVE-2026-14680, CVE-2026-16238 PostgreSQL directly credits Codex Security on two type-confusion RCEs Type confusion enabling arbitrary code execution as the database operating-system user - PostgreSQL core server OpenAI Aardvark / Codex Security (direct) Aug 13, 2026 high CVE-2026-14669 Codex Security and V12 share credit on PostgreSQL to_char RCE Heap buffer overflow enabling database-server code execution - PostgreSQL to_char OpenAI Aardvark / Codex Security (direct) + V12 (self-reported) Aug 13, 2026 high CVE-2026-14679 PostgreSQL directly credits DepthFirst AI on stack buffer overflow Stack buffer overflow with controlled writes to server memory - PostgreSQL function argument matching DepthFirst (direct) Aug 13, 2026 high CVE-2026-66376 + 3 more JFrog Artifactory directly credits Claude across four authentication flaws Stale credentials, insecure deserialization, SAML verification, and remember-me authentication flaws - JFrog Artifactory Claude / Anthropic Research (direct) Aug 12, 2026 high CVE-2026-53413, CVE-2026-53414 A Security uses frontier models to build Zoomsday in under a day Remotely reachable stack overwrite and heap over-read chained into zero-click code execution - Zoom annotation protocol and native clients A Security (self-reported) Aug 11, 2026 critical CVE-2026-62912 Aretiq.AI receives a Microsoft Exchange vulnerability credit Remote denial of service - Microsoft Exchange Server Aretiq.AI (self-reported) Aug 11, 2026 medium CVE-2026-65767 Microsoft directly credits Enclave AI on Teams for Android spoofing Mobile-client spoofing and trust-boundary failure - Microsoft Teams for Android Enclave AI (direct) Aug 11, 2026 high CVE-2026-55040, CVE-2026-63520 Rapid7's agentic SharePoint campaign yields a two-CVE unauthenticated-RCE chain JWT authentication bypass chained with authenticated remote code execution - Microsoft SharePoint Server Rapid7 Labs Agentic Research Workflow (self-reported) Aug 11, 2026 critical No CVE V12 chains two Dolphin DSP-HLE memory flaws into a guest-to-host escape Out-of-bounds stack read and indexed stack write chained into guest-to-host code execution - Dolphin Emulator DSP-HLE V12 (self-reported) Aug 11, 2026 high CVE-2026-50351 + 8 more XBreach's Microsoft credit wave spans nine Windows and Azure CVEs Privilege escalation, RCE, security-feature bypass, and information disclosure - Microsoft Windows, Edge, Azure AI Search, Azure CycleCloud, Azure App Service, and Azure Confidential Ledger XBREACH (self-reported) Aug 11, 2026 critical CVE-2026-62746 Microsoft directly credits Xint on Win32k information disclosure Information disclosure - Microsoft Win32k Xint Code (direct) Aug 11, 2026 medium CVE-2026-64638 pwn.ai autonomously chains WordPress XSS into code execution Pre-authentication reflected XSS chained into conditional remote code execution - WordPress core pwn.ai (self-reported) Aug 7, 2026 high CVE-2026-71967 + 3 more Argus discloses four OP-TEE and OpenBSD CVEs Heap underwrite, use-after-free, secure-world denial of service, and wireless countermeasure logic failure - OP-TEE OS and OpenBSD kernel Argus / ByteRay (self-reported) Aug 6, 2026 high CVE-2026-65400 Apple directly credits BynarIO Atlas on Screen Sharing root RCE Pre-authentication remote code execution as root - Apple Screen Sharing BynarIO AI (direct) Aug 6, 2026 critical CVE-2026-16420, CVE-2026-16421, CVE-2026-19168 Chrome directly credits XBOW on three WebAudio and V8 CVEs WebAudio type confusion and implementation flaws plus V8 memory safety - Chromium WebAudio and V8 XBOW (direct) Aug 6, 2026 high CVE-2026-70609 