{
  "version": "2026.09.08.670",
  "generated_at": "2026-09-24T12:24:23.823Z",
  "stats": {
    "total_entities": 656,
    "total_relationships": 670,
    "total_sources": 21,
    "total_evidence": 383,
    "total_claims": 3,
    "evidence_backed_percentage": 100,
    "high_confidence_percentage": 100,
    "contested_count": 0
  },
  "nodes": [
    {
      "id": "ACTOR-VOID-ARACHNE",
      "name": "Void Arachne",
      "type": "threat_actor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "threat-actor",
        "ai-cluster",
        "uncategorized"
      ],
      "x": 1668.9,
      "y": 1155.3
    },
    {
      "id": "THREAT-AKIRA",
      "name": "Akira Ransomware Syndicate",
      "type": "threat_actor",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/threat-intel/akira-ransomware/",
      "tags": [
        "ransomware",
        "raas",
        "conti-lineage",
        "esxi",
        "veeam-targeting"
      ],
      "x": 1165.2,
      "y": 1800.8
    },
    {
      "id": "ACTOR-FIN7",
      "name": "FIN7",
      "type": "threat_actor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "financially-motivated",
        "apt",
        "credential-theft",
        "veeam-targeting"
      ],
      "x": 1112.8,
      "y": 1650.8
    },
    {
      "id": "AAP-001",
      "name": "AAP-001: Direct System Prompt Override",
      "type": "agentic_attack_pattern",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/agentic-attack-patterns/aap-001-direct-system-prompt-override/",
      "tags": [
        "perception-layer",
        "prompt-injection",
        "jailbreak"
      ],
      "x": 1791.6,
      "y": 964.5
    },
    {
      "id": "AAP-002",
      "name": "AAP-002: Indirect Context Injection",
      "type": "agentic_attack_pattern",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/agentic-attack-patterns/aap-002-indirect-context-injection/",
      "tags": [
        "perception-layer",
        "indirect-prompt-injection",
        "context-hijacking"
      ],
      "x": 1775.2,
      "y": 875.1
    },
    {
      "id": "AAP-003",
      "name": "AAP-003: Tool Parameter Tampering & Built-in Bypass",
      "type": "agentic_attack_pattern",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/agentic-attack-patterns/aap-003-tool-parameter-tampering/",
      "tags": [
        "action-layer",
        "kinetic-execution",
        "mcp-injection",
        "tool-call"
      ],
      "x": 1709.4,
      "y": 946.9
    },
    {
      "id": "AAP-004",
      "name": "AAP-004: Semantic Tool Poisoning",
      "type": "agentic_attack_pattern",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/agentic-attack-patterns/aap-004-semantic-tool-poisoning/",
      "tags": [
        "brain-layer",
        "mcp-poisoning",
        "supply-chain"
      ],
      "x": 1647,
      "y": 1363.4
    },
    {
      "id": "AAP-005",
      "name": "AAP-005: Memory & Vector DB Knowledge Corruption",
      "type": "agentic_attack_pattern",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/agentic-attack-patterns/aap-005-memory-rag-poisoning/",
      "tags": [
        "brain-layer",
        "rag-poisoning",
        "vector-db"
      ],
      "x": 1513.8,
      "y": 1139.1
    },
    {
      "id": "AAP-006",
      "name": "AAP-006: Inter-Agent Semantic Message Spoofing",
      "type": "agentic_attack_pattern",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/agentic-attack-patterns/aap-006-inter-agent-semantic-spoofing/",
      "tags": [
        "interaction-layer",
        "multi-agent",
        "swarm-security"
      ],
      "x": 1589,
      "y": 849.6
    },
    {
      "id": "AAP-007",
      "name": "AAP-007: Autonomous Cascading RCE",
      "type": "agentic_attack_pattern",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/agentic-attack-patterns/aap-007-autonomous-cascading-rce/",
      "tags": [
        "action-layer",
        "rce",
        "cascading-loop"
      ],
      "x": 1682.4,
      "y": 870.8
    },
    {
      "id": "CAMP-MCP-RECON-2026",
      "name": "Operation MCP Harvester 2026",
      "type": "campaign",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "campaign",
        "reconnaissance",
        "mcp-targeting"
      ],
      "x": 1455,
      "y": 1496.3
    },
    {
      "id": "CAMP-MIKROTRICK-2026",
      "name": "Operation MikroTrick 2026",
      "type": "campaign",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "campaign",
        "mikrotik",
        "cisa-kev",
        "routeros",
        "botnet-recruitment",
        "perimeter-hijack"
      ],
      "x": 1137.7,
      "y": 1726
    },
    {
      "id": "CAMP-PAPERCUT-AI-2026",
      "name": "Agents Gone Wild: AI-Orchestrated Global Campaign Against PaperCut NG/MF",
      "type": "campaign",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/threat-intel/ai-orchestrated-papercut-campaign/",
      "tags": [
        "campaign",
        "agentic-ai",
        "autonomous-agents",
        "papercut",
        "active-directory",
        "cisa-kev",
        "rce"
      ],
      "x": 1427.8,
      "y": 999.2
    },
    {
      "id": "DET-SIGMA-042",
      "name": "Sigma: LiteLLM MCP Unauthenticated Session Spawn",
      "type": "detection",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "sigma",
        "mcp-detection",
        "network-rule"
      ],
      "x": 2080.1,
      "y": 1195.5
    },
    {
      "id": "DET-SIGMA-CURSOR",
      "name": "Sigma: IDE Process Modifying BASH_ENV",
      "type": "detection",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "sigma",
        "process-monitoring",
        "linux"
      ],
      "x": 1955.7,
      "y": 1374
    },
    {
      "id": "DET-YARA-THEIA",
      "name": "YARA: Malicious Theia Prompt Template Exfiltration",
      "type": "detection",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "yara",
        "file-scanner",
        "ide-security"
      ],
      "x": 2177.6,
      "y": 1080.3
    },
    {
      "id": "EXP-2026-59822-POC",
      "name": "LiteLLM Streamable MCP Token Forger",
      "type": "exploit",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "exploit-poc",
        "python",
        "weaponized"
      ],
      "x": 1851.9,
      "y": 912.5
    },
    {
      "id": "EXP-2026-22708-POC",
      "name": "Cursor Shell Builtin Auto-Run PoC",
      "type": "exploit",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "exploit-poc",
        "shell",
        "cursor"
      ],
      "x": 1374.2,
      "y": -16.8
    },
    {
      "id": "ART-BASH-ENV",
      "name": "BASH_ENV / Environment Variable Injection",
      "type": "forensic_artifact",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "forensics",
        "linux",
        "environment-variables"
      ],
      "x": 2099,
      "y": 1094.7
    },
    {
      "id": "ART-MCP-AUTH-HEADER",
      "name": "Forged MCP Authorization Header Log",
      "type": "forensic_artifact",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "forensics",
        "network",
        "mcp-telemetry"
      ],
      "x": 2056.7,
      "y": 1270.7
    },
    {
      "id": "ART-THEIA-PROMPT",
      "name": "Untrusted Workspace .prompts File",
      "type": "forensic_artifact",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "forensics",
