Tracking Vulnerabilities That Appear to be Credited to the Anthropic Research Team
80
2,413 commits
updated Oct 4, 2026
Tracking vulnerabilities that credit the Anthropic research team and are possibly discovered by Project Glasswing.
CURRENT CVE COUNT: 300
Fixed Anthropic Findings w/o CVE: 128
Findings Withdrawn by Anthropic: 243
|
|
|
If you find an Anthropic credited vulnerability, please open a Pull Request or Send me a message on linkedin or in the Extended Vulnerability Community Discord.
This project is maintained on a best effort basis.
| CVE | Date | Vendor | Product | CVSS | Ledger | vcKEV | Credit |
|---|---|---|---|---|---|---|---|
| CVE-2026-103604 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.7 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-103603 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.7 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-103602 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.2 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-103601 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.2 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-66858 | 2026-10-02 | Apache Software Foundation | Apache Thrift | 8.7 | Claude (Anthropic Research) | Arthur Chan, Ada Logics | Apache Thrift Developers | ||
| CVE-2026-66837 | 2026-10-02 | Apache Software Foundation | Apache Thrift | 8.7 | Claude (Anthropic Research) | Arthur Chan, Ada Logics (arthur.chan@adalogics.com) | ||
| CVE-2026-66081 | 2026-10-02 | Apache Software Foundation | Apache Thrift | 8.7 | Akhil Koul | Claude (Anthropic Research) | Arthur Chan, Ada Logics (arthur.chan@adalogics.com) | ||
| CVE-2026-63772 | 2026-10-02 | Apache Software Foundation | Apache Thrift | 8.7 | Anthropic (agentic research) + Ada Logics; reported by Adam Korczynski | ||
| CVE-2026-63578 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 7.1 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-63577 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.2 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-63576 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.2 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-63574 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.7 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-63573 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.2 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-63571 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.7 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-63570 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 7.1 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-63569 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 9.1 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-63568 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.7 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-63567 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.2 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-63566 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.7 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-61373 | 2026-10-02 | Apache Software Foundation | Apache Thrift | 8.7 | Claude (Anthropic Research) | Arthur Chan, Ada Logics (arthur.chan@adalogics.com) | n0mi1k | ||
| CVE-2026-17508 | 2026-10-02 | Legion of the Bouncy Castle Inc. | BC-JAVA | 5.3 | Mirko Swillus on behalf of Alpha-Omega (alpha-omega.dev), using Scrutineer with an Anthropic Claude model provided through Project Glasswing | Yu Bao from the PayPal Cyber Security Team | ||
| CVE-2026-17507 | 2026-10-02 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Mirko Swillus on behalf of Alpha-Omega (alpha-omega.dev), using Scrutineer with an Anthropic Claude model provided through Project Glasswing | ||
| CVE-2026-16001 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.2 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-16000 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.7 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-15999 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.2 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-93546 | 2026-10-01 | Apache Software Foundation | Apache HTTP Server | 8.8 | Zhen Kong | Calif.io in collaboration with Anthropic | AISLE in partnership with Red Hat | ||
| CVE-2026-101283 | 2026-09-30 | esnet | iperf3 | 9.2 | Anthropic | Ada Logics | ||
| CVE-2026-101276 | 2026-09-30 | esnet | iperf3 | 9.2 | Anthropic | Ada Logics | ||
| CVE-2026-96423 | 2026-09-29 | Wireshark Foundation | Wireshark | 5.5 | Claude and Ada Logics | ||
| CVE-2026-96421 | 2026-09-29 | Wireshark Foundation | Wireshark | 5.5 | Claude and Ada Logics | ||
| CVE-2026-96418 | 2026-09-29 | Wireshark Foundation | Wireshark | 5.5 | Credit: Claude and Ada Logics | ||
| CVE-2026-96416 | 2026-09-29 | Wireshark Foundation | Wireshark | 5.5 | Claude and Ada Logics | ||
| CVE-2026-92222 | 2026-09-29 | Joomla! Project | Joomla! CMS | 8.9 | Aria Akhavan | Calif.io in collaboration with Anthropic | ||
| CVE-2026-90915 | 2026-09-29 | Joomla! Project | Joomla! CMS | 7.0 | Aria Akhavan | Calif.io in collaboration with Anthropic | ||
| CVE-2026-94419 | 2026-09-27 | wolfSSL | wolfSSL | 2.3 | Anthropic OSS program | ||
| CVE-2026-94418 | 2026-09-27 | wolfSSL | wolfSSL | 2.3 | Anthropic OSS program | ||
| CVE-2026-94417 | 2026-09-27 | wolfSSL | wolfSSL | 2.3 | Anthropic OSS program | ||
| CVE-2026-93304 | 2026-09-27 | wolfSSL | wolfSSL | 6.3 | Anthropic OSS program | ||
| CVE-2026-93302 | 2026-09-27 | wolfSSL | wolfSSL | 8.3 | Anthropic OSS program | ||
| CVE-2026-98134 | 2026-09-25 | Linux | Linux | ||||
| CVE-2026-98085 | 2026-09-25 | Linux | Linux | ||||
| CVE-2026-98062 | 2026-09-25 | Linux | Linux | 5.5 | Reported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com | ||
| CVE-2026-98061 | 2026-09-25 | Linux | Linux | Reported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com | |||
| CVE-2026-98060 | 2026-09-25 | Linux | Linux | Reported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com | |||
| CVE-2026-98058 | 2026-09-25 | Linux | Linux | Reported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com | |||
| CVE-2026-98049 | 2026-09-25 | Linux | Linux | Reported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com | |||
| CVE-2026-98047 | 2026-09-25 | Linux | Linux | Reported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com | |||
| CVE-2026-98040 | 2026-09-25 | Linux | Linux | Reported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com | |||
| CVE-2026-98038 | 2026-09-25 | Linux | Linux | Reported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com | |||
| CVE-2026-98037 | 2026-09-25 | Linux | Linux | Reported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com | |||
| CVE-2026-98036 | 2026-09-25 | Linux | Linux | Reported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com | |||
| CVE-2026-98034 | 2026-09-25 | Linux | Linux | Reported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com | |||
| CVE-2026-98033 | 2026-09-25 | Linux | Linux | Reported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com | |||
| CVE-2026-97524 | 2026-09-25 | Linux | Linux | 7.5 | Reported-by: Xinyang Ge xinyang@anthropic.com | ||
| CVE-2026-97523 | 2026-09-25 | Linux | Linux | 7.5 | Reported-by: Xinyang Ge xinyang@anthropic.com | ||
| CVE-2026-96812 | 2026-09-25 | gVisor | 8.8 | Anthropic (using Claude) | |||
| CVE-2026-89422 | 2026-09-22 | Erlang | OTP | 9.3 | Milad Nasr / Anthropic | Luna Tong / Anthropic | Ingela Andin | ||
| CVE-2026-63276 | 2026-09-22 | The Document Foundation | LibreOffice | 5.4 | 🔗 | Claude, found by Anthropic using agents to study the security of open-source projects | Ada Logics, validating and reporting | Caolán McNamara of Collabora Productivity | |
| CVE-2026-63275 | 2026-09-22 | The Document Foundation | LibreOffice | 5.4 | 🔗 | Claude, found by Anthropic using agents to study the security of open-source projects | Ada Logics, validating and reporting | Caolán McNamara of Collabora Productivity | |
| CVE-2026-63274 | 2026-09-22 | The Document Foundation | LibreOffice | 5.4 | 🔗 | Claude, found by Anthropic using agents to study the security of open-source projects | Ada Logics, validating and reporting | Caolán McNamara of Collabora Productivity | |
| CVE-2026-63273 | 2026-09-22 | The Document Foundation | LibreOffice | 5.4 | 🔗 | Claude, found by Anthropic using agents to study the security of open-source projects | Ada Logics, validating and reporting | Caolán McNamara of Collabora Productivity | |
| CVE-2026-63272 | 2026-09-22 | The Document Foundation | LibreOffice | 5.4 | 🔗 | Claude, found by Anthropic using agents to study the security of open-source projects | Ada Logics, validating and reporting | Caolán McNamara of Collabora Productivity | |