Striga adds an Electron DevTools injection CVE JavaScript injection through an unsanitized DevTools parameter - Electron DevTools dock-state handling Striga AI (self-reported) Aug 5, 2026 medium CVE-2026-11835, CVE-2026-11836 Caliptra directly credits Claude on two secure-boot and debug-unlock flaws Secure-boot TOCTOU bypass and production debug-token device-binding weakness - Caliptra Core ROM and firmware Claude / Anthropic Research (direct) Aug 4, 2026 medium CVE-2026-8763 + 28 more Bouncy Castle records twenty-nine Claude-assisted CVEs Cryptographic validation, protocol, parsing, memory, and authentication flaws - Bouncy Castle Java, LTS, and FIPS libraries Claude / Anthropic Research (direct) Aug 2, 2026 critical CVE-2026-43760 Apple credits Atuin and BynarIO on a Screen Sharing access-control CVE Screen Sharing access-control weakness - Apple Screen Sharing Atuin Automated Vulnerability Discovery Engine (direct) + BynarIO AI (direct) Jul 27, 2026 high CVE-2026-64703, CVE-2026-64704, CVE-2026-64757 Apple's July security wave directly credits Claude on three memory-safety CVEs Type confusion, use-after-free, and browser memory corruption - Apple SMB, WebDAV, and WebKit Claude / Anthropic Research (direct) Jul 27, 2026 high CVE-2026-64783 Apple directly credits Z.AI GLM on a WebKit use-after-free WebKit use-after-free - Apple WebKit Z.AI GLM (direct) Jul 27, 2026 high CVE-2026-39875 Apple credits XBreach.ai on a CUPS root-privilege vulnerability Local privilege escalation to root - Apple CUPS XBREACH (self-reported) Jul 27, 2026 high CVE-2026-43722 + 3 more Apple directly credits ThreatBook XGPT across four system CVEs Kernel state disclosure and use-after-free, SMB remote denial of service, and Libnotify out-of-bounds write - Apple kernel, SMB, and Libnotify ThreatBook XGPT (direct) Jul 27, 2026 high CVE-2026-64744, CVE-2026-64775 Apple's July release directly credits Xint on two kernel CVEs Kernel information disclosure, uninitialized memory, and memory corruption - Apple kernel Xint Code (direct) Jul 27, 2026 high CVE-2026-64450 BynarIO maps a Linux TIPC broadcast parser flaw to CVE-2026-64450 Out-of-bounds read in broadcast Gap ACK block parsing - Linux kernel TIPC BynarIO AI (self-reported) Jul 25, 2026 medium No CVE OpenAI evaluation agents escape a benchmark and reach Hugging Face production Package-proxy compromise chained with local-file disclosure and server-side template injection - OpenAI evaluation infrastructure and Hugging Face production services OpenAI ExploitGym Evaluation Agents (direct) Jul 21, 2026 critical CVE-2026-47729 AISLE and Claude Mythos independently report Squid FTP memory disclosure Response smuggling and process-memory disclosure - Squid FTP gateway AISLE (self-reported) + Claude Mythos Preview (direct) Jul 16, 2026 medium CVE-2026-50479 Microsoft credits Doyensec collaboration with Claude on USB Hub EoP Untrusted pointer dereference and elevation of privilege - Microsoft Windows USB Hub Driver Claude / Anthropic Research (direct) Jul 14, 2026 high CVE-2026-5135 + 9 more AISLE's July disclosure stream spans ten CVEs in seven projects Authorization, injection, XSS, parser, denial-of-service, and memory-safety flaws - Foreman, Gitea, Joomla, Wireshark, dhcpcd, n8n, and alsa-lib AISLE (self-reported) Jul 8, 2026 high No CVE XGPT finds three libseccomp filter-generation vulnerabilities Incorrect security-policy generation, double-free, and heap corruption - libseccomp ThreatBook XGPT (direct) Jul 1, 2026 medium CVE-2026-14431 Chrome directly credits Codex Security on V8 type-confusion CVE Type