        "filesystem",
        "ide-workspace"
      ],
      "x": 2200.4,
      "y": 983.7
    },
    {
      "id": "MAL-SHADOWAGENT",
      "name": "ShadowAgent Stealer",
      "type": "malware",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "stealer",
        "ai-targeting",
        "python"
      ],
      "x": 1504.8,
      "y": 1425.8
    },
    {
      "id": "PROD-LITELLM",
      "name": "LiteLLM Proxy & MCP Server",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "llm-gateway",
        "mcp-server",
        "enterprise-ai"
      ],
      "x": 1817.5,
      "y": 793.5
    },
    {
      "id": "PROD-LANGGRAPH",
      "name": "LangChain & LangGraph Framework",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "agent-orchestration",
        "multi-agent",
        "graph-execution"
      ],
      "x": 1933.3,
      "y": 924.8
    },
    {
      "id": "PROD-CURSOR",
      "name": "Cursor AI Code Editor",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "ide",
        "ai-editor",
        "developer-tools"
      ],
      "x": 1596.3,
      "y": 1290.3
    },
    {
      "id": "PROD-THEIA",
      "name": "Eclipse Theia IDE Platform",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "ide",
        "cloud-ide",
        "developer-tools"
      ],
      "x": 1895.8,
      "y": 1078
    },
    {
      "id": "PROD-LANGFLOW",
      "name": "Langflow AI Workflow Orchestrator",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "agent-orchestration",
        "multi-agent",
        "visual-workflow"
      ],
      "x": 1425.1,
      "y": 861.3
    },
    {
      "id": "PROD-IOS-SIMULATOR-MCP",
      "name": "iOS Simulator MCP Server",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "mcp-server",
        "tool-interface",
        "ios-simulator"
      ],
      "x": 1188,
      "y": 998.9
    },
    {
      "id": "PROD-M365-COPILOT",
      "name": "Microsoft 365 Copilot",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "enterprise-ai",
        "office-ai",
        "rag-assistant"
      ],
      "x": 1432.8,
      "y": 1278.7
    },
    {
      "id": "PROD-GITHUB-COPILOT",
      "name": "GitHub Copilot for VS Code",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "ai-assistant",
        "developer-tools",
        "coding-agent"
      ],
      "x": 1686.2,
      "y": 1082.1
    },
    {
      "id": "PROD-LOBE-CHAT",
      "name": "Lobe Chat",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "chat-framework",
        "open-source-ai",
        "agent-ui"
      ],
      "x": 1872.4,
      "y": 992.2
    },
    {
      "id": "PROD-EMAILGPT",
      "name": "EmailGPT Service & Extension",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "email-ai",
        "browser-extension",
        "productivity-ai"
      ],
      "x": 1194.7,
      "y": 867.5
    },
    {
      "id": "TOOL-VEEAM",
      "name": "Veeam Backup & Replication",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/forensics/veeam/veeam-architecture-threat-landscape/",
      "tags": [
        "backup-infrastructure",
        "disaster-recovery",
        "enterprise-storage",
        "immutability"
      ],
      "x": 1891.2,
      "y": 27.5
    },
    {
      "id": "PROD-MIKROTIK-ROUTEROS",
      "name": "MikroTik RouterOS",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/software-intelligence/products/mikrotik-routeros/",
      "tags": [
        "network-os",
        "edge-router",
        "networking",
        "firewall"
      ],
      "x": 824.5,
      "y": 1099.4
    },
    {
      "id": "PROD-PALOALTO-PANOS",
      "name": "Palo Alto Networks PAN-OS",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/software-intelligence/products/palo-alto-pan-os/",
      "tags": [
        "firewall",
        "perimeter",
        "vpn-gateway",
        "enterprise-network"
      ],
      "x": 606.6,
      "y": 18.5
    },
    {
      "id": "PROD-CHECKPOINT-GAIA",
      "name": "Check Point Quantum Security Gateway (Gaia OS)",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/software-intelligence/products/checkpoint-gaia/",
      "tags": [
        "firewall",
        "perimeter",
        "ipsec-vpn",
        "security-gateway"
      ],
      "x": 1468.1,
      "y": 409.9
    },
    {
      "id": "PROD-F5-BIGIP",
      "name": "F5 BIG-IP TMOS",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/software-intelligence/products/f5-big-ip/",
      "tags": [
        "adc",
        "load-balancer",
        "ssl-vpn",
        "traffic-management"
      ],
      "x": 1143.7,
      "y": 1518.6
    },
    {
      "id": "PROD-SONICWALL-SONICOS",
      "name": "SonicWall SonicOS",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/software-intelligence/products/sonicwall-sonicos/",
      "tags": [
        "firewall",
        "perimeter",
        "ssl-vpn",
        "enterprise-security"
      ],
      "x": 1122.9,
      "y": -63.8
    },
    {
      "id": "PROD-KUBERNETES",
      "name": "Kubernetes",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/software-intelligence/products/kubernetes/",
      "tags": [
        "orchestration",
        "cloud-native",
        "containers",
        "devops"
      ],
      "x": 1048.3,
      "y": 506.4
    },
    {
      "id": "PROD-DOCKER",
      "name": "Docker Engine",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/software-intelligence/products/docker-engine/",
      "tags": [
        "container-runtime",
        "containers",
        "virtualization",
        "devops"
      ],
      "x": 1059.1,
      "y": 1060.9
    },
    {
      "id": "PROD-POSTGRESQL",
      "name": "PostgreSQL",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/software-intelligence/products/postgresql/",
      "tags": [
        "database",
        "sql",
        "rdbms",
        "data-store"
      ],
      "x": 1387.9,
      "y": 1348.4
    },
    {
      "id": "PROD-REDIS",
      "name": "Redis",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/software-intelligence/products/redis/",
      "tags": [
        "database",
        "in-memory",
        "cache",
        "key-value"
      ],
      "x": 1741.3,
      "y": 1611.3
    },
    {
      "id": "PROD-GITLAB",
      "name": "GitLab CE / EE",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/software-intelligence/products/gitlab/",
      "tags": [
        "devops",
        "ci-cd",
        "source-control",
        "devsecops"
      ],
      "x": 1553.2,
      "y": 408.5
    },
    {
      "id": "PROD-GRAFANA",
      "name": "Grafana",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/software-intelligence/products/grafana/",
      "tags": [
        "observability",
        "metrics",
        "visualization",
        "monitoring"
      ],
      "x": 1537.9,
      "y": 1503.5
    },
    {
      "id": "PROD-HASHICORP-VAULT",
      "name": "HashiCorp Vault",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/software-intelligence/products/hashicorp-vault/",
      "tags": [
        "secrets-management",
        "encryption",
        "security",
        "zero-trust"
      ],
      "x": 1467.8,
      "y": 928.6
    },
    {
      "id": "PROD-ELASTICSEARCH",
      "name": "Elasticsearch",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/software-intelligence/products/elasticsearch/",
