
Tracking Vulnerabilities That Appear to be Credited to the Anthropic Research Team
Tracking vulnerabilities that credit the Anthropic research team and are possibly discovered by Project Glasswing.
CURRENT CVE COUNT: 149
Tracking CVEs Attributed to Anthropic Researchers and Project Glasswing
If you find an Anthropic credited vulnerability, please open a Pull Request or Send me a message on linkedin or in the Extended Vulnerability Community Discord.
This project is maintained on a best effort basis.
| CVE | Date | Vendor | Product | CVSS | Credit |
|---|---|---|---|---|---|
| CVE-2026-16239 | 2026-08-13 | n/a | PostgreSQL | 8.8 | The PostgreSQL project thanks Ben Morris (Claude and Anthropic Research) for reporting this problem. |
| CVE-2026-15742 | 2026-08-13 | n/a | PostgreSQL | 8.8 | The PostgreSQL project thanks Ben Morris (Claude and Anthropic Research) for reporting this problem. |
| CVE-2026-15741 | 2026-08-13 | n/a | PostgreSQL | 8.8 | The PostgreSQL project thanks Ben Morris (Claude and Anthropic Research) for reporting this problem. |
| CVE-2026-68760 | 2026-08-12 | jfrog | artifactory | 5.3 | Ben Morris in collaboration with Claude and Anthropic Research |
| CVE-2026-18663 | 2026-08-12 | Red Hat | Red Hat Directory Server 11 | 5.9 | Red Hat would like to thank Adam Korczynski (Ada Logics), Arthur Chan (Ada Logics), David Korczynski (Ada Logics), and Team (Anthropic) for reporting this issue. |
| CVE-2026-11836 | 2026-08-04 | Caliptra | Core ROM | 1.8 | Alex Matrosov with Claude, Anthropic |
| CVE-2026-11835 | 2026-08-04 | Caliptra | Core ROM | 5.6 | Alex Matrosov with Claude, Anthropic |
| CVE-2026-59652 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 6.9 | Alex Gaynor in collaboration with Claude and Anthropic Research |
| CVE-2026-58063 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 5.3 |
| Alex Gaynor in collaboration with Claude and Anthropic Research |
| CVE-2026-58062 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 9.3 | Alex Gaynor in collaboration with Claude and Anthropic Research |
| CVE-2026-58061 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research |
| CVE-2026-58060 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research |
| CVE-2026-58059 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 8.7 | Alex Gaynor in collaboration with Claude and Anthropic Research |
| CVE-2026-8763 | 2026-08-03 | Legion of the Bouncy Castle Inc. | BC-JAVA | 9.3 | Alex Gaynor in collaboration with Claude and Anthropic Research |
| CVE-2026-61487 | 2026-07-28 | Apache Software Foundation | Apache ActiveMQ Broker | 6.5 | Claude and Ada Logics |
| CVE-2026-64015 | 2026-07-19 | Linux | Linux | 7.8 |
| CVE-2026-46639 | 2026-07-14 | twigphp | Twig | 7.1 | Twig would like to thank Anvil Secure in collaboration with Claude and Anthropic Research for reporting and fixing the issue. |
| CVE-2026-46633 | 2026-07-14 | twigphp | Twig | 8.7 | Twig would like to thank Anvil Secure in collaboration with Claude and Anthropic Research for reporting and fixing the issue. |
| CVE-2026-45067 | 2026-07-14 | symfony | symfony | 6.3 |
| CVE-2026-61505 | 2026-07-13 | rejetto | hfs | 6.9 | Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research |
| CVE-2026-61504 | 2026-07-13 | rejetto | hfs | 5.1 | Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research |
| CVE-2026-61503 | 2026-07-13 | rejetto | hfs | 6.9 | Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research |