confusion - Google Chrome V8 OpenAI Aardvark / Codex Security (direct) + OpenAI Daybreak (direct) Jun 30, 2026 high CVE-2026-13858 Chrome credits Theori with Xint Code on FFmpeg out-of-bounds read Out-of-bounds read - Chromium FFmpeg integration Xint Code (direct) Jun 30, 2026 medium CVE-2026-14077 Chrome directly credits pwn.ai on security-UI CVE Incorrect security UI - Google Chrome Select UI pwn.ai (direct) Jun 30, 2026 low CVE-2026-49427, CVE-2026-49428 FreeBSD credits OpenAI Codex Security on two POSIX shared-memory CVEs Kernel memory corruption and local privilege escalation - FreeBSD POSIX shared memory OpenAI Aardvark / Codex Security (direct) Jun 30, 2026 high CVE-2026-45253 + 7 more FreeBSD advisories directly credit Z.AI GLM across eight CVEs Privilege escalation, use-after-free, state leakage, and filesystem boundary failures - FreeBSD kernel, libc, and ZFS Z.AI GLM (direct) Jun 30, 2026 high CVE-2026-49420 Atuin and AISLE converge on FreeBSD libalias stack overflow Remotely reachable stack buffer overflow - FreeBSD libalias Atuin Automated Vulnerability Discovery Engine (direct) + AISLE (self-reported) Jun 30, 2026 high No CVE V12 publishes twelve accepted Miden Node findings Validation, denial-of-service, state-consistency, and protocol-logic flaws - Miden Node V12 (self-reported) Jun 30, 2026 high CVE-2026-43707, CVE-2026-43716, CVE-2026-43745 Apple credits Codex Security on three June 2026 WebKit CVEs Memory corruption, memory-handling crash, and out-of-bounds write - Apple WebKit OpenAI Aardvark / Codex Security (direct) Jun 29, 2026 high CVE-2026-43663 Apple credits researchers using Z.AI GLM on WebKit CVE WebKit memory-handling failure and browser crash - Apple WebKit Z.AI GLM (direct) Jun 29, 2026 high CVE-2026-43715 Apple credits Claude on WebKit use-after-free Use-after-free and browser memory corruption - Apple WebKit Claude / Anthropic Research (direct) Jun 29, 2026 high No CVE V12 reports storage-exhaustion and GC bypass in NEAR Intents Storage exhaustion and garbage-collection bypass - NEAR Intents V12 (self-reported) Jun 25, 2026 medium No CVE V12 finds plaintext GridPlus pairing credentials in Rabby Wallet Plaintext storage of hardware-wallet pairing credentials - Rabby Wallet GridPlus integration V12 (self-reported) Jun 25, 2026 medium CVE-2026-8925 + 5 more curl 8.21.0 credits AISLE Research on six CVEs Double-free, credential disclosure, authentication-state leakage, and protocol confusion - curl and libcurl AISLE (self-reported) Jun 24, 2026 medium CVE-2026-31504 + 3 more Linux fixes explicitly credit Claude-assisted review across four CVEs Use-after-free, ordering failure, and kernel resource leaks - Linux kernel networking, EDAC, NFS, and amd-pstate Claude / Anthropic Research (direct) Jun 24, 2026 high CVE-2026-8286 Mythos finds curl STARTTLS connection-reuse flaw Incorrect STARTTLS connection reuse - curl and libcurl Claude Mythos Preview (direct) Jun 24, 2026 low CVE-2026-49975 Codex-assisted HTTP/2 Bomb reaches Apache and other major servers HTTP/2 denial of service through decompression work amplification - Apache HTTP Server and HTTP/2 server implementations OpenAI Aardvark / Codex Security (direct) + OpenAI Daybreak (direct) Jun 22, 2026 medium CVE-2026-8390 GPT-5.5 safety evaluation surfaces high-severity Firefox WebAssembly UAF Use-after-free in browser JavaScript engine - Mozilla Firefox WebAssembly OpenAI Daybreak (direct) Jun 22, 2026 high CVE-2026-45250, CVE-2026-45251, CVE-2026-45253 Calif and Codex validate three FreeBSD local-privilege-escalation CVEs Use-after-free, credential