      "tags": [
        "search-engine",
        "siem",
        "log-analytics",
        "observability"
      ],
      "x": 1828.3,
      "y": 1464.8
    },
    {
      "id": "PROD-APACHE-KAFKA",
      "name": "Apache Kafka",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/software-intelligence/products/apache-kafka/",
      "tags": [
        "event-streaming",
        "messaging",
        "distributed-systems",
        "big-data"
      ],
      "x": 1371.1,
      "y": 1496.6
    },
    {
      "id": "PROD-RABBITMQ",
      "name": "RabbitMQ",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/software-intelligence/products/rabbitmq/",
      "tags": [
        "message-broker",
        "amqp",
        "microservices",
        "streaming"
      ],
      "x": 1240,
      "y": 1760.9
    },
    {
      "id": "PROD-SOLARWINDS-ORION",
      "name": "SolarWinds Orion Platform",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/software-intelligence/products/solarwinds-orion/",
      "tags": [
        "monitoring",
        "network-management",
        "observability",
        "enterprise-it"
      ],
      "x": 1232.5,
      "y": 1200.1
    },
    {
      "id": "PROD-ATLASSIAN-CONFLUENCE",
      "name": "Atlassian Confluence",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/software-intelligence/products/atlassian-confluence/",
      "tags": [
        "collaboration",
        "wiki",
        "enterprise-workspace",
        "atlassian"
      ],
      "x": 941.3,
      "y": 1404.7
    },
    {
      "id": "PROD-ATLASSIAN-JIRA",
      "name": "Atlassian Jira Software",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/software-intelligence/products/atlassian-jira/",
      "tags": [
        "issue-tracking",
        "project-management",
        "agile",
        "atlassian"
      ],
      "x": 1386.9,
      "y": 1703.3
    },
    {
      "id": "PROD-PAPERCUT-NG-MF",
      "name": "PaperCut NG / MF Print Management",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/software-intelligence/products/papercut-papercut_ng_mf/",
      "tags": [
        "print-management",
        "active-directory",
        "cisa-kev",
        "enterprise"
      ],
      "x": 1514,
      "y": 486.2
    },
    {
      "id": "PROD-ANYTHINGLLM",
      "name": "AnythingLLM Desktop & Workspace",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/software-intelligence/products/mintplex-labs-anythingllm/",
      "tags": [
        "ai-workspace",
        "rag",
        "agentic-ai",
        "electron"
      ],
      "x": 972.9,
      "y": 1069.8
    },
    {
      "id": "T1059",
      "name": "T1059: Command and Scripting Interpreter",
      "type": "attack_technique",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "execution",
        "mitre-attack"
      ],
      "x": 1166.1,
      "y": 793.9
    },
    {
      "id": "T1566",
      "name": "T1566: Phishing / Untrusted Content Ingestion",
      "type": "attack_technique",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "initial-access",
        "mitre-attack"
      ],
      "x": 1946.6,
      "y": 1149.9
    },
    {
      "id": "T1552",
      "name": "T1552: Unsecured Credentials",
      "type": "attack_technique",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "credential-access",
        "mitre-attack"
      ],
      "x": 1231.8,
      "y": 934.4
    },
    {
      "id": "T1574",
      "name": "T1574: Hijack Execution Flow",
      "type": "attack_technique",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "persistence",
        "privilege-escalation",
        "mitre-attack"
      ],
      "x": 2084.9,
      "y": 949.6
    },
    {
      "id": "AML.T0051",
      "name": "AML.T0051: LLM Prompt Injection",
      "type": "attack_technique",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/threat-intel/mitre-atlas-adversarial-ai-threat-matrix/",
      "tags": [
        "initial-access",
        "execution",
        "mitre-atlas"
      ],
      "x": 2295.7,
      "y": 737.8
    },
    {
      "id": "AML.T0053",
      "name": "AML.T0053: LLM Plugin and Tool Compromise",
      "type": "attack_technique",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/threat-intel/mitre-atlas-adversarial-ai-threat-matrix/",
      "tags": [
        "execution",
        "mitre-atlas",
        "mcp"
      ],
      "x": 2395.5,
      "y": 659
    },
    {
      "id": "AML.T0043",
      "name": "AML.T0043: Adversarial Data Poisoning",
      "type": "attack_technique",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/threat-intel/mitre-atlas-adversarial-ai-threat-matrix/",
      "tags": [
        "persistence",
        "mitre-atlas",
        "rag"
      ],
      "x": 2534.6,
      "y": 676.3
    },
    {
      "id": "AML.T0054",
      "name": "AML.T0054: LLM Jailbreak",
      "type": "attack_technique",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/threat-intel/mitre-atlas-adversarial-ai-threat-matrix/",
      "tags": [
        "defense-evasion",
        "mitre-atlas"
      ],
      "x": 2681.8,
      "y": 670.1
    },
    {
      "id": "VENDOR-BERRIAI",
      "name": "BerriAI",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "ai-middleware"
      ],
      "x": 1893.4,
      "y": 556.6
    },
    {
      "id": "VENDOR-LANGCHAIN",
      "name": "LangChain Inc.",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "agent-frameworks"
      ],
      "x": 1788.4,
      "y": 646.2
    },
    {
      "id": "VENDOR-ANYSPHERE",
      "name": "Anysphere",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "developer-tooling"
      ],
      "x": 1744.8,
      "y": 1137.9
    },
    {
      "id": "VENDOR-ECLIPSE",
      "name": "Eclipse Foundation",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "open-source-foundation"
      ],
      "x": 1822.2,
      "y": 1121.1
    },
    {
      "id": "VENDOR-LOGSPACE",
      "name": "Logspace / DataStax",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "agent-orchestrator",
        "ai-infrastructure"
      ],
      "x": 484.4,
      "y": 1049.5
    },
    {
      "id": "VENDOR-MICROSOFT",
      "name": "Microsoft Corporation",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "cloud-provider",
        "enterprise-software"
      ],
      "x": 1150.5,
      "y": 1329.7
    },
    {
      "id": "VENDOR-MINTPLEX",
      "name": "Mintplex Labs",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "ai-infrastructure",
        "agentic-workspace",
        "rag"
      ],
      "x": 905.3,
      "y": 1328.1
    },
    {
      "id": "CVE-2026-59822",
      "name": "CVE-2026-59822: LiteLLM MCP Streamable HTTP Auth Bypass",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2026/cve-2026-59822/",
      "tags": [
        "authentication-bypass",
        "mcp",
        "agentic-ai",
        "rce-prerequisite"
      ],
      "x": 1736.1,
      "y": 1025.8
    },
    {
      "id": "CVE-2026-41264",
      "name": "CVE-2026-41264: LangChain / LangGraph Agent Loop RCE",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2026/cve-2026-41264/",
      "tags": [
        "prompt-injection",
        "langchain",
        "langgraph",
        "autonomous-loop",
        "rce"
      ],
      "x": 1580.1,
