patrickmgarrity/Anthropic-Credited-CVEs

Tracking Vulnerabilities That Appear to be Credited to the Anthropic Research Team

80

2,413 commits

updated Oct 4, 2026

See the code

See what people are saying

README

ANTHROPIC CVE TRACKER

Overview

Tracking vulnerabilities that credit the Anthropic research team and are possibly discovered by Project Glasswing.

CURRENT CVE COUNT: 300

Fixed Anthropic Findings w/o CVE: 128

Findings Withdrawn by Anthropic: 243

Distributions

CVSS severity distribution Exploited in the wild (VulnCheck KEV)

Anthropic Research

Add a Vulnerability

If you find an Anthropic credited vulnerability, please open a Pull Request or Send me a message on linkedin or in the Extended Vulnerability Community Discord.

Considerations

This project is maintained on a best effort basis.

The List

CVEDateVendorProductCVSSLedgervcKEVCredit
CVE-2026-1036042026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.7Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-1036032026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.7Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-1036022026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.2Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-1036012026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.2Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-668582026-10-02Apache Software FoundationApache Thrift8.7Claude (Anthropic Research) | Arthur Chan, Ada Logics | Apache Thrift Developers
CVE-2026-668372026-10-02Apache Software FoundationApache Thrift8.7Claude (Anthropic Research) | Arthur Chan, Ada Logics (arthur.chan@adalogics.com)
CVE-2026-660812026-10-02Apache Software FoundationApache Thrift8.7Akhil Koul | Claude (Anthropic Research) | Arthur Chan, Ada Logics (arthur.chan@adalogics.com)
CVE-2026-637722026-10-02Apache Software FoundationApache Thrift8.7Anthropic (agentic research) + Ada Logics; reported by Adam Korczynski
CVE-2026-635782026-10-02Legion of the Bouncy Castle Inc.bc-csharp7.1Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-635772026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.2Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-635762026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.2Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-635742026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.7Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-635732026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.2Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-635712026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.7Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-635702026-10-02Legion of the Bouncy Castle Inc.bc-csharp7.1Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-635692026-10-02Legion of the Bouncy Castle Inc.bc-csharp9.1Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-635682026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.7Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-635672026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.2Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-635662026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.7Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-613732026-10-02Apache Software FoundationApache Thrift8.7Claude (Anthropic Research) | Arthur Chan, Ada Logics (arthur.chan@adalogics.com) | n0mi1k
CVE-2026-175082026-10-02Legion of the Bouncy Castle Inc.BC-JAVA5.3Mirko Swillus on behalf of Alpha-Omega (alpha-omega.dev), using Scrutineer with an Anthropic Claude model provided through Project Glasswing | Yu Bao from the PayPal Cyber Security Team
CVE-2026-175072026-10-02Legion of the Bouncy Castle Inc.BC-JAVA8.7Mirko Swillus on behalf of Alpha-Omega (alpha-omega.dev), using Scrutineer with an Anthropic Claude model provided through Project Glasswing
CVE-2026-160012026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.2Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-160002026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.7Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-159992026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.2Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-935462026-10-01Apache Software FoundationApache HTTP Server8.8Zhen Kong | Calif.io in collaboration with Anthropic | AISLE in partnership with Red Hat
CVE-2026-1012832026-09-30esnetiperf39.2Anthropic | Ada Logics
CVE-2026-1012762026-09-30esnetiperf39.2Anthropic | Ada Logics
CVE-2026-964232026-09-29Wireshark FoundationWireshark5.5Claude and Ada Logics
CVE-2026-964212026-09-29Wireshark FoundationWireshark5.5Claude and Ada Logics
CVE-2026-964182026-09-29Wireshark FoundationWireshark5.5Credit: Claude and Ada Logics
CVE-2026-964162026-09-29Wireshark FoundationWireshark5.5Claude and Ada Logics
CVE-2026-922222026-09-29Joomla! ProjectJoomla! CMS8.9Aria Akhavan | Calif.io in collaboration with Anthropic
CVE-2026-909152026-09-29Joomla! ProjectJoomla! CMS7.0Aria Akhavan | Calif.io in collaboration with Anthropic
CVE-2026-944192026-09-27wolfSSLwolfSSL2.3Anthropic OSS program
CVE-2026-944182026-09-27wolfSSLwolfSSL2.3Anthropic OSS program
CVE-2026-944172026-09-27wolfSSLwolfSSL2.3Anthropic OSS program
CVE-2026-933042026-09-27wolfSSLwolfSSL6.3Anthropic OSS program
CVE-2026-933022026-09-27wolfSSLwolfSSL8.3Anthropic OSS program
CVE-2026-981342026-09-25LinuxLinux
CVE-2026-980852026-09-25LinuxLinux
CVE-2026-980622026-09-25LinuxLinux5.5Reported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com
CVE-2026-980612026-09-25LinuxLinuxReported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com
CVE-2026-980602026-09-25LinuxLinuxReported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com
CVE-2026-980582026-09-25LinuxLinuxReported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com
CVE-2026-980492026-09-25LinuxLinuxReported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com
CVE-2026-980472026-09-25LinuxLinuxReported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com
CVE-2026-980402026-09-25LinuxLinuxReported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com
CVE-2026-980382026-09-25LinuxLinuxReported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com
CVE-2026-980372026-09-25LinuxLinuxReported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com
CVE-2026-980362026-09-25LinuxLinuxReported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com
CVE-2026-980342026-09-25LinuxLinuxReported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com
CVE-2026-980332026-09-25LinuxLinuxReported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com
CVE-2026-975242026-09-25LinuxLinux7.5Reported-by: Xinyang Ge xinyang@anthropic.com
CVE-2026-975232026-09-25LinuxLinux7.5Reported-by: Xinyang Ge xinyang@anthropic.com
CVE-2026-968122026-09-25GooglegVisor8.8Anthropic (using Claude)
CVE-2026-894222026-09-22ErlangOTP9.3Milad Nasr / Anthropic | Luna Tong / Anthropic | Ingela Andin
CVE-2026-632762026-09-22The Document FoundationLibreOffice5.4🔗Claude, found by Anthropic using agents to study the security of open-source projects | Ada Logics, validating and reporting | Caolán McNamara of Collabora Productivity
CVE-2026-632752026-09-22The Document FoundationLibreOffice5.4🔗Claude, found by Anthropic using agents to study the security of open-source projects | Ada Logics, validating and reporting | Caolán McNamara of Collabora Productivity
CVE-2026-632742026-09-22The Document FoundationLibreOffice5.4🔗Claude, found by Anthropic using agents to study the security of open-source projects | Ada Logics, validating and reporting | Caolán McNamara of Collabora Productivity