confusion, and local privilege escalation - FreeBSD kernel and credential handling OpenAI Aardvark / Codex Security (direct) + OpenAI Daybreak (direct) Jun 22, 2026 high CVE-2026-4890 + 3 more Codex Security independently identifies four fixed dnsmasq CVEs DNS and DHCP parser memory-safety and denial-of-service flaws - dnsmasq OpenAI Aardvark / Codex Security (direct) + OpenAI Daybreak (direct) Jun 22, 2026 medium No CVE OpenAI Daybreak finds and patches 23-year-old OpenBSD semaphore UAF Use-after-free and local privilege escalation - OpenBSD kernel OpenAI Daybreak (direct) Jun 22, 2026 high CVE-2026-8356 + 6 more Claude-credited LibreOffice June 2026 document-import cluster Document parser memory-safety vulnerabilities - LibreOffice Claude / Anthropic Research (direct) Jun 15, 2026 medium CVE-2026-40965, CVE-2026-41005 Cloud Foundry UAA credits Claude-assisted reports for two authentication CVEs Authentication bypass and key disclosure - Cloud Foundry UAA Claude / Anthropic Research (direct) Jun 11, 2026 critical No CVE Argus finds cross-user dashboard disclosure in Zabbix report.test Insecure direct object reference and broken authorization - Zabbix Server Argus (self-reported) Jun 10, 2026 high CVE-2026-40403 + 4 more MSRC May and June credits add five Claude-assisted Windows CVEs Windows graphics, kernel, RDP, storage, and VMSwitch vulnerabilities - Microsoft Windows Claude / Anthropic Research (direct) Jun 9, 2026 high CVE-2026-49160 MSRC credits Codex collaboration for HTTP.sys denial of service HTTP/2 resource-consumption denial of service - Microsoft Windows HTTP.sys OpenAI Aardvark / Codex Security (direct) Jun 9, 2026 high CVE-2026-45447 OpenSSL credits Claude-assisted Calif.io report for PKCS7_verify use-after-free PKCS7/S/MIME heap use-after-free - OpenSSL Claude / Anthropic Research (direct) Jun 9, 2026 high CVE-2026-9279 + 17 more Striga's public tracker adds eighteen validated CVEs across eleven projects RCE, authorization bypass, credential theft, denial-of-service, and injection flaws - Logseq, Apache Shiro, Apple container, Ollama, pac4j, Tomcat, axios, n8n, Mattermost Desktop, OpenClaw, and FreshRSS Striga AI (self-reported) Jun 9, 2026 critical CVE-2026-29167, CVE-2026-29170 Apache httpd credits AISLE Research on two 2.4.68 CVEs Request-processing and module-boundary vulnerabilities - Apache HTTP Server AISLE (self-reported) Jun 8, 2026 low No CVE Argus finds SSH identity confusion in libcurl connection reuse Authentication-context confusion in connection pooling - curl / libcurl Argus (self-reported) Jun 8, 2026 high CVE-2026-44631 DepthFirst and Striga share credit on Apache httpd heap underflow Heap underflow - Apache HTTP Server DepthFirst (self-reported) + Striga AI (self-reported) Jun 8, 2026 low CVE-2026-34356 + 5 more Apache httpd 2.4.68 credits DepthFirst across six additional CVEs Request-processing, module-boundary, denial-of-service, and memory-safety flaws - Apache HTTP Server DepthFirst (self-reported) Jun 8, 2026 medium CVE-2026-6385 Calif.io credits OpenAI Codex on FFmpeg parser CVE Signed integer overflow and media-parser memory corruption - FFmpeg OpenAI Aardvark / Codex Security (direct) Jun 8, 2026 medium CVE-2026-47345 TYPO3 credits Doyensec and Claude for HTML Sanitizer XSS Cross-site scripting sanitizer bypass - TYPO3 HTML Sanitizer Claude / Anthropic Research (direct) Jun 8, 2026 medium CVE-2026-8462 Claude discovers OpenMeter SQL injection triaged by Anvil Secure Authenticated SQL injection in meter creation - OpenMeter Claude / Anthropic Research (direct) Jun 4, 2026 medium CVE-2026-39210 + 8 more DepthFirst publishes twenty-one fixed FFmpeg zero-days Heap and stack overflows, integer overflow, and out-of-bounds access - FFmpeg DepthFirst (self-reported) Jun 2, 2026 high CVE-2026-9973 Chrome credits OpenAI researcher on V8 out-of-bounds write Out-of-bounds write - Google Chrome V8 OpenAI Daybreak (self-reported) May 27, 2026 high CVE-2026-40383, CVE-2026-40384, CVE-2026-48896 Joomla credits Doyensec and Claude on three May 2026 CMS CVEs Local file inclusion, path traversal, and authentication bypass - Joomla CMS Claude / Anthropic Research (direct) May 26, 2026 high CVE-2026-48092 + 7 more GitHub's AI-agent index adds eight fixed 7-Zip CVEs Heap buffer overflow, memory disclosure, out-of-bounds access, integer overflow, and path traversal - 7-Zip archive and filesystem-image parsers GitHub Security Lab AI agent (unspecified) (direct) May 22, 2026 high No CVE GitHub Taskflow Agent yields 24 accepted reports without CVEs SQL injection, attachment exfiltration, authorization bypass, action injection, and data exposure - Twenty web applications, libraries, and GitHub Actions workflows GitHub Security Lab Taskflow Agent (direct) May 22, 2026 high CVE-2026-39461, CVE-2026-45252, CVE-2026-45254 FreeBSD credits AISLE Research on three more May 2026 CVEs Stack overflow, heap overflow, and capability-sandbox bypass - FreeBSD libcasper, fusefs, and cap_net AISLE (self-reported) May 20, 2026 high CVE-2026-27654 + 17 more Anthropic CVD dashboard reveals fixed Mythos Preview open-source findings Project Glasswing CVD cluster: path traversal, broken access control, SSRF, heap overflow, SQL injection, RCE, and privilege escalation - Multiple open-source projects Claude Mythos Preview (direct) May 20, 2026 critical CVE-2026-45067 Symfony credits Claude Mythos on SMTP command-injection CVE Email header and SMTP command injection - Symfony Mime Claude Mythos Preview (direct) May 20, 2026 medium CVE-2026-23194 + 3 more Gemini CLI and review agents surface four Linux kernel CVEs Out-of-bounds access, NULL dereference, infinite loop, and allocation wraparound - Linux Android Binder, tracing, wlcore, and ext4 Google Gemini security review agents (direct) May 20, 2026 high CVE-2026-46633, CVE-2026-46639 Twig 3.26.0 release credits Claude, Anvil Secure, and Claude Mythos Template sandbox bypass and PHP code injection - Twig Claude / Anthropic Research (direct) May 20, 2026 critical CVE-2026-43617 + 6 more ZeroPath public research adds seven CVEs and one reserved Monaco report Authorization bypass, session hijacking, RCE, denial-of-service, and local file inclusion - rsync, AutoGPT, Keycloak, OpenClaw, Monaco, Avahi, E2nest, and Fonoster ZeroPath AI SAST (self-reported) May 20, 2026 critical CVE-2026-23967, CVE-2026-5807, CVE-2026-6475 Atuin public CVE-backed cluster spans sm-crypto, Vault, and PostgreSQL Cryptographic signature malleability, denial of service, and symlink following - sm-crypto, HashiCorp Vault, PostgreSQL Atuin Automated Vulnerability Discovery Engine (direct) May 14, 2026 high CVE-2026-6479 PostgreSQL credits Calif.io and Claude for SSL/GSS recursion DoS SSL/GSS initialization recursion denial of service - PostgreSQL Claude / Anthropic Research (direct) May 14, 2026 high CVE-2026-6473, CVE-2026-6474 PostgreSQL May 2026 release credits Xint Code on two CVEs Server memory corruption and memory disclosure - PostgreSQL Xint Code (direct) May 14, 2026 high CVE-2026-42945 + 3 more DepthFirst autonomously finds NGINX Rift and three companion CVEs NGINX memory-corruption cluster led by rewrite-module heap overflow RCE - NGINX