All systems

Anthropic and collaborators AI agent

Claude / Anthropic Research

Public Claude-assisted disclosure credits outside the Mythos-only record, spanning browsers, operating systems, cryptography, office documents, cloud auth, CMSs, and Microsoft/Apple platform bugs.

25
Indexed entries
116
CVE IDs tracked
19
Critical/high entries
94%
Evidence index

What it is

This profile covers public disclosures that credit Claude or Anthropic Research without pinning the entry to Claude Mythos Preview by name. It includes researcher-in-the-loop and collaborator workflows, not only autonomous model runs.

What is verified

The current ledger records a larger high-confidence set:

What is not counted

Vulnerabilities in Anthropic’s own products, such as Claude Code or MCP-related issues, are not counted here because they are AI-product attack-surface issues, not AI-attributed discoveries in third-party software. Embargoed Project Glasswing claims also stay out until public advisories or CVE records exist.

Sources

Attributed findings

Catalogued entries credited to Claude / Anthropic Research.

ID Title System Disclosed Severity
CVE-2026-58435 Gitea directly credits Claude-assisted research on LFS deploy-key escalation Deploy-key privilege escalation in Git LFS access control - direct Claude / Anthropic Research (direct) Aug 13, 2026 high CVE-2026-14676 + 3 more PostgreSQL directly credits Claude-assisted research on four RCE-class CVEs Heap overflow, SQL injection, arbitrary-address writes, and type confusion - direct Claude / Anthropic Research (direct) Aug 13, 2026 high CVE-2026-66376 + 3 more JFrog Artifactory directly credits Claude across four authentication flaws Stale credentials, insecure deserialization, SAML verification, and remember-me authentication flaws - direct Claude / Anthropic Research (direct) Aug 12, 2026 high CVE-2026-11835, CVE-2026-11836 Caliptra directly credits Claude on two secure-boot and debug-unlock flaws Secure-boot TOCTOU bypass and production debug-token device-binding weakness - direct Claude / Anthropic Research (direct) Aug 4, 2026 medium CVE-2026-8763 + 28 more Bouncy Castle records twenty-nine Claude-assisted CVEs Cryptographic validation, protocol, parsing, memory, and authentication flaws - direct Claude / Anthropic Research (direct) Aug 2, 2026 critical CVE-2026-64703, CVE-2026-64704, CVE-2026-64757 Apple's July security wave directly credits Claude on three memory-safety CVEs Type confusion, use-after-free, and browser memory corruption - direct Claude / Anthropic Research (direct) Jul 27, 2026 high CVE-2026-50479 Microsoft credits Doyensec collaboration with Claude on USB Hub EoP Untrusted pointer dereference and elevation of privilege - direct Claude / Anthropic Research (direct) Jul 14, 2026 high CVE-2026-43715 Apple credits Claude on WebKit use-after-free Use-after-free and browser memory corruption - direct Claude / Anthropic Research (direct) Jun 29, 2026 high CVE-2026-31504 + 3 more Linux fixes explicitly credit Claude-assisted review across four CVEs Use-after-free, ordering failure, and kernel resource leaks - direct Claude / Anthropic Research (direct) Jun 24, 2026 high CVE-2026-8356 + 6 more Claude-credited LibreOffice June 2026 document-import cluster Document parser memory-safety vulnerabilities - direct Claude / Anthropic Research (direct) Jun 15, 2026 medium CVE-2026-40965, CVE-2026-41005 Cloud Foundry UAA credits Claude-assisted reports for two authentication CVEs Authentication bypass and key disclosure - direct Claude / Anthropic Research (direct) Jun 11, 2026 critical CVE-2026-40403 + 4 more MSRC May and June credits add five Claude-assisted Windows CVEs Windows graphics, kernel, RDP, storage, and VMSwitch vulnerabilities - direct Claude / Anthropic Research (direct) Jun 9, 2026 high CVE-2026-45447 OpenSSL credits Claude-assisted Calif.io report for PKCS7_verify use-after-free PKCS7/S/MIME heap use-after-free - direct Claude / Anthropic Research (direct) Jun 9, 2026 high CVE-2026-47345 TYPO3 credits Doyensec and Claude for HTML Sanitizer XSS Cross-site scripting sanitizer bypass - direct Claude / Anthropic Research (direct) Jun 8, 2026 medium CVE-2026-8462 Claude discovers OpenMeter SQL injection triaged by Anvil Secure Authenticated SQL injection in meter creation - direct Claude / Anthropic Research (direct) Jun 4, 2026 medium CVE-2026-40383, CVE-2026-40384, CVE-2026-48896 Joomla credits Doyensec and Claude on three May 2026 CMS CVEs Local file inclusion, path traversal, and authentication bypass - direct Claude / Anthropic Research (direct) May 26, 2026 high CVE-2026-46633, CVE-2026-46639 Twig 3.26.0 release credits Claude, Anvil Secure, and Claude Mythos Template sandbox bypass and PHP code injection - direct Claude / Anthropic Research (direct) May 20, 2026 critical CVE-2026-6479 PostgreSQL credits Calif.io and Claude for SSL/GSS recursion DoS SSL/GSS initialization recursion denial of service - direct Claude / Anthropic Research (direct) May 14, 2026 high CVE-2026-33096 MDASH and Claude share public credit on HTTP.sys denial of service HTTP.sys denial of service - direct Microsoft MDASH (direct) + Claude / Anthropic Research (direct) May 12, 2026 medium CVE-2026-28952, CVE-2026-28942 Apple May 2026 advisories credit Claude-assisted kernel and WebKit reports Kernel privilege escalation and WebKit browser vulnerability - direct Claude / Anthropic Research (direct) May 11, 2026 high CVE-2026-5398, CVE-2026-6386 FreeBSD April kernel follow-ups credited to Nicholas Carlini using Claude Kernel use-after-free and memory-protection logic flaws - direct Claude / Anthropic Research (direct) Apr 21, 2026 high CVE-2026-41990 Libgcrypt credits Claude-assisted Calif.io report for Dilithium bounds check Post-quantum signature context bounds check - direct Claude / Anthropic Research (direct) Apr 21, 2026 medium CVE-2026-27654 + 8 more Calif.io MADBugs credits Claude on NGINX and wolfSSL findings Web server and cryptographic-library vulnerability cluster - direct Claude / Anthropic Research (direct) Apr 10, 2026 high CVE-2026-34197 Claude-assisted review finds Apache ActiveMQ Jolokia RCE CVE-2026-34197 Jolokia/JMX code execution through network connector configuration - direct Claude / Anthropic Research (direct) Apr 6, 2026 high CVE-2026-2763 + 27 more Mozilla Firefox 148 and 149 advisories credit Claude-assisted research Browser memory-safety and sandbox-relevant vulnerability cluster - direct Claude / Anthropic Research (direct) Mar 24, 2026 high