| CVE-2026-93292 | 2026-09-17 | SigNoz | signoz | 8.4 | 4NK1T | axel-corsiez | morimori-dev | newugly | thaidn (Calif.io, in collaboration with Anthropic) | hackchang | Scott Moore - VulnCheck | ||
| CVE-2026-44236 | 2026-09-17 | alanxz | rabbitmq-c | 7.1 | 🔗 | Anthropic | |
| CVE-2026-44235 | 2026-09-17 | alanxz | rabbitmq-c | 6.5 | 🔗 | Anthropic | |
| CVE-2026-92729 | 2026-09-16 | SigNoz | signoz | 8.8 | 4NK1T | lighthousekeeper1212 | 0xVijay | axel-corsiez | morimori-dev | PLpaPLpa | newugly | thaidn (Calif.io, in collaboration with Anthropic) | hackchang | Wenhao Wu (d3do-23), Southeast University | ||
| CVE-2026-91104 | 2026-09-16 | HP Inc. | HP Linux Imaging and Printing Software (HPLIP) | 9.3 | Calif.io in collaboration with Anthropic | ||
| CVE-2026-82717 | 2026-09-16 | NLnet Labs | Unbound | 8.4 | Ben Morris (Anthropic) | ||
| CVE-2026-65410 | 2026-09-14 | Apple | AVEVideoEncoder | 7.5 | Calif.io in collaboration with Claude and Anthropic Research | ||
| CVE-2026-65409 | 2026-09-14 | Apple | Foundation | 5.5 | Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research | ||
| CVE-2026-65376 | 2026-09-14 | Apple | SMB | 5.5 | 재영 정, Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research | ||
| CVE-2026-65375 | 2026-09-14 | Apple | WebDAV | 7.5 | YingMuo (@YingMuo) of DEVCORE Research Team, Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research | ||
| CVE-2026-65374 | 2026-09-14 | Apple | WebDAV | 8.8 | HE WEI(ギカク), Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research | ||
| CVE-2026-43719 | 2026-09-14 | Apple | SMB | 6.5 | Jakob Pammer, Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research | ||
| CVE-2026-43690 | 2026-09-14 | Apple | SMB | 4.7 | Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research | ||
| CVE-2026-43677 | 2026-09-14 | Apple | WebDAV | 6.5 | bubu, Omar Cerrito, HE WEI(ギカク), Roman Zabicki, Richard Zana, Chris Bailey - Short Circuit, Aswin Kumar Gokulakannan, Surya Narayan Kushwaha, Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research | ||
| CVE-2026-45752 | 2026-09-10 | OISF | suricata | 5.9 | 🔗 | Anthropic | |
| CVE-2026-45751 | 2026-09-10 | OISF | suricata | 5.9 | 🔗 | Anthropic | |
| CVE-2026-79678 | 2026-09-07 | Red Hat | Red Hat Enterprise Linux 10 | 8.1 | Red Hat would like to thank Calif.io (in collaboration with Anthropic) for reporting this issue. | ||
| CVE-2026-18453 | 2026-09-07 | Red Hat | Red Hat Directory Server 11 | 7.5 | Red Hat would like to thank Arthur Chan (Ada Logics) and Team (Anthropic) for reporting this issue. | ||
| CVE-2026-18355 | 2026-09-07 | Red Hat | Red Hat Directory Server 11 | 7.5 | Red Hat would like to thank Adam Korczynski (Ada Logics), Arthur Chan (Ada Logics), David Korczynski (Ada Logics), and Team (Anthropic) for reporting this issue. | ||
| CVE-2026-14957 | 2026-09-02 | The Libreswan Project | libreswan | 7.5 | Claude (Anthropic) | Guillaume Winter | ||
| CVE-2026-80590 | 2026-08-28 | Linux | Linux | 8.6 | Signed-off-by: Xinyang Ge xinyang@anthropic.com | ||
| CVE-2026-76891 | 2026-08-19 | Wireshark Foundation | Wireshark | 3.1 | 🔗 | Claude and Ada Logics | |
| CVE-2026-76890 | 2026-08-19 | Wireshark Foundation | Wireshark | 3.1 | 🔗 | Claude and Ada Logics | |
| CVE-2026-76888 | 2026-08-19 | Wireshark Foundation | Wireshark | 3.1 | 🔗 | Claude and Ada Logics | |
| CVE-2026-63652 | 2026-08-19 | FreeRDP | FreeRDP | 7.1 | 🔗 | Anthropic | |
| CVE-2026-63633 | 2026-08-19 | FreeRDP | FreeRDP | 7.7 | 🔗 | Anthropic | |
| CVE-2026-13002 | 2026-08-14 | Red Hat | Red Hat Enterprise Linux 10 | 4.4 | 🔗 | Red Hat would like to thank Lennart Espe for reporting this issue. | |
| CVE-2026-58435 | 2026-08-13 | Gitea | Gitea Open Source Git Server | 5.4 | 🔗 | adrian-doyensec | |
| CVE-2026-19694 | 2026-08-13 | Wireshark Foundation | Wireshark | 4.7 | 🔗 | Claude and Ada Logics | |
| CVE-2026-16239 | 2026-08-13 | n/a | PostgreSQL | 8.8 | The PostgreSQL project thanks Ben Morris (Claude and Anthropic Research) for reporting this problem. | ||
| CVE-2026-15742 | 2026-08-13 | n/a | PostgreSQL | 8.8 | The PostgreSQL project thanks Ben Morris (Claude and Anthropic Research) for reporting this problem. | ||
| CVE-2026-15741 | 2026-08-13 | n/a | PostgreSQL | 8.8 | The PostgreSQL project thanks Ben Morris (Claude and Anthropic Research) for reporting this problem. | ||
| CVE-2026-68760 | 2026-08-12 | jfrog | artifactory | 5.3 | Ben Morris in collaboration with Claude and Anthropic Research | ||
| CVE-2026-68757 | 2026-08-12 | jfrog | artifactory | 7.5 | Ben Morris in collaboration with Claude and Anthropic Research | ||
| CVE-2026-68756 | 2026-08-12 | jfrog | artifactory | 6.6 | Ben Morris in collaboration with Claude and Anthropic Research | ||
| CVE-2026-66376 | 2026-08-12 | jfrog | artifactory | 4.2 | Ben Morris in collaboration with Claude and Anthropic Research | ||
| CVE-2026-18663 | 2026-08-12 | Red Hat | Red Hat Directory Server 11 | 5.9 | Red Hat would like to thank Adam Korczynski (Ada Logics), Arthur Chan (Ada Logics), David Korczynski (Ada Logics), and Team (Anthropic) for reporting this issue. | ||
| CVE-2026-73242 | 2026-08-11 | FreeRDP | FreeRDP | 8.3 | 🔗 | Anthropic | |
| CVE-2026-73241 | 2026-08-11 | FreeRDP | FreeRDP | 8.3 | 🔗 | Anthropic | |
| CVE-2026-72746 | Reserved | 🔗 | Anthropic | ||||
| CVE-2026-11836 | 2026-08-04 | Caliptra | Core ROM | 1.8 | Alex Matrosov with Claude, Anthropic | ||
| CVE-2026-11835 | 2026-08-04 | Caliptra | Core ROM | 5.6 | Alex Matrosov with Claude, Anthropic | ||
| CVE-2026-59652 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 6.9 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-59651 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 7.1 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-59650 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 9.3 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-59649 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-59648 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 6.9 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-59647 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 6.9 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-59646 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-59645 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-59644 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-59643 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-59642 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-59641 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-59640 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-59639 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-59638 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 9.3 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-58063 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 5.3 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-58062 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 9.3 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-58061 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-58060 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-58059 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-15055 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 5.3 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-13506 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Yt | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-12860 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-12817 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-12816 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-12803 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-12185 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 7.1 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-8763 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 9.3 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-68579 | 2026-08-02 | FreeRDP | FreeRDP | 8.7 | 🔗 | DavidKorczynski | |
| CVE-2026-65423 | 2026-07-30 | o6 Automation | open62541 | 8.8 | 🔗 | Abhinav Agarwal reported this vulnerability to CISA. | Asher Davila and Malav Vyas of Palo Alto Networks reported this vulnerability to CISA. | |
| CVE-2026-63559 | 2026-07-30 | o6 Automation | open62541 | 7.5 | 🔗 | Asher Davila and Malav Vyas of Palo Alto Networks reported this vulnerability to CISA. | |
| CVE-2026-61487 | 2026-07-28 | Apache Software Foundation | Apache ActiveMQ Broker | 6.5 | Claude and Ada Logics | ||
| CVE-2026-66032 | 2026-07-24 | libssh2 | libssh2 | 8.7 | 🔗 | VladimirEliTokarev | |
| CVE-2026-55084 | 2026-07-21 | dhis2 | dhis2-core | 8.8 | 🔗 | Anthropic | |
| CVE-2026-64624 | 2026-07-20 | FreeRDP | FreeRDP | 8.5 | 🔗 | DavidKorczynski | |
| CVE-2026-64621 | 2026-07-20 | FreeRDP | FreeRDP | 9.3 | 🔗 | DavidKorczynski | |
| CVE-2026-64620 | 2026-07-20 | FreeRDP | FreeRDP | 9.3 | 🔗 | DavidKorczynski | |
| CVE-2026-35590 | 2026-07-20 | libvips | libvips | 6.8 | 🔗 | Anthropic | |