| CVE-2026-61502 | 2026-07-13 | rejetto | hfs | 5.1 | Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research |
| CVE-2026-61501 | 2026-07-13 | rejetto | hfs | 5.3 | Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research |
| CVE-2026-61500 | 2026-07-13 | rejetto | hfs | 9.3 | Zach Hanley (@hacks_zach) of Horizon3.ai, in collaboration with Claude and Anthropic Research |
| CVE-2026-15170 | 2026-07-08 | Wireshark Foundation | Wireshark | 5.5 | Claude and Ada Logics |
| CVE-2026-15169 | 2026-07-08 | Wireshark Foundation | Wireshark | 5.5 | Claude and Ada Logics |
| CVE-2026-15166 | 2026-07-08 | Wireshark Foundation | Wireshark | 5.5 | Claude and Ada Logics |
| CVE-2026-15165 | 2026-07-08 | Wireshark Foundation | Wireshark | 5.5 | Claude and Ada Logics |
| CVE-2026-46354 | 2026-07-07 | coder | coder | 9.1 | We'd like to thank Ben Tran of calif.io and Anthropic’s Security Team (ANT-2026-22445) for independently disclosing this issue! |
| CVE-2026-45796 | 2026-07-07 | coder | coder | 6.5 | We'd like to thank Ben Tran of calif.io and Anthropic's Security Team (ANT-2026-22447) for independently disclosing this issue! |
| CVE-2026-27775 | 2026-07-03 | Gitea | Gitea Open Source Git Server | 8.8 | adrian-doyensec |
| CVE-2026-43715 | 2026-06-29 | Apple | IOS | 8.8 | Milad Nasr and Nicholas Carlini with Claude, Anthropic |
| CVE-2026-12340 | 2026-06-25 | wolfSSL | wolfSSL | 6.3 | David Pokora, Trail of Bits (in collaboration with Anthropic) |
| CVE-2026-7531 | 2026-06-25 | wolfSSL | wolfSSL | 2.3 | Thai Duong (Calif.io / Anthropic) |
| CVE-2026-7511 | 2026-06-25 | wolfSSL | wolfSSL | 5.9 | Nicholas Carlini from Anthropic |
| CVE-2026-6681 | 2026-06-25 | wolfSSL | wolfSSL | 1.0 | Nicholas Carlini from Anthropic |
| CVE-2026-6679 | 2026-06-25 | wolfSSL | wolfSSL | 8.8 | Nicholas Carlini from Anthropic |
| CVE-2026-6331 | 2026-06-25 | wolfSSL | wolfSSL | 2.1 | Nicholas Carlini from Anthropic |
| CVE-2026-6330 | 2026-06-25 | wolfSSL | wolfSSL | 6.3 | Nicholas Carlini from Anthropic |
| CVE-2026-6329 | 2026-06-25 | wolfSSL | wolfSSL | 6.0 | Nicholas Carlini from Anthropic |
| CVE-2026-46349 | 2026-06-24 | mastodon | mastodon | 5.3 | Anthropic Advisory NOT IN CVE TABLE |
| CVE-2026-46348 | 2026-06-24 | mastodon | mastodon | 8.7 | Anthropic Advisory NOT IN CVE TABLE |
| CVE-2026-8358 | 2026-06-15 | The Document Foundation | LibreOffice | 5.4 | Anthropic (automated discovery using Claude) | Arthur Chan of Ada Logics (validation and reporting) |
| CVE-2026-8357 | 2026-06-15 | The Document Foundation | LibreOffice | 5.4 | Anthropic (automated discovery using Claude) | Arthur Chan of Ada Logics (validation and reporting) |
| CVE-2026-8356 | 2026-06-15 | The Document Foundation | LibreOffice | 5.4 | Anthropic (automated discovery using Claude) | Arthur Chan of Ada Logics (validation and reporting) |
| CVE-2026-6047 | 2026-06-15 | The Document Foundation | LibreOffice | 5.4 | Anthropic (automated discovery using Claude) | Trail of Bits (triage and validation) |
| CVE-2026-6045 | 2026-06-15 | The Document Foundation | LibreOffice | 5.4 | Anthropic (automated discovery using Claude) | Trail of Bits (triage and validation) |
| CVE-2026-6040 | 2026-06-15 | The Document Foundation | LibreOffice | 5.4 | Anthropic (automated discovery using Claude) | Trail of Bits (triage and validation) |
| CVE-2026-6039 | 2026-06-15 | The Document Foundation | LibreOffice | 5.4 | Anthropic (automated discovery using Claude) | Trail of Bits (triage and validation) |