      "y": 995.8
    },
    {
      "id": "CVE-2026-22708",
      "name": "CVE-2026-22708: Cursor IDE Terminal Allowlist Bypass via Shell Built-ins",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2026/cve-2026-22708/",
      "tags": [
        "ide",
        "cursor",
        "shell-builtins",
        "environment-poisoning",
        "rce"
      ],
      "x": 1594.8,
      "y": 1148.2
    },
    {
      "id": "CVE-2026-46580",
      "name": "CVE-2026-46580: Eclipse Theia Prompt Template Injection & RCE",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2026/cve-2026-46580/",
      "tags": [
        "eclipse-theia",
        "workspace-trust",
        "prompt-injection",
        "rce"
      ],
      "x": 2030.8,
      "y": 1135.5
    },
    {
      "id": "CVE-2026-40087",
      "name": "CVE-2026-40087: LangChain Incomplete f-string Validation & Attribute Exposure",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2026/cve-2026-40087/",
      "tags": [
        "prompt-template",
        "langchain",
        "template-injection",
        "information-disclosure"
      ],
      "x": 1956,
      "y": 826.8
    },
    {
      "id": "CVE-2025-32711",
      "name": "CVE-2025-32711: Microsoft 365 Copilot EchoLeak Zero-Click IPI",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2025/cve-2025-32711/",
      "tags": [
        "m365-copilot",
        "zero-click",
        "indirect-prompt-injection",
        "data-exfiltration"
      ],
      "x": 1633.7,
      "y": 1219.9
    },
    {
      "id": "CVE-2025-53773",
      "name": "CVE-2025-53773: GitHub Copilot RCE via Settings Hijacking",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2025/cve-2025-53773/",
      "tags": [
        "github-copilot",
        "vs-code",
        "prompt-injection",
        "rce"
      ],
      "x": 1734.2,
      "y": 801.6
    },
    {
      "id": "CVE-2026-27966",
      "name": "CVE-2026-27966: Langflow CSV Agent Hardcoded Dangerous Code Execution RCE",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2026/cve-2026-27966/",
      "tags": [
        "langflow",
        "csv-agent",
        "code-generation",
        "rce",
        "cwe-94"
      ],
      "x": 1610.4,
      "y": 1070.6
    },
    {
      "id": "CVE-2026-33873",
      "name": "CVE-2026-33873: Langflow Agentic Assistant Dynamic Execution Sink RCE",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2026/cve-2026-33873/",
      "tags": [
        "langflow",
        "agentic-assistant",
        "validation-bypass",
        "rce"
      ],
      "x": 1540.2,
      "y": 1062.6
    },
    {
      "id": "CVE-2025-52573",
      "name": "CVE-2025-52573: iOS Simulator MCP Server ui_tap Command Injection",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2025/cve-2025-52573/",
      "tags": [
        "mcp-server",
        "command-injection",
        "child-process",
        "rce",
        "cwe-78"
      ],
      "x": 1466.6,
      "y": 1067.8
    },
    {
      "id": "CVE-2025-66389",
      "name": "CVE-2025-66389: GitHub Copilot Workspace Traversal & File-Handler Exfiltration",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2025/cve-2025-66389/",
      "tags": [
        "github-copilot",
        "directory-traversal",
        "fetch-webpage",
        "data-exfiltration"
      ],
      "x": 1655.9,
      "y": 1006.6
    },
    {
      "id": "CVE-2026-24307",
      "name": "CVE-2026-24307: Microsoft 365 Copilot Input Type Confusion & Information Disclosure",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2026/cve-2026-24307/",
      "tags": [
        "m365-copilot",
        "type-confusion",
        "information-disclosure",
        "cwe-1287"
      ],
      "x": 1715.6,
      "y": 1214.2
    },
    {
      "id": "CVE-2025-59417",
      "name": "CVE-2025-59417: Lobe Chat lobeArtifact SVG dangerouslySetInnerHTML XSS to RCE",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2025/cve-2025-59417/",
      "tags": [
        "lobe-chat",
        "xss",
        "svg-injection",
        "rce",
        "cwe-79"
      ],
      "x": 1880.8,
      "y": 844.9
    },
    {
      "id": "CVE-2025-49150",
      "name": "CVE-2025-49150: Cursor AI Editor Automatic JSON Schema Download Data Exfiltration",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2025/cve-2025-49150/",
      "tags": [
        "cursor",
        "schema-download",
        "data-exfiltration",
        "side-channel"
      ],
      "x": 1794.1,
      "y": 1198.6
    },
    {
      "id": "CVE-2024-5184",
      "name": "CVE-2024-5184: EmailGPT Direct Prompt Injection & Email Data Exfiltration",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2024/cve-2024-5184/",
      "tags": [
        "emailgpt",
        "prompt-injection",
        "system-prompt-leak",
        "data-exfiltration"
      ],
      "x": 1505.2,
      "y": 854.4
    },
    {
      "id": "CVE-2026-21669",
      "name": "CVE-2026-21669: Veeam Backup Catalog Service Pre-Auth Binary Deserialization RCE",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2026/cve-2026-21669/",
      "tags": [
        "veeam",
        "deserialization",
        "pre-auth",
        "rce",
        "cwe-502",
        "backup-infrastructure"
      ],
      "x": 1731.8,
      "y": -47.2
    },
    {
      "id": "CVE-2026-21670",
      "name": "CVE-2026-21670: Veeam Backup Service WCF Impersonation Privilege Escalation",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2026/cve-2026-21670/",
      "tags": [
        "veeam",
        "privilege-escalation",
        "wcf",
        "impersonation",
        "cwe-269",
        "backup-infrastructure"
      ],
      "x": 1805.7,
      "y": 33.9
    },
    {
      "id": "CVE-2026-21671",
      "name": "CVE-2026-21671: Veeam Enterprise Manager Path Traversal Arbitrary File Read",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2026/cve-2026-21671/",
      "tags": [
        "veeam",
        "path-traversal",
        "information-disclosure",
        "pre-auth",
        "cwe-22",
        "backup-infrastructure"
      ],
      "x": 1668.7,
      "y": 326.3
    },
    {
      "id": "CVE-2026-21672",
      "name": "CVE-2026-21672: Veeam Agent Configuration Service SSRF & Cloud Metadata Theft",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2026/cve-2026-21672/",
      "tags": [
        "veeam",
        "ssrf",
        "cloud-security",
        "imds",
        "credential-theft",
        "cwe-918"
      ],
      "x": 1718.4,
      "y": 390
    },
    {
      "id": "CVE-2026-21708",
      "name": "CVE-2026-21708: Veeam Backup & Replication PostgreSQL SQL Injection to RCE",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2026/cve-2026-21708/",
      "tags": [
        "veeam",
        "sqli",
        "rce",
        "postgresql",
        "privilege-escalation",
        "cwe-89"
      ],
      "x": 1798.4,
      "y": 402.6
    },
    {
      "id": "CVE-2026-19490",
      "name": "CVE-2026-19490: Citrix NetScaler ADC & Gateway Authentication Bypass",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2026/cve-2026-19490/",
      "tags": [
        "citrix",
        "netscaler",
        "authentication-bypass",
        "saml",
        "vpn",
        "cwe-288",
        "perimeter"
      ],
      "x": 501.3,