| CVE-2026-64015 | 2026-07-19 | Linux | Linux | 7.8 | |||
| CVE-2026-46639 | 2026-07-14 | twigphp | Twig | 7.1 | 🔗 | Twig would like to thank Anvil Secure in collaboration with Claude and Anthropic Research for reporting and fixing the issue. | |
| CVE-2026-46633 | 2026-07-14 | twigphp | Twig | 8.7 | 🔗 | Twig would like to thank Anvil Secure in collaboration with Claude and Anthropic Research for reporting and fixing the issue. | |
| CVE-2026-45067 | 2026-07-14 | symfony | symfony | 6.3 | |||
| CVE-2026-61505 | 2026-07-13 | rejetto | hfs | 6.9 | Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research | ||
| CVE-2026-61504 | 2026-07-13 | rejetto | hfs | 5.1 | Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research | ||
| CVE-2026-61503 | 2026-07-13 | rejetto | hfs | 6.9 | Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research | ||
| CVE-2026-61502 | 2026-07-13 | rejetto | hfs | 5.1 | Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research | ||
| CVE-2026-61501 | 2026-07-13 | rejetto | hfs | 5.3 | Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research | ||
| CVE-2026-61500 | 2026-07-13 | rejetto | hfs | 9.3 | ✅ | Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research | |
| CVE-2026-15170 | 2026-07-08 | Wireshark Foundation | Wireshark | 5.5 | 🔗 | Claude and Ada Logics | |
| CVE-2026-15169 | 2026-07-08 | Wireshark Foundation | Wireshark | 5.5 | Claude and Ada Logics | ||
| CVE-2026-15166 | 2026-07-08 | Wireshark Foundation | Wireshark | 5.5 | 🔗 | Claude and Ada Logics | |
| CVE-2026-15165 | 2026-07-08 | Wireshark Foundation | Wireshark | 5.5 | 🔗 | Claude and Ada Logics | |
| CVE-2026-46354 | 2026-07-07 | coder | coder | 9.1 | We'd like to thank Ben Tran of calif.io and Anthropic’s Security Team (ANT-2026-22445) for independently disclosing this issue! | ||
| CVE-2026-45796 | 2026-07-07 | coder | coder | 6.5 | We'd like to thank Ben Tran of calif.io and Anthropic's Security Team (ANT-2026-22447) for independently disclosing this issue! | ||
| CVE-2026-27775 | 2026-07-03 | Gitea | Gitea Open Source Git Server | 8.8 | adrian-doyensec | ||
| CVE-2026-41579 | 2026-07-01 | opencontainers | runc | 3.3 | 🔗 | Anthropic | |
| CVE-2026-20215 | 2026-07-01 | Cisco | Cisco Secure Endpoint | 7.5 | 🔗 | Anthropic | |
| CVE-2026-20214 | 2026-07-01 | Cisco | Cisco Secure Endpoint | 7.5 | 🔗 | Anthropic | |
| CVE-2026-20213 | 2026-07-01 | Cisco | Cisco Secure Endpoint | 7.5 | 🔗 | Anthropic | |
| CVE-2026-43715 | 2026-06-29 | Apple | IOS | 8.8 | Milad Nasr and Nicholas Carlini with Claude, Anthropic | ||
| CVE-2026-13595 | 2026-06-29 | Red Hat | Red Hat Hardened Images | 6.8 | 🔗 | Red Hat would like to thank Thai Duong (Calif.io in collaboration with Claude and Anthropic Research) for reporting this issue. | |
| CVE-2026-53283 | 2026-06-26 | Linux | Linux | 5.5 | Reported-by: Ziyuan Chen zc@anthropic.com | Tested-by: Ziyuan Chen zc@anthropic.com | ||
| CVE-2026-12340 | 2026-06-25 | wolfSSL | wolfSSL | 6.3 | 🔗 | David Pokora, Trail of Bits (in collaboration with Anthropic) | |
| CVE-2026-7531 | 2026-06-25 | wolfSSL | wolfSSL | 2.3 | Thai Duong (Calif.io / Anthropic) | ||
| CVE-2026-7511 | 2026-06-25 | wolfSSL | wolfSSL | 5.9 | Nicholas Carlini from Anthropic | ||
| CVE-2026-6681 | 2026-06-25 | wolfSSL | wolfSSL | 1.0 | Nicholas Carlini from Anthropic | ||
| CVE-2026-6679 | 2026-06-25 | wolfSSL | wolfSSL | 8.8 | Nicholas Carlini from Anthropic | ||
| CVE-2026-6678 | 2026-06-25 | wolfSSL | wolfSSL | 1.0 | 🔗 | Dikai Zou | |
| CVE-2026-6331 | 2026-06-25 | wolfSSL | wolfSSL | 2.1 | Nicholas Carlini from Anthropic | ||
| CVE-2026-6330 | 2026-06-25 | wolfSSL | wolfSSL | 6.3 | Nicholas Carlini from Anthropic | ||
| CVE-2026-6329 | 2026-06-25 | wolfSSL | wolfSSL | 6.0 | Nicholas Carlini from Anthropic | ||
| CVE-2026-46349 | 2026-06-24 | mastodon | mastodon | 5.3 | 🔗 | Anthropic Advisory NOT IN CVE TABLE | |
| CVE-2026-46348 | 2026-06-24 | mastodon | mastodon | 8.7 | 🔗 | Anthropic Advisory NOT IN CVE TABLE | |
| CVE-2026-56132 | 2026-06-19 | libexpat project | libexpat | 6.9 | 🔗 | Anthropic | |
| CVE-2026-45696 | 2026-06-18 | AcademySoftwareFoundation | openexr | 8.3 | 🔗 | Anthropic | |
| CVE-2026-48929 | 2026-06-16 | Rocket.Chat | Rocket.Chat | 7.5 | 🔗 | Anthropic | |
| CVE-2026-8358 | 2026-06-15 | The Document Foundation | LibreOffice | 5.4 | 🔗 | Anthropic (automated discovery using Claude) | Arthur Chan of Ada Logics (validation and reporting) | |
| CVE-2026-8357 | 2026-06-15 | The Document Foundation | LibreOffice | 5.4 | 🔗 | Anthropic (automated discovery using Claude) | Arthur Chan of Ada Logics (validation and reporting) | |
| CVE-2026-8356 | 2026-06-15 | The Document Foundation | LibreOffice | 5.4 | 🔗 | Anthropic (automated discovery using Claude) | Arthur Chan of Ada Logics (validation and reporting) | |
| CVE-2026-6047 | 2026-06-15 | The Document Foundation | LibreOffice | 5.4 | 🔗 | Anthropic (automated discovery using Claude) | Trail of Bits (triage and validation) | |
| CVE-2026-6045 | 2026-06-15 | The Document Foundation | LibreOffice | 5.4 | 🔗 | Anthropic (automated discovery using Claude) | Trail of Bits (triage and validation) | |
| CVE-2026-6040 | 2026-06-15 | The Document Foundation | LibreOffice | 5.4 | 🔗 | Anthropic (automated discovery using Claude) | Trail of Bits (triage and validation) | |
| CVE-2026-6039 | 2026-06-15 | The Document Foundation | LibreOffice | 5.4 | 🔗 | Anthropic (automated discovery using Claude) | Trail of Bits (triage and validation) | |
| CVE-2026-45447 | 2026-06-09 | OpenSSL | OpenSSL | 8.8 | 🔗 | Thai Duong (Calif.io in collaboration with Claude and Anthropic Research) | Igor Ustinov | |
| CVE-2026-45446 | 2026-06-09 | OpenSSL | OpenSSL | 4.8 | Alex Gaynor (Anthropic) | Dmitry Belyavskiy (Red Hat) | ||
| CVE-2026-45445 | 2026-06-09 | OpenSSL | OpenSSL | 7.5 | Alex Gaynor (Anthropic) | Viktor Dukhovni | ||
| CVE-2026-42770 | 2026-06-09 | OpenSSL | OpenSSL | 3.7 | Alex Gaynor (Anthropic) | Alex Gaynor (Anthropic) | Viktor Dukhovni | Norbert Pócs | ||
| CVE-2026-42769 | 2026-06-09 | OpenSSL | OpenSSL | 5.3 | Alex Gaynor (Anthropic) | Alex Gaynor (Anthropic) | Bob Beck | ||
| CVE-2026-42768 | 2026-06-09 | OpenSSL | OpenSSL | 3.7 | Alex Gaynor (Anthropic) | Dmitry Belyavskiy (Red Hat) | Alicja Kario (Red Hat) | ||
| CVE-2026-34182 | 2026-06-09 | OpenSSL | OpenSSL | 9.1 | Asim Viladi Oglu Manizada | Alex Gaynor (Anthropic) | Ying Dong | Haiyang Huang | Neil Horman | ||
| CVE-2026-34181 | 2026-06-09 | OpenSSL | OpenSSL | 7.4 | Pavol Žáčik (Red Hat) | Alex Gaynor (Anthropic) | Alicja Kario (Red Hat) | ||
| CVE-2026-49975 | 2026-06-08 | Apache Software Foundation | Apache HTTP Server | 7.5 | Quang Luong of Calif.IO in collaboration with OpenAI Codex | ||
| CVE-2026-47345 | 2026-06-08 | TYPO3 | HTML Sanitizer | 5.1 | 🔗 | Doyensec in collaboration with Claude and Anthropic Research | Benjamin Franzke | |
| CVE-2026-47732 | 2026-06-05 | twig | twig | 7.1 | @fabpot (remediation_developer) | ||
| CVE-2026-47250 | 2026-06-05 | npm | mcp-server-kubernetes | 6.1 | @yotampe-pluto (reporter) | ||
| CVE-2026-8462 | 2026-06-04 | github.com | openmeterio/openmeter | 8.9 | 🔗 | Anthropic | |
| CVE-2026-47429 | 2026-06-01 | npm | vitest | 9.8 | @sapphi-red (reporter) | @qispark (analyst) | @joevin-slq-docto (analyst) | @koteswar-k (analyst) | @SaronGrave (analyst) | @jason-anthropic (analyst) | ||
| CVE-2026-47391 | 2026-05-29 | pip | PraisonAI | 9.8 | @foxirain (reporter) | ||
| CVE-2026-45700 | 2026-05-29 | FreeRDP | FreeRDP | 7.7 | 🔗 | Anthropic Advisory NOT IN CVE TABLE | |
| CVE-2026-44421 | 2026-05-29 | FreeRDP | FreeRDP | 8.8 | 🔗 | Anthropic | |
| CVE-2026-44420 | 2026-05-29 | FreeRDP | FreeRDP | 8.8 | 🔗 | Anthropic Advisory NOT IN CVE TABLE | |
| CVE-2026-40528 | 2026-05-29 | OpenSC | OpenSC | 1.0 | 🔗 | Nicholas Carlini of Anthropic | |
| CVE-2026-40510 | 2026-05-29 | OpenSC | OpenSC | 1.0 | Nicholas Carlini of Anthropic | ||
| CVE-2026-48896 | 2026-05-26 | Joomla! | Joomla! CMS | 8.2 | Doyensec in collaboration with Claude and Anthropic Research | ||
| CVE-2026-41401 | 2026-05-26 | libyang | libyang | 6.9 | 🔗 | https://www.vulncheck.com/advisories/libyang-heap-use-after-free-write-in-xml-metadata-parsing | |
| CVE-2026-40384 | 2026-05-26 | Joomla! | Joomla! CMS | 5.9 | 🔗 | Doyensec in collaboration with Claude and Anthropic Research | |
| CVE-2026-40383 | 2026-05-26 | Joomla! | Joomla! CMS | 7.5 | 🔗 | Doyensec in collaboration with Claude and Anthropic Research | |
| CVE-2026-40034 | 2026-05-26 | gitoxide | gitoxide | 7.3 | https://www.vulncheck.com/advisories/gitoxide-command-injection-via-partial-gitmodules-override-in-gix-submodule | ||
| CVE-2026-40033 | 2026-05-26 | FreeRDP | FreeRDP | 8.6 | 🔗 | https://www.vulncheck.com/advisories/freerdp-heap-buffer-overflow-in-gdi-cachetosurface-via-rectangle-validation-bypass | |