| CVE-2026-45447 | 2026-06-09 | OpenSSL | OpenSSL | 8.8 | Thai Duong (Calif.io in collaboration with Claude and Anthropic Research) | Igor Ustinov |
| CVE-2026-45446 | 2026-06-09 | OpenSSL | OpenSSL | 4.8 | Alex Gaynor (Anthropic) | Dmitry Belyavskiy (Red Hat) |
| CVE-2026-45445 | 2026-06-09 | OpenSSL | OpenSSL | 7.5 | Alex Gaynor (Anthropic) | Viktor Dukhovni |
| CVE-2026-42770 | 2026-06-09 | OpenSSL | OpenSSL | 3.7 | Alex Gaynor (Anthropic) | Alex Gaynor (Anthropic) | Viktor Dukhovni | Norbert Pócs |
| CVE-2026-42769 | 2026-06-09 | OpenSSL | OpenSSL | 5.3 | Alex Gaynor (Anthropic) | Alex Gaynor (Anthropic) | Bob Beck |
| CVE-2026-42768 | 2026-06-09 | OpenSSL | OpenSSL | 3.7 | Alex Gaynor (Anthropic) | Dmitry Belyavskiy (Red Hat) | Alicja Kario (Red Hat) |
| CVE-2026-34182 | 2026-06-09 | OpenSSL | OpenSSL | 9.1 | Asim Viladi Oglu Manizada | Alex Gaynor (Anthropic) | Ying Dong | Haiyang Huang | Neil Horman |
| CVE-2026-34181 | 2026-06-09 | OpenSSL | OpenSSL | 7.4 | Pavol Žáčik (Red Hat) | Alex Gaynor (Anthropic) | Alicja Kario (Red Hat) |
| CVE-2026-49975 | 2026-06-08 | Apache Software Foundation | Apache HTTP Server | 7.5 | Quang Luong of Calif.IO in collaboration with OpenAI Codex |
| CVE-2026-47345 | 2026-06-08 | TYPO3 | HTML Sanitizer | 5.1 | Doyensec in collaboration with Claude and Anthropic Research | Benjamin Franzke |
| CVE-2026-47732 | 2026-06-05 | twig | twig | 7.1 | @fabpot (remediation_developer) |
| CVE-2026-47250 | 2026-06-05 | npm | mcp-server-kubernetes | 6.1 | @yotampe-pluto (reporter) |
| CVE-2026-8462 | 2026-06-04 | github.com | openmeterio/openmeter |
| CVE-2026-47429 | 2026-06-01 | npm | vitest | 9.8 | @sapphi-red (reporter) | @qispark (analyst) | @joevin-slq-docto (analyst) | @koteswar-k (analyst) | @SaronGrave (analyst) | @jason-anthropic (analyst) |
| CVE-2026-47391 | 2026-05-29 | pip | PraisonAI | 9.8 | @foxirain (reporter) |
| CVE-2026-45700 | 2026-05-29 | FreeRDP | FreeRDP | 7.7 | Anthropic Advisory NOT IN CVE TABLE |
| CVE-2026-44420 | 2026-05-29 | FreeRDP | FreeRDP | 8.8 | Anthropic Advisory NOT IN CVE TABLE |
| CVE-2026-40528 | 2026-05-29 | OpenSC | OpenSC | 1.0 | Nicholas Carlini of Anthropic |
| CVE-2026-40510 | 2026-05-29 | OpenSC | OpenSC | 1.0 | Nicholas Carlini of Anthropic |
| CVE-2026-48896 | 2026-05-26 | Joomla! | Joomla! CMS | 8.2 | Doyensec in collaboration with Claude and Anthropic Research |
| CVE-2026-41401 | 2026-05-26 | libyang | libyang | 6.9 | https://www.vulncheck.com/advisories/libyang-heap-use-after-free-write-in-xml-metadata-parsing |
| CVE-2026-40384 | 2026-05-26 | Joomla! | Joomla! CMS | 5.9 | Doyensec in collaboration with Claude and Anthropic Research |
| CVE-2026-40383 | 2026-05-26 | Joomla! | Joomla! CMS | 7.5 | Doyensec in collaboration with Claude and Anthropic Research |
| CVE-2026-40034 | 2026-05-26 | gitoxide | gitoxide | 7.3 | https://www.vulncheck.com/advisories/gitoxide-command-injection-via-partial-gitmodules-override-in-gix-submodule |
| CVE-2026-40033 | 2026-05-26 | FreeRDP | FreeRDP | 8.6 | https://www.vulncheck.com/advisories/freerdp-heap-buffer-overflow-in-gdi-cachetosurface-via-rectangle-validation-bypass |
| CVE-2026-44212 | 2026-05-14 | PrestaShop | PrestaShop | 7.8 | Reported by Savio at Doyensec ([email protected]) in collaboration with Anthropic Research. |
| CVE-2026-6479 | 2026-05-14 | PostgreSQL | PostgreSQL | 7.5 | The PostgreSQL project thanks Calif.io in collaboration with Claude and Anthropic Research for reporting this problem. |
