| AISLE · OpenSSL 12-of-12 Jan 27, 2026 · all 12 advisory-credited |
| CVE-2025-15467 | 2026-01-27 | AISLE | OpenSSL | Critical · 9.8 | Stack buffer overflow in CMS AuthEnvelopedData parsing; pre-auth potential RCE | [1][5] |
| CVE-2025-69419 | 2026-01-27 | AISLE | OpenSSL | High | PKCS#12 character encoding memory corruption | [27] |
| CVE-2025-69420 | 2026-01-27 | AISLE | OpenSSL | High | TimeStamp Response verification crash | [28] |
| CVE-2025-69421 | 2026-01-27 | AISLE | OpenSSL | High | PKCS#12 decryption crash | [29] |
| CVE-2026-22795 | 2026-01-27 | AISLE | OpenSSL | High | PKCS#12 parsing crash | [30] |
| CVE-2025-11187 | 2026-01-27 | AISLE | OpenSSL | Moderate | PBMAC1 parameter validation flaw in PKCS#12 | [1] |
| CVE-2025-15468 | 2026-01-27 | AISLE | OpenSSL | Low | Crash in QUIC protocol cipher handling | [1] |
| CVE-2025-15469 | 2026-01-27 | AISLE | OpenSSL | Low | Silent truncation affecting post-quantum signatures (ML-DSA) | [1] |
| CVE-2025-66199 | 2026-01-27 | AISLE | OpenSSL | Low | Memory exhaustion via TLS 1.3 certificate compression | [1] |
| CVE-2025-68160 | 2026-01-27 | AISLE | OpenSSL | Low | Line-buffering memory corruption (regression back to OpenSSL 1.0.2) | [1] |
| CVE-2025-69418 | 2026-01-27 | AISLE | OpenSSL | Low | Encryption flaw in OCB mode on hardware-accelerated paths | [1] |
| CVE-2026-22796 | 2026-01-27 | AISLE | OpenSSL | Low | Crash in PKCS#7 signature verification; code inherited from SSLeay c. 1998 | [1] |
| AISLE · curl 8.18.0 Jan 7, 2026 · 5 CVEs credited on daniel.haxx.se release notes |
| CVE-2025-11563 | 2026-01-07 | AISLE | curl / wcurl | Low-Med | wcurl flaw (reporter credit on curl.se) | [2] |
| CVE-2025-13034 | 2026-01-07 | AISLE | curl | Low-Med | No QUIC certificate pinning with GnuTLS | [2] |
| CVE-2025-14017 | 2026-01-07 | AISLE | curl | Low-Med | Broken TLS options for threaded LDAPS | [2] |
| CVE-2025-14524 | 2026-01-07 | AISLE | curl | Medium | Bearer token leak on cross-protocol redirect | [2] |
| CVE-2025-14819 | 2026-01-07 | AISLE | curl | Low-Med | OpenSSL partial chain store policy bypass | [2] |
| AISLE · Other OSS targets Jan–Mar 2026 |
| CVE-2026-22695 | 2026-01-12 | AISLE | libpng 1.6.54 | Medium | Heap over-read in png_image_read_direct_scaled | [3] |
| CVE-2026-1964 | 2026-02-05 | AISLE | WeKan ≤8.20 | Medium | REST endpoint vulnerability | [4] |
| CVE-2026-1629 | 2026-02 | AISLE | Mattermost 10.11.x | Medium | Permalink cache disclosure (MMSA-2026-00580) | [4] |
| CVE-2026-24908 | 2026-02-25 | AISLE | OpenEMR | Critical · 10.0 | Critical flaw in OpenEMR | [4] |
| CVE-2026-25554 | 2026-03-19 | AISLE | OpenSIPS | High | JWT SQL injection → authentication bypass (patch merged Feb 2) | [4] |
| CVE-2026-33346 | 2026-03-19 | AISLE | OpenEMR | High · 8.7 | Stored XSS vulnerability | [4] |
| Claude · Firefox / Thunderbird bulk disclosures Feb–Apr 2026 · Anthropic + Mozilla team |
| MFSA-2026-13 | 2026-02-24 | Claude Opus 4.6 | Firefox 148 / Thunderbird 148 | 14H · 7M · 1L | 22 memory-safety and use-after-free CVEs; first bulk Claude-credited browser disclosure | [6][7] |
| MFSA-2026-20 | 2026-03-24 | Claude Opus 4.6 | Firefox 149 / ESR 140.9 | 5M · 1L | 6 Claude-credited CVEs: CVE-2026-4702 / 4723 / 4724 / 4704 / 4705 / 4718 | [8] |
| MFSA-2026-30 | 2026-04-21 | Claude (Mythos) | Firefox 150 | 271 total | 271 vulnerabilities identified during initial Mythos evaluation; 40 numbered CVEs (10H/22M/11L), 3 individually Anthropic-credited | [14][15] |
| CVE-2026-6746 | 2026-04-21 | Claude (Mythos) | Firefox 150 | High | DOM Core & HTML use-after-free | [14] |