| CVE-2026-44212 | 2026-05-14 | PrestaShop | PrestaShop | 7.8 | Reported by Savio at Doyensec (anthropic@doyensec.com) in collaboration with Anthropic Research. | ||
| CVE-2026-6479 | 2026-05-14 | PostgreSQL | PostgreSQL | 7.5 | 🔗 | The PostgreSQL project thanks Calif.io in collaboration with Claude and Anthropic Research for reporting this problem. | |
| CVE-2026-44471 | 2026-05-13 | gitoxide | gitoxide | 7.8 | This vulnerability was found by AI (specifically, Claude Mythos) as part of Project Glasswing. I have verified this and most of this advisory has been written by my probably-inferior human brain. | ||
| CVE-2026-40403 | 2026-05-12 | Microsoft | Windows | 8.8 | Calif.io in collaboration with Claude and Anthropic Research | ||
| CVE-2026-40398 | 2026-05-12 | Microsoft | Windows | 8.0 | Calif.io and Milad Nasr (Anthropic) with Claude with Calif.io and Anthropic | ||
| CVE-2026-40380 | 2026-05-12 | Microsoft | Windows | 6.2 | Calif.io in collaboration with Claude and Anthropic Research | ||
| CVE-2026-40369 | 2026-05-12 | Microsoft | Windows | 7.8 | Calif.io in collaboration with Claude and Anthropic Research Adrian Denkiewicz at Doyensec in collaboration with Anthropic Research https://doyensec.com/ Len Sadowski (lytnc) https://sec-fault.com/ and Oguz Bektas (ozb) https://ozbsec.com/ | ||
| CVE-2026-7474 | 2026-05-12 | HashiCorp | Nomad | 8.8 | 🔗 | This issue was reported to HashiCorp by Adrian Denkiewicz at Doyensec in collaboration with Claude and Anthropic Research | |
| CVE-2026-42600 | 2026-05-11 | minio | minio | 6.9 | Anthropic Advisory NOT IN CVE TABLE | ||
| CVE-2026-28952 | 2026-05-11 | Apple | Iphone/Ipad | 7.5 | Calif.io in collaboration with Claude and Anthropic Research | ||
| CVE-2026-28942 | 2026-05-11 | Apple | Webkit | 6.5 | Milad Nasr and Nicholas Carlini with Claude, Anthropic | ||
| CVE-2026-4892 | 2026-05-11 | dnsmasq | dnsmasq | 8.4 | 🔗 | Anthropic | |
| CVE-2026-4890 | 2026-05-11 | dnsmasq | dnsmasq | 7.5 | 🔗 | Anthropic | |
| CVE-2026-43185 | 2026-05-06 | Linux | Linux | 9.8 | Signed-off-by: Nicholas Carlini nicholas@carlini.com | ||
| CVE-2026-43074 | 2026-05-06 | Linux | Linux | 7.8 | 🔗 | Anthropic | |
| CVE-2026-40685 | 2026-04-30 | Exim | Exim | 6.5 | 🔗 | Anthropic | |
| CVE-2026-31554 | 2026-04-24 | Linux | Linux | 7.8 | 🔗 | Reported-by: Nicholas Carlini npc@anthropic.com | |
| CVE-2026-41990 | 2026-04-23 | gnupg | Libgcrypt | 4.0 | 🔗 | Reported by Calif.io in collaboration with Claude and Anthropic Research | |
| CVE-2026-29198 | 2026-04-22 | Rocket.Chat | Rocket.Chat | 9.8 | 🔗 | Anthropic | |
| CVE-2026-6386 | 2026-04-22 | FreeBSD | FreeBSD | 6.2 | 🔗 | Nicholas Carlini using Claude, Anthropic | |
| CVE-2026-5398 | 2026-04-22 | FreeBSD | FreeBSD | 8.4 | 🔗 | Nicholas Carlini using Claude, Anthropic | |
| CVE-2026-6772 | 2026-04-21 | Mozilla | Firefox | 7.5 | 🔗 | sseehra | |
| CVE-2026-6758 | 2026-04-21 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-6757 | 2026-04-21 | Mozilla | Firefox | 7.5 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-6746 | 2026-04-21 | Mozilla | Firefox | 7.5 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-5588 | 2026-04-15 | Legion of the Bouncy Castle Inc. | BC-JAVA | 6.3 | Nicholas Carlini using Claude, Anthropic | ||
| CVE-2026-33096 | 2026-04-14 | Microsoft | Windows | 7.5 | Milad Nasr (Anthropic) and Calif.io with Claude | ||
| CVE-2026-33901 | 2026-04-13 | ImageMagick | ImageMagick | 7.5 | 🔗 | Anthropic Advisory NOT IN CVE TABLE | |
| CVE-2026-32316 | 2026-04-13 | jqlang | JQ | 7.5 | 🔗 | Anthropic Advisory | |
| CVE-2026-57191 | Reserved | asterisk | asterisk | 🔗 | Anthropic | ||
| CVE-2026-5501 | 2026-04-10 | wolfSSL | wolfSSL | 8.6 | 🔗 | Calif.io in collaboration with Claude and Anthropic Research | |
| CVE-2026-5500 | 2026-04-10 | wolfSSL | wolfSSL | 8.7 | 🔗 | Calif.io in collaboration with Claude and Anthropic Research | |
| CVE-2026-5479 | 2026-04-10 | wolfSSL | wolfSSL | 7.6 | 🔗 | Calif.io in collaboration with Claude and Anthropic Research | |
| CVE-2026-5477 | 2026-04-10 | wolfSSL | wolfSSL | 8.2 | 🔗 | Calif.io in collaboration with Claude and Anthropic Research | |
| CVE-2026-5466 | 2026-04-10 | wolfSSL | wolfSSL | 7.6 | 🔗 | Calif.io in collaboration with Claude and Anthropic Research | |
| CVE-2026-5503 | 2026-04-09 | wolfSSL | wolfSSL | 6.9 | 🔗 | Calif.io in collaboration with Claude and Anthropic Research | |
| CVE-2026-5448 | 2026-04-09 | wolfSSL | wolfSSL | 2.3 | 🔗 | Anthropic Advisory | |
| CVE-2026-5447 | 2026-04-09 | wolfSSL | wolfSSL | 6.3 | 🔗 | Calif.io in collaboration with Claude and Anthropic Research | |
| CVE-2026-5446 | 2026-04-09 | wolfSSL | wolfSSL | 6.0 | 🔗 | Calif.io in collaboration with Claude and Anthropic Research | |
| CVE-2026-5295 | 2026-04-09 | wolfSSL | wolfSSL | 5.9 | 🔗 | Sunwoo Lee, (Korea Institute of Energy Technology, KENTECH) | Woohyun Choi, (Korea Institute of Energy Technology, KENTECH) | Seunghyun Yoon, (Korea Institute of Energy Technology, KENTECH) | |
| CVE-2026-5194 | 2026-04-09 | wolfSSL | wolfSSL | 9.3 | 🔗 | Nicholas Carlini from Anthropic | |
| CVE-2026-34580 | 2026-04-07 | Botan | Botan | 7.5 | 🔗 | Nicholas Carlini with Claude, Anthropic | |
| CVE-2026-28386 | 2026-04-07 | OpenSSL | OpenSSL | 9.1 | Stanislav Fort (Aisle Research); Pavel Kohout (Aisle Research); Alex Gaynor (Anthropic) | ||
| CVE-2026-5747 | 2026-04-07 | AWS | FireCracker | 8.7 | 🔗 | We thank Anthropic for reporting this concern to the AWS Vulnerability Disclosure Program. | |
| CVE-2026-35022 | Reserved | ||||||
| CVE-2026-31402 | 2026-04-03 | Linux | Linux | 9.8 | Reported-by: Nicholas Carlini npc@anthropic.com | ||
| CVE-2026-5199 | 2026-04-01 | temporalio | temporal | 2.3 | 🔗 | Anthropic Advisory | |
| CVE-2026-7275 | Reserved | moodle | moodle | 🔗 | Anthropic | ||
| CVE-2026-68521 | Reserved | unicorn | 🔗 | Anthropic | |||
| CVE-2026-62257 | Reserved | htslib | 🔗 | Anthropic | |||
| CVE-2026-33721 | 2026-03-26 | MapServer | MapServer | 5.3 | 🔗 | Anthropic Advisory | |
| CVE-2026-4747 | 2026-03-26 | FreeBSD | FreeBSD | 8.8 | 🔗 | Nicholas Carlini using Claude, Anthropic | |
| CVE-2026-54914 | Reserved | bytecodealliance | wasm-micro-runtime | 🔗 | Anthropic | ||
| CVE-2026-27654 | 2026-03-24 | F5 | NGINX Plus | 8.2 | 🔗 | Calif.io in collaboration with Claude and Anthropic Research | |
| CVE-2026-4724 | 2026-03-24 | Mozilla | Firefox | 9.1 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-4723 | 2026-03-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-4718 | 2026-03-24 | Mozilla | Firefox | 8.1 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-4705 | 2026-03-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-4704 | 2026-03-24 | Mozilla | Firefox | 7.5 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-4702 | 2026-03-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-4600 | 2026-03-23 | jsrsasign | jsrsasign | 9.1 | reported by Koda Reef, Nicholas Carlini and @Kr0emer | ||
| CVE-2026-61627 | Reserved | libass | libass | 🔗 | Anthropic | ||
| CVE-2026-32267 | 2026-03-16 | craftcms | cms | 7.7 | Anthropic Advisory | ||
| CVE-2026-28208 | 2026-02-26 | junrar | junrar | 5.9 | Anthropic Advisory | ||
| CVE-2026-2805 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2804 | 2026-02-24 | Mozilla | Firefox | 5.4 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2799 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2797 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2796 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2791 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2789 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2788 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2787 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2786 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2785 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2775 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2774 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2773 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2772 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2771 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2770 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2769 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2766 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2765 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2764 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2763 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-26980 | 2026-02-19 | Ghost | Ghost | 9.4 | 🔗 | ✅ | We thank Nicholas Carlini using Claude, Anthropic for disclosing this vulnerability responsibly. |
Tracking Vulnerabilities That Appear to be Credited to the Anthropic Research Team
80
2,413 commits
updated Oct 4, 2026
Tracking vulnerabilities that credit the Anthropic research team and are possibly discovered by Project Glasswing.