      "y": 124.7
    },
    {
      "id": "CVE-2025-25249",
      "name": "CVE-2025-25249: Fortinet FortiOS cw_acd CAPWAP Heap Buffer Overflow RCE",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2025/cve-2025-25249/",
      "tags": [
        "fortinet",
        "fortios",
        "heap-overflow",
        "rce",
        "capwap",
        "cwe-122",
        "perimeter",
        "pivotc2"
      ],
      "x": 798.1,
      "y": 632.2
    },
    {
      "id": "CVE-2026-87491",
      "name": "CVE-2026-87491: Google Chromium V8 Out-of-Bounds Write Zero-Day to Sandbox RCE",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2026/cve-2026-87491/",
      "tags": [
        "google",
        "chromium",
        "v8",
        "out-of-bounds-write",
        "rce",
        "zero-day",
        "cwe-787",
        "ai-agents"
      ],
      "x": 1823.2,
      "y": 480.2
    },
    {
      "id": "CVE-2026-86060",
      "name": "CVE-2026-86060: MikroTik RouterOS SSH Argument Delimiter Privilege Escalation",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2026/cve-2026-86060/",
      "tags": [
        "mikrotik",
        "routeros",
        "cisa-kev",
        "privilege-escalation",
        "argument-injection",
        "cwe-88",
        "mikrotrick",
        "perimeter-breach"
      ],
      "x": 921.3,
      "y": 1541.4
    },
    {
      "id": "CVE-2026-67277",
      "name": "CVE-2026-67277: MikroTik RouterOS Bandwidth-Test Auth Bypass & Kernel Memory Leak / DoS",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2026/cve-2026-67277/",
      "tags": [
        "mikrotik",
        "routeros",
        "cisa-kev",
        "btest",
        "authentication-bypass",
        "integer-underflow",
        "cwe-306",
        "cwe-191",
        "dos"
      ],
      "x": 740,
      "y": 837.9
    },
    {
      "id": "CVE-2026-85102",
      "name": "CVE-2026-85102: Check Point VPN Certificate Trust Validation Remote Code Execution",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2026/cve-2026-85102/",
      "tags": [
        "checkpoint",
        "gaia",
        "vpn",
        "rce",
        "certificate-validation",
        "cwe-295",
        "perimeter-breach"
      ],
      "x": 1588.7,
      "y": 334.1
    },
    {
      "id": "CVE-2026-85103",
      "name": "CVE-2026-85103: Check Point VPN Certificate ASN.1 Decoding Heap Buffer Overflow RCE",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2026/cve-2026-85103/",
      "tags": [
        "checkpoint",
        "gaia",
        "vpn",
        "rce",
        "heap-overflow",
        "asn1",
        "cwe-122",
        "perimeter-breach"
      ],
      "x": 1349.7,
      "y": 327.6
    },
    {
      "id": "CVE-2026-81578",
      "name": "CVE-2026-81578: PaperCut NG/MF Web Management Authentication Bypass",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2026/cve-2026-81578/",
      "tags": [
        "papercut",
        "auth-bypass",
        "cisa-kev",
        "cwe-306",
        "active-directory"
      ],
      "x": 1358.6,
      "y": 664.1
    },
    {
      "id": "CVE-2026-82078",
      "name": "CVE-2026-82078: PaperCut NG/MF Database Dynamic Class Loading RCE",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2026/cve-2026-82078/",
      "tags": [
        "papercut",
        "rce",
        "cisa-kev",
        "cwe-470",
        "reflection",
        "active-directory"
      ],
      "x": 1402.6,
      "y": 728.7
    },
    {
      "id": "CVE-2021-42278",
      "name": "CVE-2021-42278: Active Directory sAMAccountName Spoofing (noPac)",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2021/cve-2021-42278/",
      "tags": [
        "active-directory",
        "privilege-escalation",
        "cisa-kev",
        "cwe-269",
        "nopac"
      ],
      "x": 1636.2,
      "y": 398.2
    },
    {
      "id": "CVE-2021-42287",
      "name": "CVE-2021-42287: Kerberos KDC PAC Validation Impersonation (noPac)",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2021/cve-2021-42287/",
      "tags": [
        "active-directory",
        "kerberos",
        "cisa-kev",
        "cwe-287",
        "nopac",
        "domain-admin"
      ],
      "x": 1065.2,
      "y": 709.7
    },
    {
      "id": "CVE-2023-27532",
      "name": "CVE-2023-27532: Veeam Backup Service API Credential Disclosure",
      "type": "vulnerability",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/cve/2023/cve-2023-27532/",
      "tags": [
        "veeam",
        "backup",
        "credential-dumping",
        "cisa-kev",
        "cwe-306"
      ],
      "x": 1369.7,
      "y": 530.9
    },
    {
      "id": "CVE-2009-0238",
      "name": "CVE-2009-0238: Microsoft Excel Remote Code Execution",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2009/cve-2009-0238/",
      "tags": [
        "cve",
        "2009",
        "high",
        "auto-ingested"
      ],
      "x": 1085.1,
      "y": 1575.9
    },
    {
      "id": "PROD-OFFICE",
      "name": "Microsoft Office & 365 Apps",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 977.1,
      "y": 1482.1
    },
    {
      "id": "CVE-2012-1854",
      "name": "CVE-2012-1854: Microsoft VBA Insecure Library Loading",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2012/cve-2012-1854/",
      "tags": [
        "cve",
        "2012",
        "high",
        "auto-ingested"
      ],
      "x": 871.3,
      "y": 1602.2
    },
    {
      "id": "PROD-WINDOWS",
      "name": "Microsoft Windows & Windows Server",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 672.4,
      "y": 1497.9
    },
    {
      "id": "CVE-2020-2021",
      "name": "CVE-2020-2021: Palo Alto Networks PAN-OS SAML Authentication Bypass",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2020/cve-2020-2021/",
      "tags": [
        "cve",
        "2020",
        "high",
        "auto-ingested"
      ],
      "x": 911,
      "y": 700.4
    },
    {
      "id": "PROD-PANOS",
      "name": "Palo Alto Networks PAN-OS",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 830.7,
      "y": 419.4
    },
    {
      "id": "VENDOR-PALOALTO",
      "name": "Palo Alto Networks",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 835.9,
      "y": 703.5
    },
    {
      "id": "CVE-2020-3452",
      "name": "CVE-2020-3452: Cisco ASA and FTD Web Services Read-Only Path Traversal",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2020/cve-2020-3452/",
      "tags": [
        "cve",
        "2020",
        "critical",
        "auto-ingested"
      ],
      "x": 394.8,
      "y": 763.1
    },
    {
      "id": "PROD-FORTIOS",
      "name": "Fortinet FortiOS Gateway",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 519.7,
      "y": 550.9
    },
    {
      "id": "VENDOR-FORTINET",
      "name": "Fortinet",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 313.4,
      "y": 763.9
    },
    {
      "id": "CVE-2020-9715",
      "name": "CVE-2020-9715: Adobe Acrobat and Reader Use-After-Free",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2020/cve-2020-9715/",
      "tags": [
        "cve",
        "2020",
        "high",
        "auto-ingested"
      ],
      "x": 1841.9,
      "y": -122.5
    },
    {
      "id": "PROD-PAPERCUT",