| CVE-2026-44471 | 2026-05-13 | gitoxide | gitoxide | 7.8 | This vulnerability was found by AI (specifically, Claude Mythos) as part of Project Glasswing. I have verified this and most of this advisory has been written by my probably-inferior human brain. |
| CVE-2026-40403 | 2026-05-12 | Microsoft | Windows | 8.8 | Calif.io in collaboration with Claude and Anthropic Research |
| CVE-2026-40398 | 2026-05-12 | Microsoft | Windows | 8.0 | Calif.io and Milad Nasr (Anthropic) with Claude with Calif.io and Anthropic |
| CVE-2026-40380 | 2026-05-12 | Microsoft | Windows | 6.2 | Calif.io in collaboration with Claude and Anthropic Research |
| CVE-2026-40369 | 2026-05-12 | Microsoft | Windows | 7.8 | Calif.io in collaboration with Claude and Anthropic Research Adrian Denkiewicz at Doyensec in collaboration with Anthropic Research https://doyensec.com/ Len Sadowski (lytnc) https://sec-fault.com/ and Oguz Bektas (ozb) https://ozbsec.com/ |
| CVE-2026-7474 | 2026-05-12 | HashiCorp | Nomad | 8.8 | This issue was reported to HashiCorp by Adrian Denkiewicz at Doyensec in collaboration with Claude and Anthropic Research |
| CVE-2026-42600 | 2026-05-11 | minio | minio | 6.9 | Anthropic Advisory NOT IN CVE TABLE |
| CVE-2026-28952 | 2026-05-11 | Apple | Iphone/Ipad | 7.5 | Calif.io in collaboration with Claude and Anthropic Research |
| CVE-2026-28942 | 2026-05-11 | Apple | Webkit | 6.5 | Milad Nasr and Nicholas Carlini with Claude, Anthropic |
| CVE-2026-43185 | 2026-05-06 | Linux | Linux | 9.8 | Signed-off-by: Nicholas Carlini [email protected] |
| CVE-2026-31554 | 2026-04-24 | Linux | Linux | 7.8 | Reported-by: Nicholas Carlini [email protected] |
| CVE-2026-41990 | 2026-04-23 | gnupg | Libgcrypt | 4.0 | Reported by Calif.io in collaboration with Claude and Anthropic Research |
| CVE-2026-6386 | 2026-04-22 | FreeBSD | FreeBSD | 6.2 | Nicholas Carlini using Claude, Anthropic |
| CVE-2026-5398 | 2026-04-22 | FreeBSD | FreeBSD | 8.4 | Nicholas Carlini using Claude, Anthropic |
| CVE-2026-6758 | 2026-04-21 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-6757 | 2026-04-21 | Mozilla | Firefox | 7.5 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-6746 | 2026-04-21 | Mozilla | Firefox | 7.5 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-5588 | 2026-04-15 | Legion of the Bouncy Castle Inc. | BC-JAVA | 6.3 | Nicholas Carlini using Claude, Anthropic |
| CVE-2026-33096 | 2026-04-14 | Microsoft | Windows | 7.5 | Milad Nasr (Anthropic) and Calif.io with Claude |
| CVE-2026-33901 | 2026-04-13 | ImageMagick | ImageMagick | 7.5 | Anthropic Advisory NOT IN CVE TABLE |
| CVE-2026-32316 | 2026-04-13 | jqlang | JQ | 7.5 | Anthropic Advisory |
| CVE-2026-5501 | 2026-04-10 | wolfSSL | wolfSSL | 8.6 | Calif.io in collaboration with Claude and Anthropic Research |
| CVE-2026-5500 | 2026-04-10 | wolfSSL | wolfSSL | 8.7 | Calif.io in collaboration with Claude and Anthropic Research |
| CVE-2026-5479 | 2026-04-10 | wolfSSL | wolfSSL | 7.6 | Calif.io in collaboration with Claude and Anthropic Research |
| CVE-2026-5477 | 2026-04-10 | wolfSSL | wolfSSL | 8.2 | Calif.io in collaboration with Claude and Anthropic Research |
| CVE-2026-5466 | 2026-04-10 | wolfSSL | wolfSSL | 7.6 | Calif.io in collaboration with Claude and Anthropic Research |
| CVE-2026-5503 | 2026-04-09 | wolfSSL | wolfSSL | 6.9 | Calif.io in collaboration with Claude and Anthropic Research |
| CVE-2026-5448 | 2026-04-09 | wolfSSL | wolfSSL | 2.3 | Anthropic Advisory |
| CVE-2026-5447 | 2026-04-09 | wolfSSL | wolfSSL | 6.3 | Calif.io in collaboration with Claude and Anthropic Research |