CURRENT CVE COUNT: 300
Fixed Anthropic Findings w/o CVE: 128
Findings Withdrawn by Anthropic: 243
|
|
|
If you find an Anthropic credited vulnerability, please open a Pull Request or Send me a message on linkedin or in the Extended Vulnerability Community Discord.
This project is maintained on a best effort basis.
| CVE | Date | Vendor | Product | CVSS | Ledger | vcKEV | Credit |
|---|---|---|---|---|---|---|---|
| CVE-2026-103604 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.7 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-103603 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.7 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-103602 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.2 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-103601 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.2 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-66858 | 2026-10-02 | Apache Software Foundation | Apache Thrift | 8.7 | Claude (Anthropic Research) | Arthur Chan, Ada Logics | Apache Thrift Developers | ||
| CVE-2026-66837 | 2026-10-02 | Apache Software Foundation | Apache Thrift | 8.7 | Claude (Anthropic Research) | Arthur Chan, Ada Logics (arthur.chan@adalogics.com) | ||
| CVE-2026-66081 | 2026-10-02 | Apache Software Foundation | Apache Thrift | 8.7 | Akhil Koul | Claude (Anthropic Research) | Arthur Chan, Ada Logics (arthur.chan@adalogics.com) | ||
| CVE-2026-63772 | 2026-10-02 | Apache Software Foundation | Apache Thrift | 8.7 | Anthropic (agentic research) + Ada Logics; reported by Adam Korczynski | ||
| CVE-2026-63578 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 7.1 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-63577 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.2 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-63576 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.2 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-63574 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.7 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-63573 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.2 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-63571 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.7 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-63570 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 7.1 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-63569 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 9.1 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-63568 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.7 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-63567 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.2 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-63566 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.7 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-61373 | 2026-10-02 | Apache Software Foundation | Apache Thrift | 8.7 | Claude (Anthropic Research) | Arthur Chan, Ada Logics (arthur.chan@adalogics.com) | n0mi1k | ||
| CVE-2026-17508 | 2026-10-02 | Legion of the Bouncy Castle Inc. | BC-JAVA | 5.3 | Mirko Swillus on behalf of Alpha-Omega (alpha-omega.dev), using Scrutineer with an Anthropic Claude model provided through Project Glasswing | Yu Bao from the PayPal Cyber Security Team | ||
| CVE-2026-17507 | 2026-10-02 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Mirko Swillus on behalf of Alpha-Omega (alpha-omega.dev), using Scrutineer with an Anthropic Claude model provided through Project Glasswing | ||
| CVE-2026-16001 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.2 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-16000 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.7 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-15999 | 2026-10-02 | Legion of the Bouncy Castle Inc. | bc-csharp | 8.2 | Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. | ||
| CVE-2026-93546 | 2026-10-01 | Apache Software Foundation | Apache HTTP Server | 8.8 | Zhen Kong | Calif.io in collaboration with Anthropic | AISLE in partnership with Red Hat | ||
| CVE-2026-101283 | 2026-09-30 | esnet | iperf3 | 9.2 | Anthropic | Ada Logics | ||
| CVE-2026-101276 | 2026-09-30 | esnet | iperf3 | 9.2 | Anthropic | Ada Logics | ||
| CVE-2026-96423 | 2026-09-29 | Wireshark Foundation | Wireshark | 5.5 | Claude and Ada Logics | ||
| CVE-2026-96421 | 2026-09-29 | Wireshark Foundation | Wireshark | 5.5 | Claude and Ada Logics | ||
| CVE-2026-96418 | 2026-09-29 | Wireshark Foundation | Wireshark | 5.5 | Credit: Claude and Ada Logics | ||
| CVE-2026-96416 | 2026-09-29 | Wireshark Foundation | Wireshark | 5.5 | Claude and Ada Logics | ||
| CVE-2026-92222 | 2026-09-29 | Joomla! Project | Joomla! CMS | 8.9 | Aria Akhavan | Calif.io in collaboration with Anthropic | ||
| CVE-2026-90915 | 2026-09-29 | Joomla! Project | Joomla! CMS | 7.0 | Aria Akhavan | Calif.io in collaboration with Anthropic | ||
| CVE-2026-94419 | 2026-09-27 | wolfSSL | wolfSSL | 2.3 | Anthropic OSS program | ||
| CVE-2026-94418 | 2026-09-27 | wolfSSL | wolfSSL | 2.3 | Anthropic OSS program | ||
| CVE-2026-94417 | 2026-09-27 | wolfSSL | wolfSSL | 2.3 | Anthropic OSS program | ||
| CVE-2026-93304 | 2026-09-27 | wolfSSL | wolfSSL | 6.3 | Anthropic OSS program | ||
| CVE-2026-93302 | 2026-09-27 | wolfSSL | wolfSSL | 8.3 | Anthropic OSS program | ||
| CVE-2026-98134 | 2026-09-25 | Linux | Linux | ||||
| CVE-2026-98085 | 2026-09-25 | Linux | Linux | ||||
| CVE-2026-98062 | 2026-09-25 | Linux | Linux | 5.5 | Reported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com | ||
| CVE-2026-98061 | 2026-09-25 | Linux | Linux | Reported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com | |||
| CVE-2026-98060 | 2026-09-25 | Linux | Linux | Reported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com | |||
| CVE-2026-98058 | 2026-09-25 | Linux | Linux | Reported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com | |||
| CVE-2026-98049 | 2026-09-25 | Linux | Linux | Reported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com | |||
| CVE-2026-98047 | 2026-09-25 | Linux | Linux | Reported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com | |||
| CVE-2026-98040 | 2026-09-25 | Linux | Linux | Reported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com | |||
| CVE-2026-98038 | 2026-09-25 | Linux | Linux | Reported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com | |||
| CVE-2026-98037 | 2026-09-25 | Linux | Linux | Reported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com | |||
| CVE-2026-98036 | 2026-09-25 | Linux | Linux | Reported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com | |||
| CVE-2026-98034 | 2026-09-25 | Linux | Linux | Reported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com | |||
| CVE-2026-98033 | 2026-09-25 | Linux | Linux | Reported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com | |||
| CVE-2026-97524 | 2026-09-25 | Linux | Linux | 7.5 | Reported-by: Xinyang Ge xinyang@anthropic.com | ||
| CVE-2026-97523 | 2026-09-25 | Linux | Linux | 7.5 | Reported-by: Xinyang Ge xinyang@anthropic.com | ||
| CVE-2026-96812 | 2026-09-25 | gVisor | 8.8 | Anthropic (using Claude) | |||
| CVE-2026-89422 | 2026-09-22 | Erlang | OTP | 9.3 | Milad Nasr / Anthropic | Luna Tong / Anthropic | Ingela Andin | ||
| CVE-2026-63276 | 2026-09-22 | The Document Foundation | LibreOffice | 5.4 | 🔗 | Claude, found by Anthropic using agents to study the security of open-source projects | Ada Logics, validating and reporting | Caolán McNamara of Collabora Productivity | |
| CVE-2026-63275 | 2026-09-22 | The Document Foundation | LibreOffice | 5.4 | 🔗 | Claude, found by Anthropic using agents to study the security of open-source projects | Ada Logics, validating and reporting | Caolán McNamara of Collabora Productivity | |
| CVE-2026-63274 | 2026-09-22 | The Document Foundation | LibreOffice | 5.4 | 🔗 | Claude, found by Anthropic using agents to study the security of open-source projects | Ada Logics, validating and reporting | Caolán McNamara of Collabora Productivity | |
| CVE-2026-63273 | 2026-09-22 | The Document Foundation | LibreOffice | 5.4 | 🔗 | Claude, found by Anthropic using agents to study the security of open-source projects | Ada Logics, validating and reporting | Caolán McNamara of Collabora Productivity | |
| CVE-2026-63272 | 2026-09-22 | The Document Foundation | LibreOffice | 5.4 | 🔗 | Claude, found by Anthropic using agents to study the security of open-source projects | Ada Logics, validating and reporting | Caolán McNamara of Collabora Productivity | |
| CVE-2026-93292 | 2026-09-17 | SigNoz | signoz | 8.4 | 4NK1T | axel-corsiez | morimori-dev | newugly | thaidn (Calif.io, in collaboration with Anthropic) | hackchang | Scott Moore - VulnCheck | ||