CVE-2026-632732026-09-22The Document FoundationLibreOffice5.4🔗Claude, found by Anthropic using agents to study the security of open-source projects | Ada Logics, validating and reporting | Caolán McNamara of Collabora Productivity
CVE-2026-632722026-09-22The Document FoundationLibreOffice5.4🔗Claude, found by Anthropic using agents to study the security of open-source projects | Ada Logics, validating and reporting | Caolán McNamara of Collabora Productivity
CVE-2026-932922026-09-17SigNozsignoz8.44NK1T | axel-corsiez | morimori-dev | newugly | thaidn (Calif.io, in collaboration with Anthropic) | hackchang | Scott Moore - VulnCheck
CVE-2026-442362026-09-17alanxzrabbitmq-c7.1🔗Anthropic
CVE-2026-442352026-09-17alanxzrabbitmq-c6.5🔗Anthropic
CVE-2026-927292026-09-16SigNozsignoz8.84NK1T | lighthousekeeper1212 | 0xVijay | axel-corsiez | morimori-dev | PLpaPLpa | newugly | thaidn (Calif.io, in collaboration with Anthropic) | hackchang | Wenhao Wu (d3do-23), Southeast University
CVE-2026-911042026-09-16HP Inc.HP Linux Imaging and Printing Software (HPLIP)9.3Calif.io in collaboration with Anthropic
CVE-2026-827172026-09-16NLnet LabsUnbound8.4Ben Morris (Anthropic)
CVE-2026-654102026-09-14AppleAVEVideoEncoder7.5Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-654092026-09-14AppleFoundation5.5Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-653762026-09-14AppleSMB5.5재영 정, Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-653752026-09-14AppleWebDAV7.5YingMuo (@YingMuo) of DEVCORE Research Team, Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-653742026-09-14AppleWebDAV8.8HE WEI(ギカク), Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-437192026-09-14AppleSMB6.5Jakob Pammer, Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-436902026-09-14AppleSMB4.7Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-436772026-09-14AppleWebDAV6.5bubu, Omar Cerrito, HE WEI(ギカク), Roman Zabicki, Richard Zana, Chris Bailey - Short Circuit, Aswin Kumar Gokulakannan, Surya Narayan Kushwaha, Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-457522026-09-10OISFsuricata5.9🔗Anthropic
CVE-2026-457512026-09-10OISFsuricata5.9🔗Anthropic
CVE-2026-796782026-09-07Red HatRed Hat Enterprise Linux 108.1Red Hat would like to thank Calif.io (in collaboration with Anthropic) for reporting this issue.
CVE-2026-184532026-09-07Red HatRed Hat Directory Server 117.5Red Hat would like to thank Arthur Chan (Ada Logics) and Team (Anthropic) for reporting this issue.
CVE-2026-183552026-09-07Red HatRed Hat Directory Server 117.5Red Hat would like to thank Adam Korczynski (Ada Logics), Arthur Chan (Ada Logics), David Korczynski (Ada Logics), and Team (Anthropic) for reporting this issue.
CVE-2026-149572026-09-02The Libreswan Projectlibreswan7.5Claude (Anthropic) | Guillaume Winter
CVE-2026-805902026-08-28LinuxLinux8.6Signed-off-by: Xinyang Ge xinyang@anthropic.com
CVE-2026-768912026-08-19Wireshark FoundationWireshark3.1🔗Claude and Ada Logics
CVE-2026-768902026-08-19Wireshark FoundationWireshark3.1🔗Claude and Ada Logics
CVE-2026-768882026-08-19Wireshark FoundationWireshark3.1🔗Claude and Ada Logics
CVE-2026-636522026-08-19FreeRDPFreeRDP7.1🔗Anthropic
CVE-2026-636332026-08-19FreeRDPFreeRDP7.7🔗Anthropic
CVE-2026-130022026-08-14Red HatRed Hat Enterprise Linux 104.4🔗Red Hat would like to thank Lennart Espe for reporting this issue.
CVE-2026-584352026-08-13GiteaGitea Open Source Git Server5.4🔗adrian-doyensec
CVE-2026-196942026-08-13Wireshark FoundationWireshark4.7🔗Claude and Ada Logics
CVE-2026-162392026-08-13n/aPostgreSQL8.8The PostgreSQL project thanks Ben Morris (Claude and Anthropic Research) for reporting this problem.
CVE-2026-157422026-08-13n/aPostgreSQL8.8The PostgreSQL project thanks Ben Morris (Claude and Anthropic Research) for reporting this problem.
CVE-2026-157412026-08-13n/aPostgreSQL8.8The PostgreSQL project thanks Ben Morris (Claude and Anthropic Research) for reporting this problem.
CVE-2026-687602026-08-12jfrogartifactory5.3Ben Morris in collaboration with Claude and Anthropic Research
CVE-2026-687572026-08-12jfrogartifactory7.5Ben Morris in collaboration with Claude and Anthropic Research
CVE-2026-687562026-08-12jfrogartifactory6.6Ben Morris in collaboration with Claude and Anthropic Research
CVE-2026-663762026-08-12jfrogartifactory4.2Ben Morris in collaboration with Claude and Anthropic Research
CVE-2026-186632026-08-12Red HatRed Hat Directory Server 115.9Red Hat would like to thank Adam Korczynski (Ada Logics), Arthur Chan (Ada Logics), David Korczynski (Ada Logics), and Team (Anthropic) for reporting this issue.
CVE-2026-732422026-08-11FreeRDPFreeRDP8.3🔗Anthropic
CVE-2026-732412026-08-11FreeRDPFreeRDP8.3🔗Anthropic
CVE-2026-72746Reserved🔗Anthropic
CVE-2026-118362026-08-04CaliptraCore ROM1.8Alex Matrosov with Claude, Anthropic
CVE-2026-118352026-08-04CaliptraCore ROM5.6Alex Matrosov with Claude, Anthropic
CVE-2026-596522026-08-03Legion of the Bouncy Castle Inc.BC-JAVA6.9Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-596512026-08-03Legion of the Bouncy Castle Inc.BC-JAVA7.1Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-596502026-08-03Legion of the Bouncy Castle Inc.BC-JAVA9.3Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-596492026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-596482026-08-03Legion of the Bouncy Castle Inc.BC-JAVA6.9Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-596472026-08-03Legion of the Bouncy Castle Inc.BC-JAVA6.9Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-596462026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-596452026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-596442026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-596432026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-596422026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-596412026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-596402026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-596392026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-596382026-08-03Legion of the Bouncy Castle Inc.BC-JAVA9.3Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-580632026-08-03Legion of the Bouncy Castle Inc.BC-JAVA5.3Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-580622026-08-03Legion of the Bouncy Castle Inc.BC-JAVA9.3Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-580612026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-580602026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-580592026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-150552026-08-03Legion of the Bouncy Castle Inc.BC-JAVA5.3Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-135062026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Yt | Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-128602026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-128172026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-128162026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-128032026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-121852026-08-03Legion of the Bouncy Castle Inc.BC-JAVA7.1Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-87632026-08-03Legion of the Bouncy Castle Inc.BC-JAVA9.3Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-685792026-08-02FreeRDPFreeRDP8.7🔗DavidKorczynski
CVE-2026-654232026-07-30o6 Automationopen625418.8🔗Abhinav Agarwal reported this vulnerability to CISA. | Asher Davila and Malav Vyas of Palo Alto Networks reported this vulnerability to CISA.
