Summary
MSRC’s May and June 2026 machine-readable CVRF feeds add a set of public Windows credits that name Claude or Claude with Anthropic Research:
- CVE-2026-40403, Windows Graphics Component remote code execution.
- CVE-2026-40398, Windows Remote Desktop Services elevation of privilege.
- CVE-2026-40380, Windows Volume Manager Extension Driver remote code execution.
- CVE-2026-40369, Windows Kernel elevation of privilege.
- CVE-2026-42915, Windows VMSwitch denial of service.
Bugflation labels the grouped entry high because the same MSRC credit wave contains high-severity Windows records. Lower-scored shared-credit CVEs remain included in the cluster, but do not imply that every row is individually high.
Attribution
This is direct MSRC acknowledgement evidence. Several records include shared credits, so the entry should be read as public Claude-assisted participation in accepted Microsoft reports rather than proof of exclusive discovery.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.