| CVE-2026-44236 | 2026-09-17 | alanxz | rabbitmq-c | 7.1 | 🔗 | Anthropic | |
| CVE-2026-44235 | 2026-09-17 | alanxz | rabbitmq-c | 6.5 | 🔗 | Anthropic | |
| CVE-2026-92729 | 2026-09-16 | SigNoz | signoz | 8.8 | 4NK1T | lighthousekeeper1212 | 0xVijay | axel-corsiez | morimori-dev | PLpaPLpa | newugly | thaidn (Calif.io, in collaboration with Anthropic) | hackchang | Wenhao Wu (d3do-23), Southeast University | ||
| CVE-2026-91104 | 2026-09-16 | HP Inc. | HP Linux Imaging and Printing Software (HPLIP) | 9.3 | Calif.io in collaboration with Anthropic | ||
| CVE-2026-82717 | 2026-09-16 | NLnet Labs | Unbound | 8.4 | Ben Morris (Anthropic) | ||
| CVE-2026-65410 | 2026-09-14 | Apple | AVEVideoEncoder | 7.5 | Calif.io in collaboration with Claude and Anthropic Research | ||
| CVE-2026-65409 | 2026-09-14 | Apple | Foundation | 5.5 | Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research | ||
| CVE-2026-65376 | 2026-09-14 | Apple | SMB | 5.5 | 재영 정, Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research | ||
| CVE-2026-65375 | 2026-09-14 | Apple | WebDAV | 7.5 | YingMuo (@YingMuo) of DEVCORE Research Team, Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research | ||
| CVE-2026-65374 | 2026-09-14 | Apple | WebDAV | 8.8 | HE WEI(ギカク), Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research | ||
| CVE-2026-43719 | 2026-09-14 | Apple | SMB | 6.5 | Jakob Pammer, Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research | ||
| CVE-2026-43690 | 2026-09-14 | Apple | SMB | 4.7 | Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research | ||
| CVE-2026-43677 | 2026-09-14 | Apple | WebDAV | 6.5 | bubu, Omar Cerrito, HE WEI(ギカク), Roman Zabicki, Richard Zana, Chris Bailey - Short Circuit, Aswin Kumar Gokulakannan, Surya Narayan Kushwaha, Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research | ||
| CVE-2026-45752 | 2026-09-10 | OISF | suricata | 5.9 | 🔗 | Anthropic | |
| CVE-2026-45751 | 2026-09-10 | OISF | suricata | 5.9 | 🔗 | Anthropic | |
| CVE-2026-79678 | 2026-09-07 | Red Hat | Red Hat Enterprise Linux 10 | 8.1 | Red Hat would like to thank Calif.io (in collaboration with Anthropic) for reporting this issue. | ||
| CVE-2026-18453 | 2026-09-07 | Red Hat | Red Hat Directory Server 11 | 7.5 | Red Hat would like to thank Arthur Chan (Ada Logics) and Team (Anthropic) for reporting this issue. | ||
| CVE-2026-18355 | 2026-09-07 | Red Hat | Red Hat Directory Server 11 | 7.5 | Red Hat would like to thank Adam Korczynski (Ada Logics), Arthur Chan (Ada Logics), David Korczynski (Ada Logics), and Team (Anthropic) for reporting this issue. | ||
| CVE-2026-14957 | 2026-09-02 | The Libreswan Project | libreswan | 7.5 | Claude (Anthropic) | Guillaume Winter | ||
| CVE-2026-80590 | 2026-08-28 | Linux | Linux | 8.6 | Signed-off-by: Xinyang Ge xinyang@anthropic.com | ||
| CVE-2026-76891 | 2026-08-19 | Wireshark Foundation | Wireshark | 3.1 | 🔗 | Claude and Ada Logics | |
| CVE-2026-76890 | 2026-08-19 | Wireshark Foundation | Wireshark | 3.1 | 🔗 | Claude and Ada Logics | |
| CVE-2026-76888 | 2026-08-19 | Wireshark Foundation | Wireshark | 3.1 | 🔗 | Claude and Ada Logics | |
| CVE-2026-63652 | 2026-08-19 | FreeRDP | FreeRDP | 7.1 | 🔗 | Anthropic | |
| CVE-2026-63633 | 2026-08-19 | FreeRDP | FreeRDP | 7.7 | 🔗 | Anthropic | |
| CVE-2026-13002 | 2026-08-14 | Red Hat | Red Hat Enterprise Linux 10 | 4.4 | 🔗 | Red Hat would like to thank Lennart Espe for reporting this issue. | |
| CVE-2026-58435 | 2026-08-13 | Gitea | Gitea Open Source Git Server | 5.4 | 🔗 | adrian-doyensec | |
| CVE-2026-19694 | 2026-08-13 | Wireshark Foundation | Wireshark | 4.7 | 🔗 | Claude and Ada Logics | |
| CVE-2026-16239 | 2026-08-13 | n/a | PostgreSQL | 8.8 | The PostgreSQL project thanks Ben Morris (Claude and Anthropic Research) for reporting this problem. | ||
| CVE-2026-15742 | 2026-08-13 | n/a | PostgreSQL | 8.8 | The PostgreSQL project thanks Ben Morris (Claude and Anthropic Research) for reporting this problem. | ||
| CVE-2026-15741 | 2026-08-13 | n/a | PostgreSQL | 8.8 | The PostgreSQL project thanks Ben Morris (Claude and Anthropic Research) for reporting this problem. | ||
| CVE-2026-68760 | 2026-08-12 | jfrog | artifactory | 5.3 | Ben Morris in collaboration with Claude and Anthropic Research | ||
| CVE-2026-68757 | 2026-08-12 | jfrog | artifactory | 7.5 | Ben Morris in collaboration with Claude and Anthropic Research | ||
| CVE-2026-68756 | 2026-08-12 | jfrog | artifactory | 6.6 | Ben Morris in collaboration with Claude and Anthropic Research | ||
| CVE-2026-66376 | 2026-08-12 | jfrog | artifactory | 4.2 | Ben Morris in collaboration with Claude and Anthropic Research | ||
| CVE-2026-18663 | 2026-08-12 | Red Hat | Red Hat Directory Server 11 | 5.9 | Red Hat would like to thank Adam Korczynski (Ada Logics), Arthur Chan (Ada Logics), David Korczynski (Ada Logics), and Team (Anthropic) for reporting this issue. | ||
| CVE-2026-73242 | 2026-08-11 | FreeRDP | FreeRDP | 8.3 | 🔗 | Anthropic | |
| CVE-2026-73241 | 2026-08-11 | FreeRDP | FreeRDP | 8.3 | 🔗 | Anthropic | |
| CVE-2026-72746 | Reserved | 🔗 | Anthropic | ||||
| CVE-2026-11836 | 2026-08-04 | Caliptra | Core ROM | 1.8 | Alex Matrosov with Claude, Anthropic | ||
| CVE-2026-11835 | 2026-08-04 | Caliptra | Core ROM | 5.6 | Alex Matrosov with Claude, Anthropic | ||
| CVE-2026-59652 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 6.9 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-59651 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 7.1 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-59650 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 9.3 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-59649 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-59648 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 6.9 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-59647 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 6.9 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-59646 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-59645 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-59644 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-59643 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-59642 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-59641 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-59640 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-59639 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-59638 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 9.3 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-58063 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 5.3 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-58062 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 9.3 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-58061 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-58060 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-58059 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-15055 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 5.3 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-13506 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Yt | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-12860 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-12817 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-12816 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-12803 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-12185 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 7.1 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-8763 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 9.3 | Alex Gaynor in collaboration with Claude and Anthropic Research | ||
| CVE-2026-68579 | 2026-08-02 | FreeRDP | FreeRDP | 8.7 | 🔗 | DavidKorczynski | |
| CVE-2026-65423 | 2026-07-30 | o6 Automation | open62541 | 8.8 | 🔗 | Abhinav Agarwal reported this vulnerability to CISA. | Asher Davila and Malav Vyas of Palo Alto Networks reported this vulnerability to CISA. | |
| CVE-2026-63559 | 2026-07-30 | o6 Automation | open62541 | 7.5 | 🔗 | Asher Davila and Malav Vyas of Palo Alto Networks reported this vulnerability to CISA. | |
| CVE-2026-61487 | 2026-07-28 | Apache Software Foundation | Apache ActiveMQ Broker | 6.5 | Claude and Ada Logics | ||
| CVE-2026-66032 | 2026-07-24 | libssh2 | libssh2 | 8.7 | 🔗 | VladimirEliTokarev | |
| CVE-2026-55084 | 2026-07-21 | dhis2 | dhis2-core | 8.8 | 🔗 | Anthropic | |
| CVE-2026-64624 | 2026-07-20 | FreeRDP | FreeRDP | 8.5 | 🔗 | DavidKorczynski | |
| CVE-2026-64621 | 2026-07-20 | FreeRDP | FreeRDP | 9.3 | 🔗 | DavidKorczynski | |
| CVE-2026-64620 | 2026-07-20 | FreeRDP | FreeRDP | 9.3 | 🔗 | DavidKorczynski | |
| CVE-2026-35590 | 2026-07-20 | libvips | libvips | 6.8 | 🔗 | Anthropic | |