CVE-2026-635592026-07-30o6 Automationopen625417.5🔗Asher Davila and Malav Vyas of Palo Alto Networks reported this vulnerability to CISA.
CVE-2026-614872026-07-28Apache Software FoundationApache ActiveMQ Broker6.5Claude and Ada Logics
CVE-2026-660322026-07-24libssh2libssh28.7🔗VladimirEliTokarev
CVE-2026-550842026-07-21dhis2dhis2-core8.8🔗Anthropic
CVE-2026-646242026-07-20FreeRDPFreeRDP8.5🔗DavidKorczynski
CVE-2026-646212026-07-20FreeRDPFreeRDP9.3🔗DavidKorczynski
CVE-2026-646202026-07-20FreeRDPFreeRDP9.3🔗DavidKorczynski
CVE-2026-355902026-07-20libvipslibvips6.8🔗Anthropic
CVE-2026-640152026-07-19LinuxLinux7.8
CVE-2026-466392026-07-14twigphpTwig7.1🔗Twig would like to thank Anvil Secure in collaboration with Claude and Anthropic Research for reporting and fixing the issue.
CVE-2026-466332026-07-14twigphpTwig8.7🔗Twig would like to thank Anvil Secure in collaboration with Claude and Anthropic Research for reporting and fixing the issue.
CVE-2026-450672026-07-14symfonysymfony6.3
CVE-2026-615052026-07-13rejettohfs6.9Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research
CVE-2026-615042026-07-13rejettohfs5.1Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research
CVE-2026-615032026-07-13rejettohfs6.9Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research
CVE-2026-615022026-07-13rejettohfs5.1Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research
CVE-2026-615012026-07-13rejettohfs5.3Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research
CVE-2026-615002026-07-13rejettohfs9.3✅Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research
CVE-2026-151702026-07-08Wireshark FoundationWireshark5.5🔗Claude and Ada Logics
CVE-2026-151692026-07-08Wireshark FoundationWireshark5.5Claude and Ada Logics
CVE-2026-151662026-07-08Wireshark FoundationWireshark5.5🔗Claude and Ada Logics
CVE-2026-151652026-07-08Wireshark FoundationWireshark5.5🔗Claude and Ada Logics
CVE-2026-463542026-07-07codercoder9.1We'd like to thank Ben Tran of calif.io and Anthropic’s Security Team (ANT-2026-22445) for independently disclosing this issue!
CVE-2026-457962026-07-07codercoder6.5We'd like to thank Ben Tran of calif.io and Anthropic's Security Team (ANT-2026-22447) for independently disclosing this issue!
CVE-2026-277752026-07-03GiteaGitea Open Source Git Server8.8adrian-doyensec
CVE-2026-415792026-07-01opencontainersrunc3.3🔗Anthropic
CVE-2026-202152026-07-01CiscoCisco Secure Endpoint7.5🔗Anthropic
CVE-2026-202142026-07-01CiscoCisco Secure Endpoint7.5🔗Anthropic
CVE-2026-202132026-07-01CiscoCisco Secure Endpoint7.5🔗Anthropic
CVE-2026-437152026-06-29AppleIOS8.8Milad Nasr and Nicholas Carlini with Claude, Anthropic
CVE-2026-135952026-06-29Red HatRed Hat Hardened Images6.8🔗Red Hat would like to thank Thai Duong (Calif.io in collaboration with Claude and Anthropic Research) for reporting this issue.
CVE-2026-532832026-06-26LinuxLinux5.5Reported-by: Ziyuan Chen zc@anthropic.com | Tested-by: Ziyuan Chen zc@anthropic.com
CVE-2026-123402026-06-25wolfSSLwolfSSL6.3🔗David Pokora, Trail of Bits (in collaboration with Anthropic)
CVE-2026-75312026-06-25wolfSSLwolfSSL2.3Thai Duong (Calif.io / Anthropic)
CVE-2026-75112026-06-25wolfSSLwolfSSL5.9Nicholas Carlini from Anthropic
CVE-2026-66812026-06-25wolfSSLwolfSSL1.0Nicholas Carlini from Anthropic
CVE-2026-66792026-06-25wolfSSLwolfSSL8.8Nicholas Carlini from Anthropic
CVE-2026-66782026-06-25wolfSSLwolfSSL1.0🔗Dikai Zou
CVE-2026-63312026-06-25wolfSSLwolfSSL2.1Nicholas Carlini from Anthropic
CVE-2026-63302026-06-25wolfSSLwolfSSL6.3Nicholas Carlini from Anthropic
CVE-2026-63292026-06-25wolfSSLwolfSSL6.0Nicholas Carlini from Anthropic
CVE-2026-463492026-06-24mastodonmastodon5.3🔗Anthropic Advisory NOT IN CVE TABLE
CVE-2026-463482026-06-24mastodonmastodon8.7🔗Anthropic Advisory NOT IN CVE TABLE
CVE-2026-561322026-06-19libexpat projectlibexpat6.9🔗Anthropic
CVE-2026-456962026-06-18AcademySoftwareFoundationopenexr8.3🔗Anthropic
CVE-2026-489292026-06-16Rocket.ChatRocket.Chat7.5🔗Anthropic
CVE-2026-83582026-06-15The Document FoundationLibreOffice5.4🔗Anthropic (automated discovery using Claude) | Arthur Chan of Ada Logics (validation and reporting)
CVE-2026-83572026-06-15The Document FoundationLibreOffice5.4🔗Anthropic (automated discovery using Claude) | Arthur Chan of Ada Logics (validation and reporting)
CVE-2026-83562026-06-15The Document FoundationLibreOffice5.4🔗Anthropic (automated discovery using Claude) | Arthur Chan of Ada Logics (validation and reporting)
CVE-2026-60472026-06-15The Document FoundationLibreOffice5.4🔗Anthropic (automated discovery using Claude) | Trail of Bits (triage and validation)
CVE-2026-60452026-06-15The Document FoundationLibreOffice5.4🔗Anthropic (automated discovery using Claude) | Trail of Bits (triage and validation)
CVE-2026-60402026-06-15The Document FoundationLibreOffice5.4🔗Anthropic (automated discovery using Claude) | Trail of Bits (triage and validation)
CVE-2026-60392026-06-15The Document FoundationLibreOffice5.4🔗Anthropic (automated discovery using Claude) | Trail of Bits (triage and validation)
CVE-2026-454472026-06-09OpenSSLOpenSSL8.8🔗Thai Duong (Calif.io in collaboration with Claude and Anthropic Research) | Igor Ustinov
CVE-2026-454462026-06-09OpenSSLOpenSSL4.8Alex Gaynor (Anthropic) | Dmitry Belyavskiy (Red Hat)
CVE-2026-454452026-06-09OpenSSLOpenSSL7.5Alex Gaynor (Anthropic) | Viktor Dukhovni
CVE-2026-427702026-06-09OpenSSLOpenSSL3.7Alex Gaynor (Anthropic) | Alex Gaynor (Anthropic) | Viktor Dukhovni | Norbert Pócs
CVE-2026-427692026-06-09OpenSSLOpenSSL5.3Alex Gaynor (Anthropic) | Alex Gaynor (Anthropic) | Bob Beck
CVE-2026-427682026-06-09OpenSSLOpenSSL3.7Alex Gaynor (Anthropic) | Dmitry Belyavskiy (Red Hat) | Alicja Kario (Red Hat)
CVE-2026-341822026-06-09OpenSSLOpenSSL9.1Asim Viladi Oglu Manizada | Alex Gaynor (Anthropic) | Ying Dong | Haiyang Huang | Neil Horman
CVE-2026-341812026-06-09OpenSSLOpenSSL7.4Pavol Žáčik (Red Hat) | Alex Gaynor (Anthropic) | Alicja Kario (Red Hat)
CVE-2026-499752026-06-08Apache Software FoundationApache HTTP Server7.5Quang Luong of Calif.IO in collaboration with OpenAI Codex
CVE-2026-473452026-06-08TYPO3HTML Sanitizer5.1🔗Doyensec in collaboration with Claude and Anthropic Research | Benjamin Franzke
CVE-2026-477322026-06-05twigtwig7.1@fabpot (remediation_developer)
CVE-2026-472502026-06-05npmmcp-server-kubernetes6.1@yotampe-pluto (reporter)
CVE-2026-84622026-06-04github.comopenmeterio/openmeter8.9🔗Anthropic
CVE-2026-474292026-06-01npmvitest9.8@sapphi-red (reporter) | @qispark (analyst) | @joevin-slq-docto (analyst) | @koteswar-k (analyst) | @SaronGrave (analyst) | @jason-anthropic (analyst)
CVE-2026-473912026-05-29pipPraisonAI9.8@foxirain (reporter)
CVE-2026-457002026-05-29FreeRDPFreeRDP7.7🔗Anthropic Advisory NOT IN CVE TABLE
CVE-2026-444212026-05-29FreeRDPFreeRDP8.8🔗Anthropic
CVE-2026-444202026-05-29FreeRDPFreeRDP8.8🔗Anthropic Advisory NOT IN CVE TABLE
CVE-2026-405282026-05-29OpenSCOpenSC1.0🔗Nicholas Carlini of Anthropic
CVE-2026-405102026-05-29OpenSCOpenSC1.0Nicholas Carlini of Anthropic
CVE-2026-488962026-05-26Joomla!Joomla! CMS8.2Doyensec in collaboration with Claude and Anthropic Research
CVE-2026-414012026-05-26libyanglibyang6.9🔗https://www.vulncheck.com/advisories/libyang-heap-use-after-free-write-in-xml-metadata-parsing
CVE-2026-403842026-05-26Joomla!Joomla! CMS5.9🔗Doyensec in collaboration with Claude and Anthropic Research
CVE-2026-403832026-05-26Joomla!Joomla! CMS7.5🔗Doyensec in collaboration with Claude and Anthropic Research
CVE-2026-400342026-05-26gitoxidegitoxide7.3https://www.vulncheck.com/advisories/gitoxide-command-injection-via-partial-gitmodules-override-in-gix-submodule
