OpenSSL's 27 January 2026 security advisory lists 12 CVEs, one High and one Moderate, all reported by researchers from Aisle Research, who also developed several of the fixes. AISLE states the issues were discovered by its AI system and that it accounted for 13 of 14 OpenSSL CVEs in 2025; the OpenSSL advisory itself credits the researchers but does not describe the discovery method.
Why it matters
It is a concrete, maintainer-published record of an AI-security firm's findings dominating a critical library's security release.
Key facts
As stated in the sources, with where to find them.
- The advisory lists 12 CVEs, including CVE-2025-15467 (High, CMS AuthEnvelopedData/EnvelopedData parsing) and CVE-2025-11187 (Moderate, PKCS#12 PBMAC1 validation); every issue is credited to Aisle Research staff.OpenSSL advisory, per-issue 'reported by' lines
- CVE-2025-11187 was also reported independently by a researcher from Metadust about a month after AISLE's report; AISLE staff wrote or co-wrote the fixes for 5 of the 12 issues.OpenSSL advisory, CVE-2025-11187 entry and per-issue fix credits
- AISLE's author states that its AI system found all 12, and that AISLE accounts for 13 of the 14 CVE-2025 identifiers issued for OpenSSL.LessWrong post
Findings that cite this record
Key questions this bears on
- Is AI shifting the balance between finding and fixing vulnerabilities?Discovery is ahead. AI finds real vulnerabilities faster than they are fixed, and simple checks overstate how often AI patches work.