Summary
AISLE’s public registry grew by forty-five auditable CVE IDs after the July 20 ledger pass. The stream includes five Ninja Forms issues, six FFmpeg issues, three libssh issues, three cJSON issues, five RabbitMQ issues, and smaller clusters across core networking, cryptography, desktop, and systems projects.
The complete project mapping is:
- Ninja Forms: CVE-2026-65048 through CVE-2026-65052.
- FFmpeg: CVE-2026-64830 through CVE-2026-64835.
- rpcbind: CVE-2026-16277 and CVE-2026-16461.
- libsolv: CVE-2026-48863.
- libssh: CVE-2026-59848, CVE-2026-59849, and CVE-2026-59851.
- Saleor: CVE-2026-48744; libheif: CVE-2026-62377.
- cJSON: CVE-2026-67215 through CVE-2026-67217.
- redhat-leapp: CVE-2026-68562 and CVE-2026-68563.
- yggdrasil: CVE-2026-18157; GNOME Remote Desktop: CVE-2026-18358.
- stunnel: CVE-2026-70367 and CVE-2026-70368.
- libkcapi: CVE-2026-71225 through CVE-2026-71227.
- p11-kit: CVE-2026-18938.
- RabbitMQ: CVE-2026-67416 and CVE-2026-67418 through CVE-2026-67421.
- openvt: CVE-2026-72693; mrtg: CVE-2026-72694.
- iperf3: CVE-2026-71217 and CVE-2026-71218.
- Wireshark: CVE-2026-19696.
- sblim: CVE-2026-73583 through CVE-2026-73585.
Attribution boundary
The CVE records establish that the vulnerabilities are public. AISLE’s own registry establishes the AI-native discovery attribution, so this remains a self-reported campaign. The site’s headline of 323 assigned CVEs is not used as a finding count; only its 312 public rows are eligible for reconciliation.
References
- AISLE CVE discovery registry
- CVE record: CVE-2026-65048
- CVE record: CVE-2026-64830
- AISLE record: CVE-2026-67416
- RabbitMQ security advisories
- CVE record: CVE-2026-73585
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.