CVE-2026-400332026-05-26FreeRDPFreeRDP8.6🔗https://www.vulncheck.com/advisories/freerdp-heap-buffer-overflow-in-gdi-cachetosurface-via-rectangle-validation-bypass
CVE-2026-442122026-05-14PrestaShopPrestaShop7.8Reported by Savio at Doyensec (anthropic@doyensec.com) in collaboration with Anthropic Research.
CVE-2026-64792026-05-14PostgreSQLPostgreSQL7.5🔗The PostgreSQL project thanks Calif.io in collaboration with Claude and Anthropic Research for reporting this problem.
CVE-2026-444712026-05-13gitoxidegitoxide7.8This vulnerability was found by AI (specifically, Claude Mythos) as part of Project Glasswing. I have verified this and most of this advisory has been written by my probably-inferior human brain.
CVE-2026-404032026-05-12MicrosoftWindows8.8Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-403982026-05-12MicrosoftWindows8.0Calif.io and Milad Nasr (Anthropic) with Claude with Calif.io and Anthropic
CVE-2026-403802026-05-12MicrosoftWindows6.2Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-403692026-05-12MicrosoftWindows7.8Calif.io in collaboration with Claude and Anthropic Research Adrian Denkiewicz at Doyensec in collaboration with Anthropic Research https://doyensec.com/ Len Sadowski (lytnc) https://sec-fault.com/ and Oguz Bektas (ozb) https://ozbsec.com/
CVE-2026-74742026-05-12HashiCorpNomad8.8🔗This issue was reported to HashiCorp by Adrian Denkiewicz at Doyensec in collaboration with Claude and Anthropic Research
CVE-2026-426002026-05-11miniominio6.9Anthropic Advisory NOT IN CVE TABLE
CVE-2026-289522026-05-11AppleIphone/Ipad7.5Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-289422026-05-11AppleWebkit6.5Milad Nasr and Nicholas Carlini with Claude, Anthropic
CVE-2026-48922026-05-11dnsmasqdnsmasq8.4🔗Anthropic
CVE-2026-48902026-05-11dnsmasqdnsmasq7.5🔗Anthropic
CVE-2026-431852026-05-06LinuxLinux9.8Signed-off-by: Nicholas Carlini nicholas@carlini.com
CVE-2026-430742026-05-06LinuxLinux7.8🔗Anthropic
CVE-2026-406852026-04-30EximExim6.5🔗Anthropic
CVE-2026-315542026-04-24LinuxLinux7.8🔗Reported-by: Nicholas Carlini npc@anthropic.com
CVE-2026-419902026-04-23gnupgLibgcrypt4.0🔗Reported by Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-291982026-04-22Rocket.ChatRocket.Chat9.8🔗Anthropic
CVE-2026-63862026-04-22FreeBSDFreeBSD6.2🔗Nicholas Carlini using Claude, Anthropic
CVE-2026-53982026-04-22FreeBSDFreeBSD8.4🔗Nicholas Carlini using Claude, Anthropic
CVE-2026-67722026-04-21MozillaFirefox7.5🔗sseehra
CVE-2026-67582026-04-21MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-67572026-04-21MozillaFirefox7.5Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-67462026-04-21MozillaFirefox7.5Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-55882026-04-15Legion of the Bouncy Castle Inc.BC-JAVA6.3Nicholas Carlini using Claude, Anthropic
CVE-2026-330962026-04-14MicrosoftWindows7.5Milad Nasr (Anthropic) and Calif.io with Claude
CVE-2026-339012026-04-13ImageMagickImageMagick7.5🔗Anthropic Advisory NOT IN CVE TABLE
CVE-2026-323162026-04-13jqlangJQ7.5🔗Anthropic Advisory
CVE-2026-57191Reservedasteriskasterisk🔗Anthropic
CVE-2026-55012026-04-10wolfSSLwolfSSL8.6🔗Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-55002026-04-10wolfSSLwolfSSL8.7🔗Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-54792026-04-10wolfSSLwolfSSL7.6🔗Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-54772026-04-10wolfSSLwolfSSL8.2🔗Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-54662026-04-10wolfSSLwolfSSL7.6🔗Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-55032026-04-09wolfSSLwolfSSL6.9🔗Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-54482026-04-09wolfSSLwolfSSL2.3🔗Anthropic Advisory
CVE-2026-54472026-04-09wolfSSLwolfSSL6.3🔗Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-54462026-04-09wolfSSLwolfSSL6.0🔗Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-52952026-04-09wolfSSLwolfSSL5.9🔗Sunwoo Lee, (Korea Institute of Energy Technology, KENTECH) | Woohyun Choi, (Korea Institute of Energy Technology, KENTECH) | Seunghyun Yoon, (Korea Institute of Energy Technology, KENTECH)
CVE-2026-51942026-04-09wolfSSLwolfSSL9.3🔗Nicholas Carlini from Anthropic
CVE-2026-345802026-04-07BotanBotan7.5🔗Nicholas Carlini with Claude, Anthropic
CVE-2026-283862026-04-07OpenSSLOpenSSL9.1Stanislav Fort (Aisle Research); Pavel Kohout (Aisle Research); Alex Gaynor (Anthropic)
CVE-2026-57472026-04-07AWSFireCracker8.7🔗We thank Anthropic for reporting this concern to the AWS Vulnerability Disclosure Program.
CVE-2026-35022Reserved
CVE-2026-314022026-04-03LinuxLinux9.8Reported-by: Nicholas Carlini npc@anthropic.com
CVE-2026-51992026-04-01temporaliotemporal2.3🔗Anthropic Advisory
CVE-2026-7275Reservedmoodlemoodle🔗Anthropic
CVE-2026-68521Reservedunicorn🔗Anthropic
CVE-2026-62257Reservedhtslib🔗Anthropic
CVE-2026-337212026-03-26MapServerMapServer5.3🔗Anthropic Advisory
CVE-2026-47472026-03-26FreeBSDFreeBSD8.8🔗Nicholas Carlini using Claude, Anthropic
CVE-2026-54914Reservedbytecodealliancewasm-micro-runtime🔗Anthropic
CVE-2026-276542026-03-24F5NGINX Plus8.2🔗Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-47242026-03-24MozillaFirefox9.1Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-47232026-03-24MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-47182026-03-24MozillaFirefox8.1Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-47052026-03-24MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-47042026-03-24MozillaFirefox7.5Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-47022026-03-24MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-46002026-03-23jsrsasignjsrsasign9.1reported by Koda Reef, Nicholas Carlini and @Kr0emer
CVE-2026-61627Reservedlibasslibass🔗Anthropic
CVE-2026-322672026-03-16craftcmscms7.7Anthropic Advisory
CVE-2026-282082026-02-26junrarjunrar5.9Anthropic Advisory
CVE-2026-28052026-02-24MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-28042026-02-24MozillaFirefox5.4Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27992026-02-24MozillaFirefox8.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27972026-02-24MozillaFirefox8.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27962026-02-24MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27912026-02-24MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27892026-02-24MozillaFirefox8.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27882026-02-24MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27872026-02-24MozillaFirefox8.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27862026-02-24MozillaFirefox8.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27852026-02-24MozillaFirefox8.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27752026-02-24MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27742026-02-24MozillaFirefox8.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27732026-02-24MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27722026-02-24MozillaFirefox8.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27712026-02-24MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27702026-02-24MozillaFirefox8.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27692026-02-24MozillaFirefox8.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27662026-02-24MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27652026-02-24MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27642026-02-24MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27632026-02-24MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-269802026-02-19GhostGhost9.4🔗✅We thank Nicholas Carlini using Claude, Anthropic for disclosing this vulnerability responsibly.