| CVE-2026-64015 | 2026-07-19 | Linux | Linux | 7.8 | |||
| CVE-2026-46639 | 2026-07-14 | twigphp | Twig | 7.1 | 🔗 | Twig would like to thank Anvil Secure in collaboration with Claude and Anthropic Research for reporting and fixing the issue. | |
| CVE-2026-46633 | 2026-07-14 | twigphp | Twig | 8.7 | 🔗 | Twig would like to thank Anvil Secure in collaboration with Claude and Anthropic Research for reporting and fixing the issue. | |
| CVE-2026-45067 | 2026-07-14 | symfony | symfony | 6.3 | |||
| CVE-2026-61505 | 2026-07-13 | rejetto | hfs | 6.9 | Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research | ||
| CVE-2026-61504 | 2026-07-13 | rejetto | hfs | 5.1 | Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research | ||
| CVE-2026-61503 | 2026-07-13 | rejetto | hfs | 6.9 | Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research | ||
| CVE-2026-61502 | 2026-07-13 | rejetto | hfs | 5.1 | Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research | ||
| CVE-2026-61501 | 2026-07-13 | rejetto | hfs | 5.3 | Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research | ||
| CVE-2026-61500 | 2026-07-13 | rejetto | hfs | 9.3 | ✅ | Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research | |
| CVE-2026-15170 | 2026-07-08 | Wireshark Foundation | Wireshark | 5.5 | 🔗 | Claude and Ada Logics | |
| CVE-2026-15169 | 2026-07-08 | Wireshark Foundation | Wireshark | 5.5 | Claude and Ada Logics | ||
| CVE-2026-15166 | 2026-07-08 | Wireshark Foundation | Wireshark | 5.5 | 🔗 | Claude and Ada Logics | |
| CVE-2026-15165 | 2026-07-08 | Wireshark Foundation | Wireshark | 5.5 | 🔗 | Claude and Ada Logics | |
| CVE-2026-46354 | 2026-07-07 | coder | coder | 9.1 | We'd like to thank Ben Tran of calif.io and Anthropic’s Security Team (ANT-2026-22445) for independently disclosing this issue! | ||
| CVE-2026-45796 | 2026-07-07 | coder | coder | 6.5 | We'd like to thank Ben Tran of calif.io and Anthropic's Security Team (ANT-2026-22447) for independently disclosing this issue! | ||
| CVE-2026-27775 | 2026-07-03 | Gitea | Gitea Open Source Git Server | 8.8 | adrian-doyensec | ||
| CVE-2026-41579 | 2026-07-01 | opencontainers | runc | 3.3 | 🔗 | Anthropic | |
| CVE-2026-20215 | 2026-07-01 | Cisco | Cisco Secure Endpoint | 7.5 | 🔗 | Anthropic | |
| CVE-2026-20214 | 2026-07-01 | Cisco | Cisco Secure Endpoint | 7.5 | 🔗 | Anthropic | |
| CVE-2026-20213 | 2026-07-01 | Cisco | Cisco Secure Endpoint | 7.5 | 🔗 | Anthropic | |
| CVE-2026-43715 | 2026-06-29 | Apple | IOS | 8.8 | Milad Nasr and Nicholas Carlini with Claude, Anthropic | ||
| CVE-2026-13595 | 2026-06-29 | Red Hat | Red Hat Hardened Images | 6.8 | 🔗 | Red Hat would like to thank Thai Duong (Calif.io in collaboration with Claude and Anthropic Research) for reporting this issue. | |
| CVE-2026-53283 | 2026-06-26 | Linux | Linux | 5.5 | Reported-by: Ziyuan Chen zc@anthropic.com | Tested-by: Ziyuan Chen zc@anthropic.com | ||
| CVE-2026-12340 | 2026-06-25 | wolfSSL | wolfSSL | 6.3 | 🔗 | David Pokora, Trail of Bits (in collaboration with Anthropic) | |
| CVE-2026-7531 | 2026-06-25 | wolfSSL | wolfSSL | 2.3 | Thai Duong (Calif.io / Anthropic) | ||
| CVE-2026-7511 | 2026-06-25 | wolfSSL | wolfSSL | 5.9 | Nicholas Carlini from Anthropic | ||
| CVE-2026-6681 | 2026-06-25 | wolfSSL | wolfSSL | 1.0 | Nicholas Carlini from Anthropic | ||
| CVE-2026-6679 | 2026-06-25 | wolfSSL | wolfSSL | 8.8 | Nicholas Carlini from Anthropic | ||
| CVE-2026-6678 | 2026-06-25 | wolfSSL | wolfSSL | 1.0 | 🔗 | Dikai Zou | |
| CVE-2026-6331 | 2026-06-25 | wolfSSL | wolfSSL | 2.1 | Nicholas Carlini from Anthropic | ||
| CVE-2026-6330 | 2026-06-25 | wolfSSL | wolfSSL | 6.3 | Nicholas Carlini from Anthropic | ||
| CVE-2026-6329 | 2026-06-25 | wolfSSL | wolfSSL | 6.0 | Nicholas Carlini from Anthropic | ||
| CVE-2026-46349 | 2026-06-24 | mastodon | mastodon | 5.3 | 🔗 | Anthropic Advisory NOT IN CVE TABLE | |
| CVE-2026-46348 | 2026-06-24 | mastodon | mastodon | 8.7 | 🔗 | Anthropic Advisory NOT IN CVE TABLE | |
| CVE-2026-56132 | 2026-06-19 | libexpat project | libexpat | 6.9 | 🔗 | Anthropic | |
| CVE-2026-45696 | 2026-06-18 | AcademySoftwareFoundation | openexr | 8.3 | 🔗 | Anthropic | |
| CVE-2026-48929 | 2026-06-16 | Rocket.Chat | Rocket.Chat | 7.5 | 🔗 | Anthropic | |
| CVE-2026-8358 | 2026-06-15 | The Document Foundation | LibreOffice | 5.4 | 🔗 | Anthropic (automated discovery using Claude) | Arthur Chan of Ada Logics (validation and reporting) | |
| CVE-2026-8357 | 2026-06-15 | The Document Foundation | LibreOffice | 5.4 | 🔗 | Anthropic (automated discovery using Claude) | Arthur Chan of Ada Logics (validation and reporting) | |
| CVE-2026-8356 | 2026-06-15 | The Document Foundation | LibreOffice | 5.4 | 🔗 | Anthropic (automated discovery using Claude) | Arthur Chan of Ada Logics (validation and reporting) | |
| CVE-2026-6047 | 2026-06-15 | The Document Foundation | LibreOffice | 5.4 | 🔗 | Anthropic (automated discovery using Claude) | Trail of Bits (triage and validation) | |
| CVE-2026-6045 | 2026-06-15 | The Document Foundation | LibreOffice | 5.4 | 🔗 | Anthropic (automated discovery using Claude) | Trail of Bits (triage and validation) | |
| CVE-2026-6040 | 2026-06-15 | The Document Foundation | LibreOffice | 5.4 | 🔗 | Anthropic (automated discovery using Claude) | Trail of Bits (triage and validation) | |
| CVE-2026-6039 | 2026-06-15 | The Document Foundation | LibreOffice | 5.4 | 🔗 | Anthropic (automated discovery using Claude) | Trail of Bits (triage and validation) | |
| CVE-2026-45447 | 2026-06-09 | OpenSSL | OpenSSL | 8.8 | 🔗 | Thai Duong (Calif.io in collaboration with Claude and Anthropic Research) | Igor Ustinov | |
| CVE-2026-45446 | 2026-06-09 | OpenSSL | OpenSSL | 4.8 | Alex Gaynor (Anthropic) | Dmitry Belyavskiy (Red Hat) | ||
| CVE-2026-45445 | 2026-06-09 | OpenSSL | OpenSSL | 7.5 | Alex Gaynor (Anthropic) | Viktor Dukhovni | ||
| CVE-2026-42770 | 2026-06-09 | OpenSSL | OpenSSL | 3.7 | Alex Gaynor (Anthropic) | Alex Gaynor (Anthropic) | Viktor Dukhovni | Norbert Pócs | ||
| CVE-2026-42769 | 2026-06-09 | OpenSSL | OpenSSL | 5.3 | Alex Gaynor (Anthropic) | Alex Gaynor (Anthropic) | Bob Beck | ||
| CVE-2026-42768 | 2026-06-09 | OpenSSL | OpenSSL | 3.7 | Alex Gaynor (Anthropic) | Dmitry Belyavskiy (Red Hat) | Alicja Kario (Red Hat) | ||
| CVE-2026-34182 | 2026-06-09 | OpenSSL | OpenSSL | 9.1 | Asim Viladi Oglu Manizada | Alex Gaynor (Anthropic) | Ying Dong | Haiyang Huang | Neil Horman | ||
| CVE-2026-34181 | 2026-06-09 | OpenSSL | OpenSSL | 7.4 | Pavol Žáčik (Red Hat) | Alex Gaynor (Anthropic) | Alicja Kario (Red Hat) | ||
| CVE-2026-49975 | 2026-06-08 | Apache Software Foundation | Apache HTTP Server | 7.5 | Quang Luong of Calif.IO in collaboration with OpenAI Codex | ||
| CVE-2026-47345 | 2026-06-08 | TYPO3 | HTML Sanitizer | 5.1 | 🔗 | Doyensec in collaboration with Claude and Anthropic Research | Benjamin Franzke | |
| CVE-2026-47732 | 2026-06-05 | twig | twig | 7.1 | @fabpot (remediation_developer) | ||
| CVE-2026-47250 | 2026-06-05 | npm | mcp-server-kubernetes | 6.1 | @yotampe-pluto (reporter) | ||
| CVE-2026-8462 | 2026-06-04 | github.com | openmeterio/openmeter | 8.9 | 🔗 | Anthropic | |
| CVE-2026-47429 | 2026-06-01 | npm | vitest | 9.8 | @sapphi-red (reporter) | @qispark (analyst) | @joevin-slq-docto (analyst) | @koteswar-k (analyst) | @SaronGrave (analyst) | @jason-anthropic (analyst) | ||
| CVE-2026-47391 | 2026-05-29 | pip | PraisonAI | 9.8 | @foxirain (reporter) | ||
| CVE-2026-45700 | 2026-05-29 | FreeRDP | FreeRDP | 7.7 | 🔗 | Anthropic Advisory NOT IN CVE TABLE | |
| CVE-2026-44421 | 2026-05-29 | FreeRDP | FreeRDP | 8.8 | 🔗 | Anthropic | |
| CVE-2026-44420 | 2026-05-29 | FreeRDP | FreeRDP | 8.8 | 🔗 | Anthropic Advisory NOT IN CVE TABLE | |
| CVE-2026-40528 | 2026-05-29 | OpenSC | OpenSC | 1.0 | 🔗 | Nicholas Carlini of Anthropic | |
| CVE-2026-40510 | 2026-05-29 | OpenSC | OpenSC | 1.0 | Nicholas Carlini of Anthropic | ||
| CVE-2026-48896 | 2026-05-26 | Joomla! | Joomla! CMS | 8.2 | Doyensec in collaboration with Claude and Anthropic Research | ||
| CVE-2026-41401 | 2026-05-26 | libyang | libyang | 6.9 | 🔗 | https://www.vulncheck.com/advisories/libyang-heap-use-after-free-write-in-xml-metadata-parsing | |
| CVE-2026-40384 | 2026-05-26 | Joomla! | Joomla! CMS | 5.9 | 🔗 | Doyensec in collaboration with Claude and Anthropic Research | |
| CVE-2026-40383 | 2026-05-26 | Joomla! | Joomla! CMS | 7.5 | 🔗 | Doyensec in collaboration with Claude and Anthropic Research | |
| CVE-2026-40034 | 2026-05-26 | gitoxide | gitoxide | 7.3 | https://www.vulncheck.com/advisories/gitoxide-command-injection-via-partial-gitmodules-override-in-gix-submodule | ||