Open Source and NGINX Plus DepthFirst (self-reported) May 13, 2026 critical CVE-2026-46300 Fragnesia: V12-assisted Linux kernel page-cache LPE CVE-2026-46300 Shared page-fragment marker loss leading to page-cache corruption and local privilege escalation - Linux kernel XFRM ESP-in-TCP / skbuff V12 (direct) May 13, 2026 high CVE-2026-0235 + 25 more Palo Alto Networks reports 26-CVE frontier-AI scan wave Vendor-scale frontier-AI vulnerability-discovery wave across PAN-OS, GlobalProtect, Prisma, Cortex, WildFire, Browser, and related products - Palo Alto Networks products Palo Alto frontier AI scan (self-reported) May 13, 2026 high CVE-2026-33096 MDASH and Claude share public credit on HTTP.sys denial of service HTTP.sys denial of service - Microsoft Windows HTTP.sys Microsoft MDASH (direct) + Claude / Anthropic Research (direct) May 12, 2026 medium CVE-2026-33827 + 14 more Microsoft MDASH publishes 15-CVE Windows networking cohort Windows network-stack and authentication vulnerability-discovery cluster - Windows TCP/IP, IKEEXT, Netlogon, DNS, HTTP.sys, Telnet Microsoft MDASH (direct) May 12, 2026 critical CVE-2026-45185 XBOW reports unauthenticated Exim RCE in Dead.Letter disclosure GnuTLS BDAT use-after-free remote code execution - Exim XBOW (self-reported) May 12, 2026 critical CVE-2026-28952, CVE-2026-28942 Apple May 2026 advisories credit Claude-assisted kernel and WebKit reports Kernel privilege escalation and WebKit browser vulnerability - Apple kernel, WebKit Claude / Anthropic Research (direct) May 11, 2026 high CVE-2026-28972, CVE-2026-28986 Apple credits Xint Code on two May 2026 kernel CVEs Kernel race condition and information leakage - Apple kernel Xint Code (direct) May 11, 2026 medium CVE-2026-31532 Bynario AI assists Linux CAN raw socket UAF fix RCU teardown race causing use-after-free of per-CPU CAN raw socket state - Linux kernel CAN raw sockets BynarIO AI (direct) May 7, 2026 high CVE-2026-39816 ZeroPath finds Apache NiFi Execute Code permission bypass CVE-2026-39816 Authorization bypass leading to server-side code execution - Apache NiFi ZeroPath AI SAST (self-reported) May 7, 2026 high CVE-2026-39852 + 23 more GitHub Taskflow Agent produces 24 public CVEs across thirteen projects Authorization bypass, data exposure, XSS, CSRF, and business-logic vulnerabilities - Quarkus, Docmost, Frappe, NocoDB, Sylius, Spree, Rocket.Chat, Wekan, WooCommerce, homeassistant-tapo-control, Outline, bit platform, and Sentry GitHub Security Lab Taskflow Agent (direct) May 6, 2026 high CVE-2026-23918 Striga says its Apache httpd scan surfaced CVE-2026-23918 HTTP/2 double free with possible remote code execution - Apache HTTP Server Striga AI (self-reported) May 4, 2026 high CVE-2026-31694 Bynario AI assists Linux FUSE page-cache overflow fix Oversized FUSE dirent copied into a single page-cache page - Linux kernel FUSE readdir cache BynarIO AI (direct) May 1, 2026 high CVE-2025-68388 + 5 more AISLE analyzer finds Elastic Beats denial-of-service cluster Network and telemetry parser denial-of-service vulnerabilities - Elastic Beats AISLE (self-reported) Apr 30, 2026 medium CVE-2026-42511, CVE-2026-42512, CVE-2026-39457 AISLE finds FreeBSD dhclient root RCE and two companion core CVEs DHCP client command injection, heap overflow, and libnv stack overflow - FreeBSD dhclient / libnv AISLE (self-reported) Apr 29, 2026 high CVE-2026-31431 CopyFail: Linux kernel page-cache write to root found with Xint Code Incorrect resource transfer -> page-cache corruption -> local privilege escalation - Linux kernel crypto subsystem Xint Code (direct) Apr 29, 2026 high CVE-2026-6100 + 6 more Xint public tracker adds seven CVE-backed findings beyond CopyFail Memory-safety and parser vulnerabilities across open-source server and runtime projects - CPython, CUPS, NGINX, mruby, MariaDB, PostgreSQL Xint Code (self-reported) Apr 29, 2026 critical CVE-2026-42167 ZeroPath finds ProFTPD mod_sql CVE-2026-42167 SQL injection in FTP SQL logging and authentication paths - ProFTPD ZeroPath AI SAST (self-reported) Apr 28, 2026 high CVE-2025-9230 + 19 more AISLE autonomous analyzer finds a 20-CVE OpenSSL run Cryptographic-library vulnerability cluster - OpenSSL AISLE (self-reported) Apr 24, 2026 high CVE-2026-5398, CVE-2026-6386 FreeBSD April kernel follow-ups credited to Nicholas Carlini using Claude Kernel use-after-free and memory-protection logic flaws - FreeBSD kernel Claude / Anthropic Research (direct) Apr 21, 2026 high CVE-2026-41990 Libgcrypt credits Claude-assisted Calif.io report for Dilithium bounds check Post-quantum signature context bounds check - Libgcrypt Claude / Anthropic Research (direct) Apr 21, 2026 medium CVE-2026-6746, CVE-2026-6757, CVE-2026-6758 Firefox 150 ships fixes for 271 Mythos-identified vulnerabilities Browser vulnerability cluster - Mozilla Firefox Claude Mythos Preview (direct) Apr 21, 2026 high CVE-2026-32604, CVE-2026-32613 ZeroPath discloses two critical Spinnaker RCE CVEs Command injection and Spring Expression Language code injection in deployment services - Spinnaker ZeroPath AI SAST (self-reported) Apr 20, 2026 critical CVE-2026-26168 Microsoft credits Atuin on Windows AFD Winsock elevation of privilege Kernel elevation of privilege - Microsoft Windows Ancillary Function Driver for Winsock Atuin Automated Vulnerability Discovery Engine (direct) Apr 14, 2026 high CVE-2026-27654 + 8 more Calif.io MADBugs credits Claude on NGINX and wolfSSL findings Web server and cryptographic-library vulnerability cluster - NGINX / wolfSSL Claude / Anthropic Research (direct) Apr 10, 2026 high CVE-2026-4747 FreeBSD NFS remote kernel RCE identified and exploited by Claude Mythos Preview Remote kernel memory corruption -> root code execution - FreeBSD NFS / RPCSEC_GSS Claude Mythos Preview (direct) Apr 7, 2026 critical CVE-2026-34197 Claude-assisted review finds Apache ActiveMQ Jolokia RCE CVE-2026-34197 Jolokia/JMX code execution through network connector configuration - Apache ActiveMQ Claude / Anthropic Research (direct) Apr 6, 2026 high CVE-2026-2763 + 27 more Mozilla Firefox 148 and 149 advisories credit Claude-assisted research Browser memory-safety and sandbox-relevant vulnerability cluster - Mozilla Firefox Claude / Anthropic Research (direct) Mar 24, 2026 high CVE-2026-32191 Microsoft Bing Images OS command injection credited by XBOW OS command injection -> remote code execution - Microsoft Bing Images XBOW (self-reported) Mar 19, 2026 critical CVE-2026-32194 Microsoft Bing Images command injection credited by XBOW Command injection -> remote code execution - Microsoft Bing Images XBOW (self-reported) Mar 19, 2026 critical CVE-2025-32988 + 13 more OpenAI Codex Security publishes OSS CVE examples Open-source vulnerability discovery and validation cluster - GnuTLS, Gogs, Thorium, GnuPG OpenAI Aardvark / Codex Security (direct) Mar 6, 2026 high CVE-2026-21536 Microsoft Devices Pricing Program critical RCE credited by XBOW Remote code execution - Microsoft Devices Pricing Program XBOW (self-reported) Mar 5, 2026 critical No CVE Aether finds a two-part OpenClaw tool-permission escalation Improper tool authorization and unsafe permission auto-approval - OpenClaw