patrickmgarrity/Anthropic-Credited-CVEs

Tracking Vulnerabilities That Appear to be Credited to the Anthropic Research Team

80

2,413 commits

updated Oct 4, 2026

See the code

See what people are saying

README

ANTHROPIC CVE TRACKER

Overview

Tracking vulnerabilities that credit the Anthropic research team and are possibly discovered by Project Glasswing.

CURRENT CVE COUNT: 300

Fixed Anthropic Findings w/o CVE: 128

Findings Withdrawn by Anthropic: 243

Distributions

CVSS severity distribution Exploited in the wild (VulnCheck KEV)

Anthropic Research

Add a Vulnerability

If you find an Anthropic credited vulnerability, please open a Pull Request or Send me a message on linkedin or in the Extended Vulnerability Community Discord.

Considerations

This project is maintained on a best effort basis.

The List

CVEDateVendorProductCVSSLedgervcKEVCredit
CVE-2026-1036042026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.7Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-1036032026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.7Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-1036022026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.2Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-1036012026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.2Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-668582026-10-02Apache Software FoundationApache Thrift8.7Claude (Anthropic Research) | Arthur Chan, Ada Logics | Apache Thrift Developers
CVE-2026-668372026-10-02Apache Software FoundationApache Thrift8.7Claude (Anthropic Research) | Arthur Chan, Ada Logics (arthur.chan@adalogics.com)
CVE-2026-660812026-10-02Apache Software FoundationApache Thrift8.7Akhil Koul | Claude (Anthropic Research) | Arthur Chan, Ada Logics (arthur.chan@adalogics.com)
CVE-2026-637722026-10-02Apache Software FoundationApache Thrift8.7Anthropic (agentic research) + Ada Logics; reported by Adam Korczynski
CVE-2026-635782026-10-02Legion of the Bouncy Castle Inc.bc-csharp7.1Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-635772026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.2Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-635762026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.2Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-635742026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.7Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-635732026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.2Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-635712026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.7Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-635702026-10-02Legion of the Bouncy Castle Inc.bc-csharp7.1Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-635692026-10-02Legion of the Bouncy Castle Inc.bc-csharp9.1Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-635682026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.7Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-635672026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.2Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-635662026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.7Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-613732026-10-02Apache Software FoundationApache Thrift8.7Claude (Anthropic Research) | Arthur Chan, Ada Logics (arthur.chan@adalogics.com) | n0mi1k
CVE-2026-175082026-10-02Legion of the Bouncy Castle Inc.BC-JAVA5.3Mirko Swillus on behalf of Alpha-Omega (alpha-omega.dev), using Scrutineer with an Anthropic Claude model provided through Project Glasswing | Yu Bao from the PayPal Cyber Security Team
CVE-2026-175072026-10-02Legion of the Bouncy Castle Inc.BC-JAVA8.7Mirko Swillus on behalf of Alpha-Omega (alpha-omega.dev), using Scrutineer with an Anthropic Claude model provided through Project Glasswing
CVE-2026-160012026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.2Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-160002026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.7Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-159992026-10-02Legion of the Bouncy Castle Inc.bc-csharp8.2Discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research.
CVE-2026-935462026-10-01Apache Software FoundationApache HTTP Server8.8Zhen Kong | Calif.io in collaboration with Anthropic | AISLE in partnership with Red Hat
CVE-2026-1012832026-09-30esnetiperf39.2Anthropic | Ada Logics
CVE-2026-1012762026-09-30esnetiperf39.2Anthropic | Ada Logics
CVE-2026-964232026-09-29Wireshark FoundationWireshark5.5Claude and Ada Logics
CVE-2026-964212026-09-29Wireshark FoundationWireshark5.5Claude and Ada Logics
CVE-2026-964182026-09-29Wireshark FoundationWireshark5.5Credit: Claude and Ada Logics
CVE-2026-964162026-09-29Wireshark FoundationWireshark5.5Claude and Ada Logics
CVE-2026-922222026-09-29Joomla! ProjectJoomla! CMS8.9Aria Akhavan | Calif.io in collaboration with Anthropic
CVE-2026-909152026-09-29Joomla! ProjectJoomla! CMS7.0Aria Akhavan | Calif.io in collaboration with Anthropic
CVE-2026-944192026-09-27wolfSSLwolfSSL2.3Anthropic OSS program
CVE-2026-944182026-09-27wolfSSLwolfSSL2.3Anthropic OSS program
CVE-2026-944172026-09-27wolfSSLwolfSSL2.3Anthropic OSS program
CVE-2026-933042026-09-27wolfSSLwolfSSL6.3Anthropic OSS program
CVE-2026-933022026-09-27wolfSSLwolfSSL8.3Anthropic OSS program
CVE-2026-981342026-09-25LinuxLinux
CVE-2026-980852026-09-25LinuxLinux
CVE-2026-980622026-09-25LinuxLinux5.5Reported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com
CVE-2026-980612026-09-25LinuxLinuxReported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com
CVE-2026-980602026-09-25LinuxLinuxReported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com
CVE-2026-980582026-09-25LinuxLinuxReported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com
CVE-2026-980492026-09-25LinuxLinuxReported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com
CVE-2026-980472026-09-25LinuxLinuxReported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com
CVE-2026-980402026-09-25LinuxLinuxReported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com
CVE-2026-980382026-09-25LinuxLinuxReported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com
CVE-2026-980372026-09-25LinuxLinuxReported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com
CVE-2026-980362026-09-25LinuxLinuxReported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com
CVE-2026-980342026-09-25LinuxLinuxReported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com
CVE-2026-980332026-09-25LinuxLinuxReported-by: Nicholas Carlini npc@anthropic.com | Suggested-by: Nicholas Carlini npc@anthropic.com
CVE-2026-975242026-09-25LinuxLinux7.5Reported-by: Xinyang Ge xinyang@anthropic.com
CVE-2026-975232026-09-25LinuxLinux7.5Reported-by: Xinyang Ge xinyang@anthropic.com
CVE-2026-968122026-09-25GooglegVisor8.8Anthropic (using Claude)
CVE-2026-894222026-09-22ErlangOTP9.3Milad Nasr / Anthropic | Luna Tong / Anthropic | Ingela Andin
CVE-2026-632762026-09-22The Document FoundationLibreOffice5.4🔗Claude, found by Anthropic using agents to study the security of open-source projects | Ada Logics, validating and reporting | Caolán McNamara of Collabora Productivity
CVE-2026-632752026-09-22The Document FoundationLibreOffice5.4🔗Claude, found by Anthropic using agents to study the security of open-source projects | Ada Logics, validating and reporting | Caolán McNamara of Collabora Productivity
CVE-2026-632742026-09-22The Document FoundationLibreOffice5.4🔗Claude, found by Anthropic using agents to study the security of open-source projects | Ada Logics, validating and reporting | Caolán McNamara of Collabora Productivity