| CVE-2026-5446 | 2026-04-09 | wolfSSL | wolfSSL | 6.0 | Calif.io in collaboration with Claude and Anthropic Research |
| CVE-2026-5194 | 2026-04-09 | wolfSSL | wolfSSL | 9.3 | Nicholas Carlini from Anthropic |
| CVE-2026-34580 | 2026-04-07 | Botan | Botan | 7.5 | Nicholas Carlini with Claude, Anthropic |
| CVE-2026-28386 | 2026-04-07 | OpenSSL | OpenSSL | 9.1 | Stanislav Fort (Aisle Research); Pavel Kohout (Aisle Research); Alex Gaynor (Anthropic) |
| CVE-2026-5747 | 2026-04-07 | AWS | FireCracker | 8.7 | We thank Anthropic for reporting this concern to the AWS Vulnerability Disclosure Program. |
| CVE-2026-35022 | Reserved |
| CVE-2026-31402 | 2026-04-03 | Linux | Linux | 9.8 | Reported-by: Nicholas Carlini [email protected] |
| CVE-2026-5199 | 2026-04-01 | temporalio | temporal | 2.3 | Anthropic Advisory |
| CVE-2026-33721 | 2026-03-26 | MapServer | MapServer | 5.3 | Anthropic Advisory |
| CVE-2026-4747 | 2026-03-26 | FreeBSD | FreeBSD | 8.8 | Nicholas Carlini using Claude, Anthropic |
| CVE-2026-27654 | 2026-03-24 | F5 | NGINX Plus | 8.2 | Calif.io in collaboration with Claude and Anthropic Research |
| CVE-2026-4724 | 2026-03-24 | Mozilla | Firefox | 9.1 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-4723 | 2026-03-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-4718 | 2026-03-24 | Mozilla | Firefox | 8.1 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-4705 | 2026-03-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-4704 | 2026-03-24 | Mozilla | Firefox | 7.5 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-4702 | 2026-03-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-4600 | 2026-03-23 | jsrsasign | jsrsasign | 9.1 | reported by Koda Reef, Nicholas Carlini and @Kr0emer |
| CVE-2026-32267 | 2026-03-16 | craftcms | cms | 7.7 | Anthropic Advisory |
| CVE-2026-28208 | 2026-02-26 | junrar | junrar | 5.9 | Anthropic Advisory |
| CVE-2026-2805 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-2804 | 2026-02-24 | Mozilla | Firefox | 5.4 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-2799 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-2797 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-2796 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-2791 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-2789 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-2788 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-2787 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-2786 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-2785 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-2775 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-2774 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-2773 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-2772 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-2771 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-2770 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-2769 | 2026-02-24 | Mozilla | Firefox | 8.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-2766 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-2765 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-2764 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-2763 | 2026-02-24 | Mozilla | Firefox | 9.8 | Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic |
| CVE-2026-26980 | 2026-02-19 | Ghost | Ghost | 9.4 | We thank Nicholas Carlini using Claude, Anthropic for disclosing this vulnerability responsibly. |