| CVE-2026-40033 | 2026-05-26 | FreeRDP | FreeRDP | 8.6 | 🔗 | https://www.vulncheck.com/advisories/freerdp-heap-buffer-overflow-in-gdi-cachetosurface-via-rectangle-validation-bypass | |
| CVE-2026-44212 | 2026-05-14 | PrestaShop | PrestaShop | 7.8 | Reported by Savio at Doyensec (anthropic@doyensec.com) in collaboration with Anthropic Research. | ||
| CVE-2026-6479 | 2026-05-14 | PostgreSQL | PostgreSQL | 7.5 | 🔗 | The PostgreSQL project thanks Calif.io in collaboration with Claude and Anthropic Research for reporting this problem. | |
| CVE-2026-44471 | 2026-05-13 | gitoxide | gitoxide | 7.8 | This vulnerability was found by AI (specifically, Claude Mythos) as part of Project Glasswing. I have verified this and most of this advisory has been written by my probably-inferior human brain. | ||
| CVE-2026-40403 | 2026-05-12 | Microsoft | Windows | 8.8 | Calif.io in collaboration with Claude and Anthropic Research | ||
| CVE-2026-40398 | 2026-05-12 | Microsoft | Windows | 8.0 | Calif.io and Milad Nasr (Anthropic) with Claude with Calif.io and Anthropic | ||
| CVE-2026-40380 | 2026-05-12 | Microsoft | Windows | 6.2 | Calif.io in collaboration with Claude and Anthropic Research | ||
| CVE-2026-40369 | 2026-05-12 | Microsoft | Windows | 7.8 | Calif.io in collaboration with Claude and Anthropic Research Adrian Denkiewicz at Doyensec in collaboration with Anthropic Research https://doyensec.com/ Len Sadowski (lytnc) https://sec-fault.com/ and Oguz Bektas (ozb) https://ozbsec.com/ | ||
| CVE-2026-7474 | 2026-05-12 | HashiCorp | Nomad | 8.8 | 🔗 | This issue was reported to HashiCorp by Adrian Denkiewicz at Doyensec in collaboration with Claude and Anthropic Research | |
| CVE-2026-42600 | 2026-05-11 | minio | minio | 6.9 | Anthropic Advisory NOT IN CVE TABLE | ||
| CVE-2026-28952 | 2026-05-11 | Apple | Iphone/Ipad | 7.5 | Calif.io in collaboration with Claude and Anthropic Research | ||
| CVE-2026-28942 | 2026-05-11 | Apple | Webkit | 6.5 | Milad Nasr and Nicholas Carlini with Claude, Anthropic | ||
| CVE-2026-4892 | 2026-05-11 | dnsmasq | dnsmasq | 8.4 | 🔗 | Anthropic | |
| CVE-2026-4890 | 2026-05-11 | dnsmasq | dnsmasq | 7.5 | 🔗 | Anthropic | |
| CVE-2026-43185 | 2026-05-06 | Linux | Linux | 9.8 | Signed-off-by: Nicholas Carlini nicholas@carlini.com | ||
| CVE-2026-43074 | 2026-05-06 | Linux | Linux | 7.8 | 🔗 | Anthropic | |
| CVE-2026-40685 | 2026-04-30 | Exim | Exim | 6.5 | 🔗 | Anthropic | |
| CVE-2026-31554 | 2026-04-24 | Linux | Linux | 7.8 | 🔗 | Reported-by: Nicholas Carlini npc@anthropic.com | |
| CVE-2026-41990 | 2026-04-23 | gnupg | Libgcrypt | 4.0 | 🔗 | Reported by Calif.io in collaboration with Claude and Anthropic Research | |
| CVE-2026-29198 | 2026-04-22 | Rocket.Chat | Rocket.Chat | 9.8 | 🔗 | Anthropic | |
| CVE-2026-6386 | 2026-04-22 | FreeBSD | FreeBSD | 6.2 | 🔗 | Nicholas Carlini using Claude, Anthropic | |
| CVE-2026-5398 | 2026-04-22 | FreeBSD | FreeBSD | 8.4 | 🔗 | Nicholas Carlini using Claude, Anthropic | |
| CVE-2026-6772 | 2026-04-21 | Mozilla | Firefox | 7.5 | 🔗 | sseehra | |
| CVE-2026-6758 | 2026-04-21 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-6757 | 2026-04-21 | Mozilla | Firefox | 7.5 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-6746 | 2026-04-21 | Mozilla | Firefox | 7.5 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-5588 | 2026-04-15 | Legion of the Bouncy Castle Inc. | BC-JAVA | 6.3 | Nicholas Carlini using Claude, Anthropic | ||
| CVE-2026-33096 | 2026-04-14 | Microsoft | Windows | 7.5 | Milad Nasr (Anthropic) and Calif.io with Claude | ||
| CVE-2026-33901 | 2026-04-13 | ImageMagick | ImageMagick | 7.5 | 🔗 | Anthropic Advisory NOT IN CVE TABLE | |
| CVE-2026-32316 | 2026-04-13 | jqlang | JQ | 7.5 | 🔗 | Anthropic Advisory | |
| CVE-2026-57191 | Reserved | asterisk | asterisk | 🔗 | Anthropic | ||
| CVE-2026-5501 | 2026-04-10 | wolfSSL | wolfSSL | 8.6 | 🔗 | Calif.io in collaboration with Claude and Anthropic Research | |
| CVE-2026-5500 | 2026-04-10 | wolfSSL | wolfSSL | 8.7 | 🔗 | Calif.io in collaboration with Claude and Anthropic Research | |
| CVE-2026-5479 | 2026-04-10 | wolfSSL | wolfSSL | 7.6 | 🔗 | Calif.io in collaboration with Claude and Anthropic Research | |
| CVE-2026-5477 | 2026-04-10 | wolfSSL | wolfSSL | 8.2 | 🔗 | Calif.io in collaboration with Claude and Anthropic Research | |
| CVE-2026-5466 | 2026-04-10 | wolfSSL | wolfSSL | 7.6 | 🔗 | Calif.io in collaboration with Claude and Anthropic Research | |
| CVE-2026-5503 | 2026-04-09 | wolfSSL | wolfSSL | 6.9 | 🔗 | Calif.io in collaboration with Claude and Anthropic Research | |
| CVE-2026-5448 | 2026-04-09 | wolfSSL | wolfSSL | 2.3 | 🔗 | Anthropic Advisory | |
| CVE-2026-5447 | 2026-04-09 | wolfSSL | wolfSSL | 6.3 | 🔗 | Calif.io in collaboration with Claude and Anthropic Research | |
| CVE-2026-5446 | 2026-04-09 | wolfSSL | wolfSSL | 6.0 | 🔗 | Calif.io in collaboration with Claude and Anthropic Research | |
| CVE-2026-5295 | 2026-04-09 | wolfSSL | wolfSSL | 5.9 | 🔗 | Sunwoo Lee, (Korea Institute of Energy Technology, KENTECH) | Woohyun Choi, (Korea Institute of Energy Technology, KENTECH) | Seunghyun Yoon, (Korea Institute of Energy Technology, KENTECH) | |
| CVE-2026-5194 | 2026-04-09 | wolfSSL | wolfSSL | 9.3 | 🔗 | Nicholas Carlini from Anthropic | |
| CVE-2026-34580 | 2026-04-07 | Botan | Botan | 7.5 | 🔗 | Nicholas Carlini with Claude, Anthropic | |
| CVE-2026-28386 | 2026-04-07 | OpenSSL | OpenSSL | 9.1 | Stanislav Fort (Aisle Research); Pavel Kohout (Aisle Research); Alex Gaynor (Anthropic) | ||
| CVE-2026-5747 | 2026-04-07 | AWS | FireCracker | 8.7 | 🔗 | We thank Anthropic for reporting this concern to the AWS Vulnerability Disclosure Program. | |
| CVE-2026-35022 | Reserved | ||||||
| CVE-2026-31402 | 2026-04-03 | Linux | Linux | 9.8 | Reported-by: Nicholas Carlini npc@anthropic.com | ||
| CVE-2026-5199 | 2026-04-01 | temporalio | temporal | 2.3 | 🔗 | Anthropic Advisory | |
| CVE-2026-7275 | Reserved | moodle | moodle | 🔗 | Anthropic | ||
| CVE-2026-68521 | Reserved | unicorn | 🔗 | Anthropic | |||
| CVE-2026-62257 | Reserved | htslib | 🔗 | Anthropic | |||
| CVE-2026-33721 | 2026-03-26 | MapServer | MapServer | 5.3 | 🔗 | Anthropic Advisory | |
| CVE-2026-4747 | 2026-03-26 | FreeBSD | FreeBSD | 8.8 | 🔗 | Nicholas Carlini using Claude, Anthropic | |
| CVE-2026-54914 | Reserved | bytecodealliance | wasm-micro-runtime | 🔗 | Anthropic | ||
| CVE-2026-27654 | 2026-03-24 | F5 | NGINX Plus | 8.2 | 🔗 | Calif.io in collaboration with Claude and Anthropic Research | |
| CVE-2026-4724 | 2026-03-24 | Mozilla | Firefox | 9.1 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-4723 | 2026-03-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-4718 | 2026-03-24 | Mozilla | Firefox | 8.1 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-4705 | 2026-03-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-4704 | 2026-03-24 | Mozilla | Firefox | 7.5 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-4702 | 2026-03-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-4600 | 2026-03-23 | jsrsasign | jsrsasign | 9.1 | reported by Koda Reef, Nicholas Carlini and @Kr0emer | ||
| CVE-2026-61627 | Reserved | libass | libass | 🔗 | Anthropic | ||
| CVE-2026-32267 | 2026-03-16 | craftcms | cms | 7.7 | Anthropic Advisory | ||
| CVE-2026-28208 | 2026-02-26 | junrar | junrar | 5.9 | Anthropic Advisory | ||
| CVE-2026-2805 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2804 | 2026-02-24 | Mozilla | Firefox | 5.4 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2799 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2797 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2796 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2791 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2789 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2788 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2787 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2786 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2785 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2775 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2774 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2773 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2772 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2771 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2770 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2769 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2766 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2765 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2764 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-2763 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic | ||
| CVE-2026-26980 | 2026-02-19 | Ghost | Ghost | 9.4 | 🔗 | ✅ | We thank Nicholas Carlini using Claude, Anthropic for disclosing this vulnerability responsibly. |