CVE-2026-632732026-09-22The Document FoundationLibreOffice5.4🔗Claude, found by Anthropic using agents to study the security of open-source projects | Ada Logics, validating and reporting | Caolán McNamara of Collabora Productivity
CVE-2026-632722026-09-22The Document FoundationLibreOffice5.4🔗Claude, found by Anthropic using agents to study the security of open-source projects | Ada Logics, validating and reporting | Caolán McNamara of Collabora Productivity
CVE-2026-932922026-09-17SigNozsignoz8.44NK1T | axel-corsiez | morimori-dev | newugly | thaidn (Calif.io, in collaboration with Anthropic) | hackchang | Scott Moore - VulnCheck
CVE-2026-442362026-09-17alanxzrabbitmq-c7.1🔗Anthropic
CVE-2026-442352026-09-17alanxzrabbitmq-c6.5🔗Anthropic
CVE-2026-927292026-09-16SigNozsignoz8.84NK1T | lighthousekeeper1212 | 0xVijay | axel-corsiez | morimori-dev | PLpaPLpa | newugly | thaidn (Calif.io, in collaboration with Anthropic) | hackchang | Wenhao Wu (d3do-23), Southeast University
CVE-2026-911042026-09-16HP Inc.HP Linux Imaging and Printing Software (HPLIP)9.3Calif.io in collaboration with Anthropic
CVE-2026-827172026-09-16NLnet LabsUnbound8.4Ben Morris (Anthropic)
CVE-2026-654102026-09-14AppleAVEVideoEncoder7.5Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-654092026-09-14AppleFoundation5.5Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-653762026-09-14AppleSMB5.5재영 정, Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-653752026-09-14AppleWebDAV7.5YingMuo (@YingMuo) of DEVCORE Research Team, Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-653742026-09-14AppleWebDAV8.8HE WEI(ギカク), Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-437192026-09-14AppleSMB6.5Jakob Pammer, Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-436902026-09-14AppleSMB4.7Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-436772026-09-14AppleWebDAV6.5bubu, Omar Cerrito, HE WEI(ギカク), Roman Zabicki, Richard Zana, Chris Bailey - Short Circuit, Aswin Kumar Gokulakannan, Surya Narayan Kushwaha, Bruce Dang of Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-457522026-09-10OISFsuricata5.9🔗Anthropic
CVE-2026-457512026-09-10OISFsuricata5.9🔗Anthropic
CVE-2026-796782026-09-07Red HatRed Hat Enterprise Linux 108.1Red Hat would like to thank Calif.io (in collaboration with Anthropic) for reporting this issue.
CVE-2026-184532026-09-07Red HatRed Hat Directory Server 117.5Red Hat would like to thank Arthur Chan (Ada Logics) and Team (Anthropic) for reporting this issue.
CVE-2026-183552026-09-07Red HatRed Hat Directory Server 117.5Red Hat would like to thank Adam Korczynski (Ada Logics), Arthur Chan (Ada Logics), David Korczynski (Ada Logics), and Team (Anthropic) for reporting this issue.
CVE-2026-149572026-09-02The Libreswan Projectlibreswan7.5Claude (Anthropic) | Guillaume Winter
CVE-2026-805902026-08-28LinuxLinux8.6Signed-off-by: Xinyang Ge xinyang@anthropic.com
CVE-2026-768912026-08-19Wireshark FoundationWireshark3.1🔗Claude and Ada Logics
CVE-2026-768902026-08-19Wireshark FoundationWireshark3.1🔗Claude and Ada Logics
CVE-2026-768882026-08-19Wireshark FoundationWireshark3.1🔗Claude and Ada Logics
CVE-2026-636522026-08-19FreeRDPFreeRDP7.1🔗Anthropic
CVE-2026-636332026-08-19FreeRDPFreeRDP7.7🔗Anthropic
CVE-2026-130022026-08-14Red HatRed Hat Enterprise Linux 104.4🔗Red Hat would like to thank Lennart Espe for reporting this issue.
CVE-2026-584352026-08-13GiteaGitea Open Source Git Server5.4🔗adrian-doyensec
CVE-2026-196942026-08-13Wireshark FoundationWireshark4.7🔗Claude and Ada Logics
CVE-2026-162392026-08-13n/aPostgreSQL8.8The PostgreSQL project thanks Ben Morris (Claude and Anthropic Research) for reporting this problem.
CVE-2026-157422026-08-13n/aPostgreSQL8.8The PostgreSQL project thanks Ben Morris (Claude and Anthropic Research) for reporting this problem.
CVE-2026-157412026-08-13n/aPostgreSQL8.8The PostgreSQL project thanks Ben Morris (Claude and Anthropic Research) for reporting this problem.
CVE-2026-687602026-08-12jfrogartifactory5.3Ben Morris in collaboration with Claude and Anthropic Research
CVE-2026-687572026-08-12jfrogartifactory7.5Ben Morris in collaboration with Claude and Anthropic Research
CVE-2026-687562026-08-12jfrogartifactory6.6Ben Morris in collaboration with Claude and Anthropic Research
CVE-2026-663762026-08-12jfrogartifactory4.2Ben Morris in collaboration with Claude and Anthropic Research
CVE-2026-186632026-08-12Red HatRed Hat Directory Server 115.9Red Hat would like to thank Adam Korczynski (Ada Logics), Arthur Chan (Ada Logics), David Korczynski (Ada Logics), and Team (Anthropic) for reporting this issue.
CVE-2026-732422026-08-11FreeRDPFreeRDP8.3🔗Anthropic
CVE-2026-732412026-08-11FreeRDPFreeRDP8.3🔗Anthropic
CVE-2026-72746Reserved🔗Anthropic
CVE-2026-118362026-08-04CaliptraCore ROM1.8Alex Matrosov with Claude, Anthropic
CVE-2026-118352026-08-04CaliptraCore ROM5.6Alex Matrosov with Claude, Anthropic
CVE-2026-596522026-08-03Legion of the Bouncy Castle Inc.BC-JAVA6.9Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-596512026-08-03Legion of the Bouncy Castle Inc.BC-JAVA7.1Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-596502026-08-03Legion of the Bouncy Castle Inc.BC-JAVA9.3Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-596492026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-596482026-08-03Legion of the Bouncy Castle Inc.BC-JAVA6.9Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-596472026-08-03Legion of the Bouncy Castle Inc.BC-JAVA6.9Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-596462026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-596452026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-596442026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-596432026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-596422026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-596412026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-596402026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-596392026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-596382026-08-03Legion of the Bouncy Castle Inc.BC-JAVA9.3Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-580632026-08-03Legion of the Bouncy Castle Inc.BC-JAVA5.3Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-580622026-08-03Legion of the Bouncy Castle Inc.BC-JAVA9.3Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-580612026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-580602026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-580592026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-150552026-08-03Legion of the Bouncy Castle Inc.BC-JAVA5.3Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-135062026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Yt | Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-128602026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-128172026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-128162026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-128032026-08-03Legion of the Bouncy Castle Inc.BC-JAVA8.7Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-121852026-08-03Legion of the Bouncy Castle Inc.BC-JAVA7.1Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-87632026-08-03Legion of the Bouncy Castle Inc.BC-JAVA9.3Alex Gaynor in collaboration with Claude and Anthropic Research
CVE-2026-685792026-08-02FreeRDPFreeRDP8.7🔗DavidKorczynski
CVE-2026-654232026-07-30o6 Automationopen625418.8🔗Abhinav Agarwal reported this vulnerability to CISA. | Asher Davila and Malav Vyas of Palo Alto Networks reported this vulnerability to CISA.
