{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/aisle-openssl-january-2026-advisory/",
 "asOf": "2026-09-26",
 "id": "aisle-openssl-january-2026-advisory",
 "date": "2026-01-27",
 "datePrecision": "day",
 "title": "All 12 CVEs in OpenSSL's January 2026 advisory credited to AISLE, which says its AI system found them",
 "lane": "defense",
 "kind": "vulnerability-disclosure",
 "summary": "OpenSSL's 27 January 2026 security advisory lists 12 CVEs, one High and one Moderate, all reported by researchers from Aisle Research, who also developed several of the fixes. AISLE states the issues were discovered by its AI system and that it accounted for 13 of 14 OpenSSL CVEs in 2025; the OpenSSL advisory itself credits the researchers but does not describe the discovery method.",
 "whyItMatters": "It is a concrete, maintainer-published record of an AI-security firm's findings dominating a critical library's security release.",
 "actors": [
  "aisle",
  "openssl"
 ],
 "topics": [
  "vulnerability-discovery"
 ],
 "atlas": [],
 "artifacts": [],
 "sources": [
  {
   "url": "https://openssl-library.org/news/secadv/20260127.txt",
   "publisher": "OpenSSL",
   "title": "OpenSSL Security Advisory [27th January 2026]",
   "date": "2026-01-27",
   "type": "primary",
   "accessed": "2026-09-25"
  },
  {
   "url": "https://www.lesswrong.com/posts/7aJwgbMEiKq5egQbd/ai-found-12-of-12-openssl-zero-days-while-curl-cancelled-its",
   "publisher": "LessWrong (Stanislav Fort, AISLE)",
   "title": "AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)",
   "date": "2026-01-27",
   "type": "secondary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "The advisory lists 12 CVEs, including CVE-2025-15467 (High, CMS AuthEnvelopedData/EnvelopedData parsing) and CVE-2025-11187 (Moderate, PKCS#12 PBMAC1 validation); every issue is credited to Aisle Research staff.",
   "locator": "OpenSSL advisory, per-issue 'reported by' lines"
  },
  {
   "fact": "CVE-2025-11187 was also reported independently by a researcher from Metadust about a month after AISLE's report; AISLE staff wrote or co-wrote the fixes for 5 of the 12 issues.",
   "locator": "OpenSSL advisory, CVE-2025-11187 entry and per-issue fix credits"
  },
  {
   "fact": "AISLE's author states that its AI system found all 12, and that AISLE accounts for 13 of the 14 CVE-2025 identifiers issued for OpenSSL.",
   "locator": "LessWrong post"
  }
 ],
 "significance": 3,
 "fideQuestions": [],
 "methods": [],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}