| CVE-2026-6757 | 2026-04-21 | Claude (Mythos) | Firefox 150 | Moderate | JavaScript WebAssembly invalid pointer | [14] |
| CVE-2026-6758 | 2026-04-21 | Claude (Mythos) | Firefox 150 | Moderate | JavaScript WebAssembly use-after-free | [14] |
| XBOW · Microsoft Patch Tuesday & HackerOne submissions Mar 2026 · autonomous pentesting |
| CVE-2026-21536 | 2026-03-11 | XBOW | MS Devices Pricing (cloud) | Critical · 9.8 | Unauthenticated RCE via unrestricted file upload; no user interaction | [9][10] |
| CVE-2026-32194 | 2026-03-11 | XBOW | Microsoft Bing | Critical | RCE with potential SYSTEM-level privileges | [9] |
| CVE-2026-32191 | 2026-03-11 | XBOW | Microsoft Bing | Critical | RCE with potential SYSTEM-level privileges | [9] |
| 1,060 submissions | 2026-03-02 | XBOW | HackerOne programs | 54C · 242H · 524M · 65L | Cumulative 1,060 HackerOne submissions over 90-day window | [19][20] |
| Claude (Mythos Preview) · System software Mar–Apr 2026 · Anthropic Frontier Red Team |
| CVE-2026-4747 | 2026-03-26 | Claude (Mythos) | FreeBSD NFS server | Critical | 17-year stack overflow in svc_rpc_gss_validate(); unauth remote kernel root; full ROP chain auto-generated | [11][12] |
| OpenBSD-Errata-025 | 2026-03-25 | Claude (Mythos) | OpenBSD TCP SACK | High | 27-year signed-integer overflow; 2-packet remote kernel crash; patched pre-disclosure | [13] |
| FFmpeg 8.1 | 2026-04-07 | Claude (Mythos) | FFmpeg H.264 parsing | High | 16-year out-of-bounds write in H.264 slice table; survived 5M fuzzer iterations | [13] |
| GHSA-v782-6fq4-q827 | 2026-04-07 | Claude (Mythos) | Randombit Botan | Med-High | Certificate authentication bypass due to trust anchor confusion | [25] |
| CVE-2026-31402 | 2026-04-10 | Claude Code / Opus 4.6 | Linux kernel NFSv4.0 | High | 23-year heap overflow in LOCK replay | [13] |
| Mythos Linux LPEs | 2026-04-07 | Claude (Mythos) | Linux kernel | Local PrivEsc | Race conditions + KASLR bypass chained into local privilege escalation (multiple unassigned CVEs) | [13] |
| Mythos VMM | 2026-04-07 | Claude (Mythos) | Unnamed memory-safe VMM | Critical | Guest-to-host memory corruption (under SHA-3 commitment) | [13] |
| Aggregate & programmatic claims Self-reported · bulk hash commitments |
| Mythos “thousands” | 2026-04-07 | Claude (Mythos) | Every major OS / browser | SHA-3 committed | Thousands of zero-days claimed; 14 SHA-3 hash commitments published; >99% remain unpatched; mandatory disclosure Jul–Sep 2026 | [13][24] |
| 500+ zero-days paper | 2026-02-05 | Claude Opus 4.6 | Open-source projects | 500+ high-severity | Named examples: GhostScript gs_type1_blend, OpenSC strcat, CGIF LZW; no CVEs assigned | [17][18] |
| AISLE 100+ / 180+ | 2026-01 → 04 | AISLE | Linux, glibc, Chromium, WebKit, Samba, Apache, GnuTLS, OpenVPN, NASA CryptoLib | Mixed | 100+ externally-validated CVEs by late Jan; grew to 180+ by April | [4] |
| OpenAI Codex Security | 2026-03-06 | Codex Security (ex-Aardvark) | Open-source projects | Mixed | 10 responsibly-disclosed OSS CVEs + contributions to 3,000+ critical/high fixes | [21] |
| AIxCC Team Atlanta | 2026-02-09 | ATLANTIS CRS | OSS-Fuzz projects | 10 · 3 high | 10 previously unknown bugs (3 high-severity) across 8 OSS-Fuzz projects via OSS-CRS port | [22][23] |
| Third-party integrations AI-assisted, human-filed |
| CVE-2026-34197 | 2026-04-09 | Claude (via Horizon3.ai) | Apache ActiveMQ | Critical | 13-year-old chained unauthenticated RCE; Naveen Sunkavally / Horizon3.ai | [16] |