CVE-2026-635592026-07-30o6 Automationopen625417.5🔗Asher Davila and Malav Vyas of Palo Alto Networks reported this vulnerability to CISA.
CVE-2026-614872026-07-28Apache Software FoundationApache ActiveMQ Broker6.5Claude and Ada Logics
CVE-2026-660322026-07-24libssh2libssh28.7🔗VladimirEliTokarev
CVE-2026-550842026-07-21dhis2dhis2-core8.8🔗Anthropic
CVE-2026-646242026-07-20FreeRDPFreeRDP8.5🔗DavidKorczynski
CVE-2026-646212026-07-20FreeRDPFreeRDP9.3🔗DavidKorczynski
CVE-2026-646202026-07-20FreeRDPFreeRDP9.3🔗DavidKorczynski
CVE-2026-355902026-07-20libvipslibvips6.8🔗Anthropic
CVE-2026-640152026-07-19LinuxLinux7.8
CVE-2026-466392026-07-14twigphpTwig7.1🔗Twig would like to thank Anvil Secure in collaboration with Claude and Anthropic Research for reporting and fixing the issue.
CVE-2026-466332026-07-14twigphpTwig8.7🔗Twig would like to thank Anvil Secure in collaboration with Claude and Anthropic Research for reporting and fixing the issue.
CVE-2026-450672026-07-14symfonysymfony6.3
CVE-2026-615052026-07-13rejettohfs6.9Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research
CVE-2026-615042026-07-13rejettohfs5.1Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research
CVE-2026-615032026-07-13rejettohfs6.9Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research
CVE-2026-615022026-07-13rejettohfs5.1Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research
CVE-2026-615012026-07-13rejettohfs5.3Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research
CVE-2026-615002026-07-13rejettohfs9.3✅Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research
CVE-2026-151702026-07-08Wireshark FoundationWireshark5.5🔗Claude and Ada Logics
CVE-2026-151692026-07-08Wireshark FoundationWireshark5.5Claude and Ada Logics
CVE-2026-151662026-07-08Wireshark FoundationWireshark5.5🔗Claude and Ada Logics
CVE-2026-151652026-07-08Wireshark FoundationWireshark5.5🔗Claude and Ada Logics
CVE-2026-463542026-07-07codercoder9.1We'd like to thank Ben Tran of calif.io and Anthropic’s Security Team (ANT-2026-22445) for independently disclosing this issue!
CVE-2026-457962026-07-07codercoder6.5We'd like to thank Ben Tran of calif.io and Anthropic's Security Team (ANT-2026-22447) for independently disclosing this issue!
CVE-2026-277752026-07-03GiteaGitea Open Source Git Server8.8adrian-doyensec
CVE-2026-415792026-07-01opencontainersrunc3.3🔗Anthropic
CVE-2026-202152026-07-01CiscoCisco Secure Endpoint7.5🔗Anthropic
CVE-2026-202142026-07-01CiscoCisco Secure Endpoint7.5🔗Anthropic
CVE-2026-202132026-07-01CiscoCisco Secure Endpoint7.5🔗Anthropic
CVE-2026-437152026-06-29AppleIOS8.8Milad Nasr and Nicholas Carlini with Claude, Anthropic
CVE-2026-135952026-06-29Red HatRed Hat Hardened Images6.8🔗Red Hat would like to thank Thai Duong (Calif.io in collaboration with Claude and Anthropic Research) for reporting this issue.
CVE-2026-532832026-06-26LinuxLinux5.5Reported-by: Ziyuan Chen zc@anthropic.com | Tested-by: Ziyuan Chen zc@anthropic.com
CVE-2026-123402026-06-25wolfSSLwolfSSL6.3🔗David Pokora, Trail of Bits (in collaboration with Anthropic)
CVE-2026-75312026-06-25wolfSSLwolfSSL2.3Thai Duong (Calif.io / Anthropic)
CVE-2026-75112026-06-25wolfSSLwolfSSL5.9Nicholas Carlini from Anthropic
CVE-2026-66812026-06-25wolfSSLwolfSSL1.0Nicholas Carlini from Anthropic
CVE-2026-66792026-06-25wolfSSLwolfSSL8.8Nicholas Carlini from Anthropic
CVE-2026-66782026-06-25wolfSSLwolfSSL1.0🔗Dikai Zou
CVE-2026-63312026-06-25wolfSSLwolfSSL2.1Nicholas Carlini from Anthropic
CVE-2026-63302026-06-25wolfSSLwolfSSL6.3Nicholas Carlini from Anthropic
CVE-2026-63292026-06-25wolfSSLwolfSSL6.0Nicholas Carlini from Anthropic
CVE-2026-463492026-06-24mastodonmastodon5.3🔗Anthropic Advisory NOT IN CVE TABLE
CVE-2026-463482026-06-24mastodonmastodon8.7🔗Anthropic Advisory NOT IN CVE TABLE
CVE-2026-561322026-06-19libexpat projectlibexpat6.9🔗Anthropic
CVE-2026-456962026-06-18AcademySoftwareFoundationopenexr8.3🔗Anthropic
CVE-2026-489292026-06-16Rocket.ChatRocket.Chat7.5🔗Anthropic
CVE-2026-83582026-06-15The Document FoundationLibreOffice5.4🔗Anthropic (automated discovery using Claude) | Arthur Chan of Ada Logics (validation and reporting)
CVE-2026-83572026-06-15The Document FoundationLibreOffice5.4🔗Anthropic (automated discovery using Claude) | Arthur Chan of Ada Logics (validation and reporting)
CVE-2026-83562026-06-15The Document FoundationLibreOffice5.4🔗Anthropic (automated discovery using Claude) | Arthur Chan of Ada Logics (validation and reporting)
CVE-2026-60472026-06-15The Document FoundationLibreOffice5.4🔗Anthropic (automated discovery using Claude) | Trail of Bits (triage and validation)
CVE-2026-60452026-06-15The Document FoundationLibreOffice5.4🔗Anthropic (automated discovery using Claude) | Trail of Bits (triage and validation)
CVE-2026-60402026-06-15The Document FoundationLibreOffice5.4🔗Anthropic (automated discovery using Claude) | Trail of Bits (triage and validation)
CVE-2026-60392026-06-15The Document FoundationLibreOffice5.4🔗Anthropic (automated discovery using Claude) | Trail of Bits (triage and validation)
CVE-2026-454472026-06-09OpenSSLOpenSSL8.8🔗Thai Duong (Calif.io in collaboration with Claude and Anthropic Research) | Igor Ustinov
CVE-2026-454462026-06-09OpenSSLOpenSSL4.8Alex Gaynor (Anthropic) | Dmitry Belyavskiy (Red Hat)
CVE-2026-454452026-06-09OpenSSLOpenSSL7.5Alex Gaynor (Anthropic) | Viktor Dukhovni
CVE-2026-427702026-06-09OpenSSLOpenSSL3.7Alex Gaynor (Anthropic) | Alex Gaynor (Anthropic) | Viktor Dukhovni | Norbert Pócs
CVE-2026-427692026-06-09OpenSSLOpenSSL5.3Alex Gaynor (Anthropic) | Alex Gaynor (Anthropic) | Bob Beck
CVE-2026-427682026-06-09OpenSSLOpenSSL3.7Alex Gaynor (Anthropic) | Dmitry Belyavskiy (Red Hat) | Alicja Kario (Red Hat)
CVE-2026-341822026-06-09OpenSSLOpenSSL9.1Asim Viladi Oglu Manizada | Alex Gaynor (Anthropic) | Ying Dong | Haiyang Huang | Neil Horman
CVE-2026-341812026-06-09OpenSSLOpenSSL7.4Pavol Žáčik (Red Hat) | Alex Gaynor (Anthropic) | Alicja Kario (Red Hat)
CVE-2026-499752026-06-08Apache Software FoundationApache HTTP Server7.5Quang Luong of Calif.IO in collaboration with OpenAI Codex
CVE-2026-473452026-06-08TYPO3HTML Sanitizer5.1🔗Doyensec in collaboration with Claude and Anthropic Research | Benjamin Franzke
CVE-2026-477322026-06-05twigtwig7.1@fabpot (remediation_developer)
CVE-2026-472502026-06-05npmmcp-server-kubernetes6.1@yotampe-pluto (reporter)
CVE-2026-84622026-06-04github.comopenmeterio/openmeter8.9🔗Anthropic
CVE-2026-474292026-06-01npmvitest9.8@sapphi-red (reporter) | @qispark (analyst) | @joevin-slq-docto (analyst) | @koteswar-k (analyst) | @SaronGrave (analyst) | @jason-anthropic (analyst)
CVE-2026-473912026-05-29pipPraisonAI9.8@foxirain (reporter)
CVE-2026-457002026-05-29FreeRDPFreeRDP7.7🔗Anthropic Advisory NOT IN CVE TABLE
CVE-2026-444212026-05-29FreeRDPFreeRDP8.8🔗Anthropic
CVE-2026-444202026-05-29FreeRDPFreeRDP8.8🔗Anthropic Advisory NOT IN CVE TABLE
CVE-2026-405282026-05-29OpenSCOpenSC1.0🔗Nicholas Carlini of Anthropic
CVE-2026-405102026-05-29OpenSCOpenSC1.0Nicholas Carlini of Anthropic
CVE-2026-488962026-05-26Joomla!Joomla! CMS8.2Doyensec in collaboration with Claude and Anthropic Research
CVE-2026-414012026-05-26libyanglibyang6.9🔗https://www.vulncheck.com/advisories/libyang-heap-use-after-free-write-in-xml-metadata-parsing
CVE-2026-403842026-05-26Joomla!Joomla! CMS5.9🔗Doyensec in collaboration with Claude and Anthropic Research
CVE-2026-403832026-05-26Joomla!Joomla! CMS7.5🔗Doyensec in collaboration with Claude and Anthropic Research
CVE-2026-400342026-05-26gitoxidegitoxide7.3https://www.vulncheck.com/advisories/gitoxide-command-injection-via-partial-gitmodules-override-in-gix-submodule