gateway and ACP clients Aether AI (direct) Mar 2, 2026 high No CVE Endor Labs AI SAST finds SSRF in OpenClaw's Image tool Server-side request forgery in remote media fetching - OpenClaw Endor Labs AI SAST (direct) Feb 17, 2026 high CVE-2025-40345, CVE-2025-68352, CVE-2025-68797 Linux records three CVEs discovered by Atuin Heap corruption, out-of-bounds access, and NULL dereference - Linux USB storage, CH341 SPI, and applicom drivers Atuin Automated Vulnerability Discovery Engine (direct) Jan 13, 2026 high CVE-2025-68246, CVE-2025-68811 Linux fixes credit ZeroPath on ksmbd and svcrdma CVEs Remote resource exhaustion and memory-copy boundary error - Linux ksmbd and svcrdma ZeroPath AI SAST (direct) Jan 13, 2026 high CVE-2025-43535, CVE-2025-46299 Apple WebKit 26.2 follow-up issues credited to Google Big Sleep WebKit memory handling / internal-state disclosure - Apple WebKit / iOS and iPadOS Google Big Sleep (direct) Jan 9, 2026 medium No CVE ZeroPath AI SAST reports seven FFmpeg memory-safety fixes Memory-safety and protocol logic vulnerability cluster - FFmpeg ZeroPath AI SAST (self-reported) Dec 2, 2025 high CVE-2025-8901 + 10 more Chrome directly credits Big Sleep on eleven additional 2025 CVEs Out-of-bounds write, heap overflow, integer overflow, use-after-free, and type confusion - Google Chrome V8 and ANGLE Google Big Sleep (direct) Nov 17, 2025 high No CVE ZeroPath AI Security Engineer credited on sudo exec_mailer fix Incomplete privilege drop in sudo mailer execution - sudo ZeroPath AI SAST (direct) Nov 8, 2025 high CVE-2025-43429 + 4 more Apple WebKit 26.1 security cluster credited to Google Big Sleep WebKit memory-safety cluster - Apple WebKit / Safari Google Big Sleep (direct) Nov 3, 2025 high CVE-2025-43377 Apple credits BynarIO AI on Model I/O CVE-2025-43377 Out-of-bounds read in Model I/O media parsing - Apple Model I/O / USD library BynarIO AI (direct) Nov 3, 2025 medium CVE-2025-12443 Chrome directly credits AISLE Research on 2025 security fix Out-of-bounds read - Google Chrome WebXR AISLE (self-reported) Oct 28, 2025 medium CVE-2025-61928 ZeroPath scanner finds better-auth API key takeover CVE-2025-61928 Authentication bypass in API key creation and update routes - better-auth ZeroPath AI SAST (self-reported) Oct 19, 2025 high CVE-2025-9478 Chrome ANGLE use-after-free reported by Google Big Sleep Use-after-free -> heap corruption - Google Chrome ANGLE Google Big Sleep (direct) Aug 26, 2025 critical CVE-2025-9132 Chrome V8 out-of-bounds write reported by Google Big Sleep Out-of-bounds write -> heap corruption - Google Chrome V8 Google Big Sleep (direct) Aug 19, 2025 high CVE-2025-54322 pwn.ai reports unauthenticated root RCE in XSpeeder SXZOS Unauthenticated OS command injection and root code execution - XSpeeder SXZOS pwn.ai (self-reported) Jul 22, 2025 critical CVE-2025-6965 SQLite aggregate-term memory corruption found by Big Sleep Aggregate-term accounting -> memory corruption - SQLite Google Big Sleep (direct) Jul 15, 2025 high CVE-2024-56737 + 19 more Microsoft Security Copilot accelerates GRUB2, U-Boot, and Barebox findings Bootloader memory corruption and Secure Boot bypass-relevant flaws - GRUB2, U-Boot, Barebox Microsoft Security Copilot (direct) Mar 31, 2025 high CVE-2024-9143 Google OSS-Fuzz AI finds OpenSSL CVE-2024-9143 AI-generated fuzz target vulnerability discovery - OpenSSL / OSS-Fuzz projects Google OSS-Fuzz AI (direct) Nov 20, 2024 medium No CVE Big Sleep finds an exploitable SQLite stack buffer underflow before release Stack buffer underflow - SQLite Google Big Sleep (direct) Nov 1, 2024 high