      "name": "PaperCut MF/NG",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1289,
      "y": 524.4
    },
    {
      "id": "VENDOR-PAPERCUT",
      "name": "PaperCut Software",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 1152.9,
      "y": 226.6
    },
    {
      "id": "CVE-2022-29230",
      "name": "CVE-2022-29230: XSS in Shopify Hydrogen",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2022/cve-2022-29230/",
      "tags": [
        "cve",
        "2022",
        "high",
        "auto-ingested"
      ],
      "x": 2194.4,
      "y": 318.7
    },
    {
      "id": "CVE-2022-42475",
      "name": "CVE-2022-42475: Fortinet FortiOS SSL-VPN Pre-Auth Heap Buffer Overflow",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2022/cve-2022-42475/",
      "tags": [
        "cve",
        "2022",
        "high",
        "auto-ingested"
      ],
      "x": 474.1,
      "y": 763.3
    },
    {
      "id": "CVE-2023-20198",
      "name": "CVE-2023-20198: Cisco IOS XE Software Web UI Privilege Escalation Zero-Day",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2023/cve-2023-20198/",
      "tags": [
        "cve",
        "2023",
        "high",
        "auto-ingested"
      ],
      "x": 666.8,
      "y": 837.5
    },
    {
      "id": "CVE-2023-21529",
      "name": "CVE-2023-21529: Microsoft Exchange Server RCE via Untrusted Deserialization",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2023/cve-2023-21529/",
      "tags": [
        "cve",
        "2023",
        "high",
        "auto-ingested"
      ],
      "x": 2115.9,
      "y": 140.2
    },
    {
      "id": "PROD-VEEAM-VBR",
      "name": "Veeam Backup & Replication",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1646.2,
      "y": 185.9
    },
    {
      "id": "VENDOR-VEEAM",
      "name": "Veeam Software",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 1106.1,
      "y": 71.7
    },
    {
      "id": "CVE-2023-27997",
      "name": "CVE-2023-27997: Fortinet FortiOS SSL-VPN Heap Buffer Overflow RCE (Volt Typhoon)",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2023/cve-2023-27997/",
      "tags": [
        "cve",
        "2023",
        "high",
        "auto-ingested"
      ],
      "x": 719.9,
      "y": 499.6
    },
    {
      "id": "CVE-2023-36424",
      "name": "CVE-2023-36424: VMware vCenter Server Authentication Bypass",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2023/cve-2023-36424/",
      "tags": [
        "cve",
        "2023",
        "high",
        "auto-ingested"
      ],
      "x": 1985.2,
      "y": 44.8
    },
    {
      "id": "CVE-2024-0012",
      "name": "CVE-2024-0012: Palo Alto Networks PAN-OS Management Web Interface Authentication Bypass",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2024/cve-2024-0012/",
      "tags": [
        "cve",
        "2024",
        "high",
        "auto-ingested"
      ],
      "x": 869.9,
      "y": 801.9
    },
    {
      "id": "CVE-2024-20353",
      "name": "CVE-2024-20353: Cisco ASA and FTD Web Server Denial of Service & Memory Corruption (ArcaneDoor)",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2024/cve-2024-20353/",
      "tags": [
        "cve",
        "2024",
        "high",
        "auto-ingested"
      ],
      "x": 474.9,
      "y": 906.1
    },
    {
      "id": "CVE-2024-20359",
      "name": "CVE-2024-20359: Cisco ASA and FTD Persistent Local Code Execution (Line Runner / ArcaneDoor)",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2024/cve-2024-20359/",
      "tags": [
        "cve",
        "2024",
        "critical",
        "auto-ingested"
      ],
      "x": 396.8,
      "y": 620.3
    },
    {
      "id": "CVE-2024-21762",
      "name": "CVE-2024-21762: Fortinet FortiOS SSL-VPN Out-of-Bounds Write Remote Code Execution Zero-Day",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2024/cve-2024-21762/",
      "tags": [
        "cve",
        "2024",
        "high",
        "auto-ingested"
      ],
      "x": 593.8,
      "y": 337.8
    },
    {
      "id": "CVE-2024-3400",
      "name": "CVE-2024-3400: Palo Alto Networks PAN-OS GlobalProtect Command Injection Zero-Day",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2024/cve-2024-3400/",
      "tags": [
        "cve",
        "2024",
        "high",
        "auto-ingested"
      ],
      "x": 483.1,
      "y": 475.7
    },
    {
      "id": "CVE-2024-47575",
      "name": "CVE-2024-47575: Fortinet FortiManager fgfmd Authentication Bypass & Remote Code Execution (FortiJump)",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2024/cve-2024-47575/",
      "tags": [
        "cve",
        "2024",
        "high",
        "auto-ingested"
      ],
      "x": 600.7,
      "y": 556.7
    },
    {
      "id": "VENDOR-EMAILGPT",
      "name": "EmailGPT OpenSource",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 934.3,
      "y": 925.4
    },
    {
      "id": "CVE-2024-57728",
      "name": "CVE-2024-57728 : SimpleHelp Arbitrary File Upload",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2024/cve-2024-57728/",
      "tags": [
        "cve",
        "2024",
        "high",
        "auto-ingested"
      ],
      "x": 1507.2,
      "y": -160.2
    },
    {
      "id": "PROD-SIMPLEHELP",
      "name": "SimpleHelp Remote Access",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1212.3,
      "y": -55.5
    },
    {
      "id": "VENDOR-SIMPLEHELP",
      "name": "SimpleHelp Ltd",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 1049.3,
      "y": 128.6
    },
    {
      "id": "CVE-2025-0282",
      "name": "CVE-2025-0282: Pre-Authentication Root RCE via Stack Buffer Overflow in Ivanti Connect Secure (ICS / IPS / ZTA)",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2025/cve-2025-0282/",
      "tags": [
        "cve",
        "2025",
        "critical",
        "auto-ingested"
      ],
      "x": 1208,
      "y": 167.7
    },
    {
      "id": "PROD-IVANTI-CONNECT",
      "name": "Ivanti Connect Secure VPN",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 912.1,
      "y": 19.8
    },
    {
      "id": "VENDOR-IVANTI",
      "name": "Ivanti",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 738.4,
      "y": 142.6
    },
    {
      "id": "CVE-2025-20188",
      "name": "CVE-2025-20188: Arbitrary File Upload and Root RCE in Cisco IOS XE WLC via Hard-Coded JWT",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2025/cve-2025-20188/",
      "tags": [
        "cve",
        "2025",
        "critical",
        "auto-ingested"
      ],
      "x": 1670.6,
      "y": 533.5
    },
    {
      "id": "CVE-2025-20281",
      "name": "CVE-2025-20281: Unauthenticated Root RCE in Cisco Identity Services Engine (ISE) API",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2025/cve-2025-20281/",
      "tags": [
        "cve",
        "2025",
        "critical",
        "auto-ingested"
      ],
      "x": 947.7,
      "y": 996.4
    },
    {
      "id": "PROD-CISCO-ISE",
      "name": "Cisco Identity Services Engine (ISE)",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1030.8,
      "y": 1268.2
    },
    {
      "id": "VENDOR-CISCO",
      "name": "Cisco Systems",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 1206.9,
      "y": 1466.1
    },
    {