CVE-2026-400332026-05-26FreeRDPFreeRDP8.6🔗https://www.vulncheck.com/advisories/freerdp-heap-buffer-overflow-in-gdi-cachetosurface-via-rectangle-validation-bypass
CVE-2026-442122026-05-14PrestaShopPrestaShop7.8Reported by Savio at Doyensec (anthropic@doyensec.com) in collaboration with Anthropic Research.
CVE-2026-64792026-05-14PostgreSQLPostgreSQL7.5🔗The PostgreSQL project thanks Calif.io in collaboration with Claude and Anthropic Research for reporting this problem.
CVE-2026-444712026-05-13gitoxidegitoxide7.8This vulnerability was found by AI (specifically, Claude Mythos) as part of Project Glasswing. I have verified this and most of this advisory has been written by my probably-inferior human brain.
CVE-2026-404032026-05-12MicrosoftWindows8.8Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-403982026-05-12MicrosoftWindows8.0Calif.io and Milad Nasr (Anthropic) with Claude with Calif.io and Anthropic
CVE-2026-403802026-05-12MicrosoftWindows6.2Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-403692026-05-12MicrosoftWindows7.8Calif.io in collaboration with Claude and Anthropic Research Adrian Denkiewicz at Doyensec in collaboration with Anthropic Research https://doyensec.com/ Len Sadowski (lytnc) https://sec-fault.com/ and Oguz Bektas (ozb) https://ozbsec.com/
CVE-2026-74742026-05-12HashiCorpNomad8.8🔗This issue was reported to HashiCorp by Adrian Denkiewicz at Doyensec in collaboration with Claude and Anthropic Research
CVE-2026-426002026-05-11miniominio6.9Anthropic Advisory NOT IN CVE TABLE
CVE-2026-289522026-05-11AppleIphone/Ipad7.5Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-289422026-05-11AppleWebkit6.5Milad Nasr and Nicholas Carlini with Claude, Anthropic
CVE-2026-48922026-05-11dnsmasqdnsmasq8.4🔗Anthropic
CVE-2026-48902026-05-11dnsmasqdnsmasq7.5🔗Anthropic
CVE-2026-431852026-05-06LinuxLinux9.8Signed-off-by: Nicholas Carlini nicholas@carlini.com
CVE-2026-430742026-05-06LinuxLinux7.8🔗Anthropic
CVE-2026-406852026-04-30EximExim6.5🔗Anthropic
CVE-2026-315542026-04-24LinuxLinux7.8🔗Reported-by: Nicholas Carlini npc@anthropic.com
CVE-2026-419902026-04-23gnupgLibgcrypt4.0🔗Reported by Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-291982026-04-22Rocket.ChatRocket.Chat9.8🔗Anthropic
CVE-2026-63862026-04-22FreeBSDFreeBSD6.2🔗Nicholas Carlini using Claude, Anthropic
CVE-2026-53982026-04-22FreeBSDFreeBSD8.4🔗Nicholas Carlini using Claude, Anthropic
CVE-2026-67722026-04-21MozillaFirefox7.5🔗sseehra
CVE-2026-67582026-04-21MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-67572026-04-21MozillaFirefox7.5Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-67462026-04-21MozillaFirefox7.5Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-55882026-04-15Legion of the Bouncy Castle Inc.BC-JAVA6.3Nicholas Carlini using Claude, Anthropic
CVE-2026-330962026-04-14MicrosoftWindows7.5Milad Nasr (Anthropic) and Calif.io with Claude
CVE-2026-339012026-04-13ImageMagickImageMagick7.5🔗Anthropic Advisory NOT IN CVE TABLE
CVE-2026-323162026-04-13jqlangJQ7.5🔗Anthropic Advisory
CVE-2026-57191Reservedasteriskasterisk🔗Anthropic
CVE-2026-55012026-04-10wolfSSLwolfSSL8.6🔗Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-55002026-04-10wolfSSLwolfSSL8.7🔗Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-54792026-04-10wolfSSLwolfSSL7.6🔗Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-54772026-04-10wolfSSLwolfSSL8.2🔗Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-54662026-04-10wolfSSLwolfSSL7.6🔗Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-55032026-04-09wolfSSLwolfSSL6.9🔗Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-54482026-04-09wolfSSLwolfSSL2.3🔗Anthropic Advisory
CVE-2026-54472026-04-09wolfSSLwolfSSL6.3🔗Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-54462026-04-09wolfSSLwolfSSL6.0🔗Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-52952026-04-09wolfSSLwolfSSL5.9🔗Sunwoo Lee, (Korea Institute of Energy Technology, KENTECH) | Woohyun Choi, (Korea Institute of Energy Technology, KENTECH) | Seunghyun Yoon, (Korea Institute of Energy Technology, KENTECH)
CVE-2026-51942026-04-09wolfSSLwolfSSL9.3🔗Nicholas Carlini from Anthropic
CVE-2026-345802026-04-07BotanBotan7.5🔗Nicholas Carlini with Claude, Anthropic
CVE-2026-283862026-04-07OpenSSLOpenSSL9.1Stanislav Fort (Aisle Research); Pavel Kohout (Aisle Research); Alex Gaynor (Anthropic)
CVE-2026-57472026-04-07AWSFireCracker8.7🔗We thank Anthropic for reporting this concern to the AWS Vulnerability Disclosure Program.
CVE-2026-35022Reserved
CVE-2026-314022026-04-03LinuxLinux9.8Reported-by: Nicholas Carlini npc@anthropic.com
CVE-2026-51992026-04-01temporaliotemporal2.3🔗Anthropic Advisory
CVE-2026-7275Reservedmoodlemoodle🔗Anthropic
CVE-2026-68521Reservedunicorn🔗Anthropic
CVE-2026-62257Reservedhtslib🔗Anthropic
CVE-2026-337212026-03-26MapServerMapServer5.3🔗Anthropic Advisory
CVE-2026-47472026-03-26FreeBSDFreeBSD8.8🔗Nicholas Carlini using Claude, Anthropic
CVE-2026-54914Reservedbytecodealliancewasm-micro-runtime🔗Anthropic
CVE-2026-276542026-03-24F5NGINX Plus8.2🔗Calif.io in collaboration with Claude and Anthropic Research
CVE-2026-47242026-03-24MozillaFirefox9.1Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-47232026-03-24MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-47182026-03-24MozillaFirefox8.1Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-47052026-03-24MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-47042026-03-24MozillaFirefox7.5Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-47022026-03-24MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-46002026-03-23jsrsasignjsrsasign9.1reported by Koda Reef, Nicholas Carlini and @Kr0emer
CVE-2026-61627Reservedlibasslibass🔗Anthropic
CVE-2026-322672026-03-16craftcmscms7.7Anthropic Advisory
CVE-2026-282082026-02-26junrarjunrar5.9Anthropic Advisory
CVE-2026-28052026-02-24MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-28042026-02-24MozillaFirefox5.4Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27992026-02-24MozillaFirefox8.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27972026-02-24MozillaFirefox8.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27962026-02-24MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27912026-02-24MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27892026-02-24MozillaFirefox8.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27882026-02-24MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27872026-02-24MozillaFirefox8.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27862026-02-24MozillaFirefox8.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27852026-02-24MozillaFirefox8.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27752026-02-24MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27742026-02-24MozillaFirefox8.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27732026-02-24MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27722026-02-24MozillaFirefox8.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27712026-02-24MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27702026-02-24MozillaFirefox8.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27692026-02-24MozillaFirefox8.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27662026-02-24MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27652026-02-24MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27642026-02-24MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-27632026-02-24MozillaFirefox9.8Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
CVE-2026-269802026-02-19GhostGhost9.4🔗✅We thank Nicholas Carlini using Claude, Anthropic for disclosing this vulnerability responsibly.