All findings

CVE-2026-65048 + 44 more critical

AISLE's late-July and August stream adds forty-five public CVE IDs

AISLE's public discovery registry adds forty-five exact CVE IDs across twenty-one projects after Bugflation's July audit cutoff.

Bug class
Memory corruption, authentication and authorization, injection, information disclosure, and denial-of-service flaws
Affected codebase
Ninja Forms, FFmpeg, rpcbind, libsolv, libssh, Saleor, libheif, cJSON, redhat-leapp, yggdrasil, GNOME Remote Desktop, stunnel, libkcapi, p11-kit, RabbitMQ, openvt, mrtg, iperf3, Wireshark, and sblim
Credited system
AISLE
Disclosed
August 18, 2026
Attribution
Self-reported attribution
Severity
critical
Source status: AISLE's registry provides an exact per-CVE claim that its AI-native engine discovered each issue. Forty IDs had public CVE JSON at the audit; RabbitMQ independently lists CVE-2026-67418 through CVE-2026-67421 while the CVE corpus catches up. CVE-2026-67416 remains an AISLE-only public record and is flagged for recheck. The entry does not count AISLE's eleven assigned-but-not-public rows.

Summary

AISLE’s public registry grew by forty-five auditable CVE IDs after the July 20 ledger pass. The stream includes five Ninja Forms issues, six FFmpeg issues, three libssh issues, three cJSON issues, five RabbitMQ issues, and smaller clusters across core networking, cryptography, desktop, and systems projects.

The complete project mapping is:

Attribution boundary

The CVE records establish that the vulnerabilities are public. AISLE’s own registry establishes the AI-native discovery attribution, so this remains a self-reported campaign. The site’s headline of 323 assigned CVEs is not used as a finding count; only its 312 public rows are eligible for reconciliation.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.