      "id": "CVE-2025-20352",
      "name": "CVE-2025-20352: SNMP Stack Buffer Overflow in Cisco IOS and IOS XE (DoS & RCE)",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2025/cve-2025-20352/",
      "tags": [
        "cve",
        "2025",
        "high",
        "auto-ingested"
      ],
      "x": 2002.4,
      "y": 672.8
    },
    {
      "id": "CVE-2025-20393",
      "name": "CVE-2025-20393: Unauthenticated Root RCE in Cisco Secure Email Gateway (Spam Quarantine)",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2025/cve-2025-20393/",
      "tags": [
        "cve",
        "2025",
        "critical",
        "auto-ingested"
      ],
      "x": 1553.2,
      "y": 1216.3
    },
    {
      "id": "PROD-CISCO-SEG",
      "name": "Cisco Secure Email Gateway (AsyncOS)",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1339.9,
      "y": 1417.3
    },
    {
      "id": "CVE-2025-21333",
      "name": "CVE-2025-21333: Windows Kernel Privilege Escalation via Hyper-V VSP (Heap Overflow)",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2025/cve-2025-21333/",
      "tags": [
        "cve",
        "2025",
        "high",
        "auto-ingested"
      ],
      "x": 541.4,
      "y": 1474.3
    },
    {
      "id": "CVE-2025-22457",
      "name": "CVE-2025-22457: Subsequent Pre-Auth Root RCE via Stack Buffer Overflow in Ivanti Connect Secure (ICS / IPS / ZTA)",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2025/cve-2025-22457/",
      "tags": [
        "cve",
        "2025",
        "critical",
        "auto-ingested"
      ],
      "x": 1016.1,
      "y": 290.5
    },
    {
      "id": "CVE-2025-23304",
      "name": "CVE-2025-23304: NVIDIA NeMo Framework RCE",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2025/cve-2025-23304/",
      "tags": [
        "cve",
        "2025",
        "high",
        "auto-ingested"
      ],
      "x": 841,
      "y": -27.6
    },
    {
      "id": "CVE-2025-24054",
      "name": "CVE-2025-24054: NTLM Hash Disclosure and Coerced Authentication in Windows (.library-ms)",
      "type": "vulnerability",
      "severity": "MEDIUM",
      "cvss_score": 6.5,
      "doc_url": "/cve/2025/cve-2025-24054/",
      "tags": [
        "cve",
        "2025",
        "medium",
        "auto-ingested"
      ],
      "x": 739.9,
      "y": 1647.3
    },
    {
      "id": "CVE-2025-24472",
      "name": "CVE-2025-24472: Super-Admin Authentication Bypass in Fortinet FortiOS & FortiProxy (CSF Proxy)",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2025/cve-2025-24472/",
      "tags": [
        "cve",
        "2025",
        "critical",
        "auto-ingested"
      ],
      "x": 348.6,
      "y": 403.1
    },
    {
      "id": "CVE-2025-24813",
      "name": "CVE-2025-24813: RCE via Partial PUT Requests and Session Deserialization in Apache Tomcat",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2025/cve-2025-24813/",
      "tags": [
        "cve",
        "2025",
        "critical",
        "auto-ingested"
      ],
      "x": 808.5,
      "y": 855.9
    },
    {
      "id": "PROD-APACHE-TOMCAT",
      "name": "Apache Tomcat",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 908.1,
      "y": 1122.7
    },
    {
      "id": "VENDOR-APACHE",
      "name": "Apache Software Foundation",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 1089.9,
      "y": 781.9
    },
    {
      "id": "CVE-2025-25257",
      "name": "CVE-2025-25257: Unauthenticated SQL Injection in Fortinet FortiWeb Management Interface",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2025/cve-2025-25257/",
      "tags": [
        "cve",
        "2025",
        "critical",
        "auto-ingested"
      ],
      "x": 709.2,
      "y": 768.6
    },
    {
      "id": "CVE-2025-26319",
      "name": "CVE-2025-26319: Flowise Arbitrary File Upload and Directory Traversal Remote Code Execution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2025/cve-2025-26319/",
      "tags": [
        "cve",
        "2025",
        "critical",
        "auto-ingested"
      ],
      "x": 1310.3,
      "y": 1555.2
    },
    {
      "id": "PROD-FLOWISE",
      "name": "Flowise AI Workflow Builder",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1073.9,
      "y": 1342.8
    },
    {
      "id": "VENDOR-FLOWISE",
      "name": "FlowiseAI",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 793.4,
      "y": 1236.4
    },
    {
      "id": "CVE-2025-29635",
      "name": "CVE-2025-29635: Command injection vulnerability in D-Link DIR-823X router firmware",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2025/cve-2025-29635/",
      "tags": [
        "cve",
        "2025",
        "high",
        "auto-ingested"
      ],
      "x": 2048.6,
      "y": 509.5
    },
    {
      "id": "CVE-2025-29824",
      "name": "CVE-2025-29824: SYSTEM Privilege Escalation in Windows CLFS Driver (Use-After-Free)",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2025/cve-2025-29824/",
      "tags": [
        "cve",
        "2025",
        "high",
        "auto-ingested"
      ],
      "x": 765.1,
      "y": 1723.7
    },
    {
      "id": "CVE-2025-29927",
      "name": "CVE-2025-29927: Middleware Authorization Bypass via x-middleware-subrequest Header in Next.js",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2025/cve-2025-29927/",
      "tags": [
        "cve",
        "2025",
        "critical",
        "auto-ingested"
      ],
      "x": 1731.4,
      "y": 177.8
    },
    {
      "id": "CVE-2025-30733",
      "name": "CVE-2025-30733: Pre-Authentication Memory Leak in Oracle Database Server (RDBMS Listener)",
      "type": "vulnerability",
      "severity": "MEDIUM",
      "cvss_score": 6.5,
      "doc_url": "/cve/2025/cve-2025-30733/",
      "tags": [
        "cve",
        "2025",
        "medium",
        "auto-ingested"
      ],
      "x": 1258.5,
      "y": 1405.1
    },
    {
      "id": "CVE-2025-32433",
      "name": "CVE-2025-32433: Pre-Authentication Command Execution in Erlang/OTP SSH Server",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2025/cve-2025-32433/",
      "tags": [
        "cve",
        "2025",
        "critical",
        "auto-ingested"
      ],
      "x": 1685.6,
      "y": 459.1
    },
    {
      "id": "CVE-2025-3248",
      "name": "CVE-2025-3248: Langflow Unauthenticated Code Validation Python exec() Remote Code Execution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2025/cve-2025-3248/",
      "tags": [
        "cve",
        "2025",
        "critical",
        "auto-ingested"
      ],
      "x": 1307.6,
      "y": 803
    },
    {
      "id": "VENDOR-LANGFLOW",
      "name": "DataStax / Langflow",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 1036.1,
      "y": 846
    },
    {
      "id": "CVE-2025-32724",
      "name": "CVE-2025-32724: Remote Denial of Service and System Crash in Windows LSASS via RPC",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2025/cve-2025-32724/",
      "tags": [
        "cve",
        "2025",
        "high",
        "auto-ingested"
      ],
      "x": 819,
      "y": 1663
    },
    {
      "id": "CVE-2025-39682",
      "name": "CVE-2025-39682: Linux Kernel kTLS Receive Path Zero-Length Record Use-After-Free Privilege Escalation",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2025/cve-2025-39682/",
      "tags": [
        "cve",
        "2025",
        "critical",
        "auto-ingested"
      ],
      "x": 354.5,
      "y": 693
    },
    {
      "id": "PROD-LINUX-KERNEL",
      "name": "Linux Kernel Core",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 354.1,
      "y": 837.8
    },
    {
      "id": "VENDOR-LINUX",
      "name": "Linux Foundation",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 342.3,
      "y": 1103.4
    },
    {
      "id": "CVE-2025-39964",
      "name": "CVE-2025-39964: Linux Kernel Crypto AF_ALG Concurrent Write Race Condition",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2025/cve-2025-39964/",
      "tags": [
        "cve",
        "2025",
        "high",
        "auto-ingested"
      ],
      "x": 235.4,
      "y": 909.6
    },
    {
      "id": "CVE-2025-42944",
      "name": "CVE-2025-42944: Unauthenticated Java Deserialization RCE in SAP NetWeaver AS Java (RMI-P4)",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2025/cve-2025-42944/",
      "tags": [
        "cve",
        "2025",
        "critical",
        "auto-ingested"
      ],
      "x": 917.2,
      "y": 1197.5
    },
    {
      "id": "CVE-2025-47277",
      "name": "CVE-2025-47277: vLLM Distributed KV-Cache PyNcclPipe Remote Code Execution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2025/cve-2025-47277/",
      "tags": [
        "cve",
        "2025",
        "critical",
        "auto-ingested"
      ],
      "x": 1237.6,
      "y": 803.8
    },
    {
      "id": "PROD-VLLM",
      "name": "vLLM Inference Engine",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1145.3,
      "y": 1065.7
    },
    {
      "id": "VENDOR-VLLM",
      "name": "vLLM Project",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 515.7,
      "y": 976.3
    },
    {
      "id": "CVE-2025-49113",
      "name": "CVE-2025-49113: Authenticated RCE via PHP Deserialization in Roundcube Webmail (upload.php)",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2025/cve-2025-49113/",
      "tags": [
        "cve",
        "2025",
        "critical",
        "auto-ingested"
      ],
      "x": 1449.9,
      "y": 540.4
    },
    {
      "id": "CVE-2025-49704",
      "name": "CVE-2025-49704: Remote Code Injection in Microsoft SharePoint Server",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2025/cve-2025-49704/",
      "tags": [
        "cve",
        "2025",
        "critical",
        "auto-ingested"
      ],
      "x": 1006.4,
      "y": 1558
    },
    {
      "id": "CVE-2025-50105",
      "name": "CVE-2025-50105: Privilege Escalation and Workflow Tampering in Oracle E-Business Suite (Universal Work Queue)",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2025/cve-2025-50105/",
      "tags": [
        "cve",
        "2025",
        "high",
        "auto-ingested"
      ],
      "x": 1980.8,
      "y": 340.4
    },
    {
      "id": "PROD-IOS-SIMULATOR",
      "name": "Apple iOS Simulator MCP Server",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1270.8,
      "y": 1001.9
    },
    {
      "id": "VENDOR-APPLE",
      "name": "Apple Inc",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 1241.2,
      "y": 590.8
    },
    {
      "id": "CVE-2025-5277",
      "name": "CVE-2025-5277: Command Injection in AWS MCP Server via Prompt-Coerced Tool Execution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2025/cve-2025-5277/",
      "tags": [
        "cve",
        "2025",
        "critical",
        "auto-ingested"
      ],
      "x": 1387.4,
      "y": 933.9
    },
    {
      "id": "PROD-AWS-MCP-SERVER",
      "name": "AWS MCP Server Suite",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 716.5,
      "y": 914.8
    },
    {
      "id": "VENDOR-AMAZON",
      "name": "Amazon Web Services / MCP Community",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 514.2,
      "y": 835.1
    },
    {
      "id": "CVE-2025-52970",
      "name": "CVE-2025-52970: Access Control Bypass and Privilege Escalation in Fortinet FortiWeb",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2025/cve-2025-52970/",
      "tags": [
        "cve",
        "2025",
        "high",
        "auto-ingested"
      ],
      "x": 418.6,
      "y": 182.2
    },
    {
      "id": "CVE-2025-53770",
      "name": "CVE-2025-53770: Insecure Deserialization RCE in Microsoft SharePoint Server (ToolShell)",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2025/cve-2025-53770/",
      "tags": [
        "cve",
        "2025",
        "critical",
        "auto-ingested"
      ],
      "x": 858.7,
      "y": 1389.8
    },
    {
      "id": "CVE-2025-53844",
      "name": "CVE-2025-53844: FortiOS Out-of-Bounds Write via Compromised Fabric Devices",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2025/cve-2025-53844/",
      "tags": [
        "cve",
        "2025",
        "high",
        "auto-ingested"
      ],
      "x": 355.9,
      "y": 264.5
    },
    {
      "id": "CVE-2025-54794",
      "name": "CVE-2025-54794: Claude Code Working Directory Sandbox Escape via Path Prefix Matching",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2025/cve-2025-54794/",
      "tags": [
        "cve",
        "2025",
        "critical",
        "auto-ingested"
      ],
      "x": 1576.4,
      "y": 626.7
    },
    {
      "id": "PROD-CLAUDE-CODE",
      "name": "Claude Code Agentic CLI",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1278.5,
      "y": 662.4
    },
    {
      "id": "VENDOR-ANTHROPIC",
      "name": "Anthropic",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 953.6,
      "y": 846.6
    },
    {
      "id": "CVE-2025-54795",
      "name": "CVE-2025-54795: Claude Code Echo Command Injection and Approval Prompt Bypass via Untrusted Context",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2025/cve-2025-54795/",
      "tags": [
        "cve",
        "2025",
        "critical",
        "auto-ingested"
      ],
      "x": 1553.6,
      "y": 701.6
    },
    {
      "id": "CVE-2025-55125",
      "name": "CVE-2025-55125: Root Command Injection via Backup Configuration in Veeam Backup & Replication",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2025/cve-2025-55125/",
      "tags": [
        "cve",
        "2025",
        "high",
        "auto-ingested"
      ],
      "x": 1469.7,
      "y": 270.7
    },
    {
      "id": "CVE-2025-55182",
      "name": "CVE-2025-55182:",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2025/cve-2025-55182/",
      "tags": [
        "cve",
        "2025",
        "critical",
        "auto-ingested"
      ],
      "x": 1067.7,
      "y": 1197.4
    },
    {
      "id": "CVE-2025-5777",
      "name": "CVE-2025-5777: OOB Memory Disclosure and MFA Session Hijacking in Citrix NetScaler ADC & Gateway (CitrixBleed 2)",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2025/cve-2025-5777/",
      "tags": [
        "cve",
        "2025",
        "critical",
        "auto-ingested"
      ],
      "x": 276.1,
      "y": 248.4
    },
    {
      "id": "PROD-NETSCALER",
      "name": "Citrix NetScaler ADC",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 399,
      "y": 336.9
    },
    {
      "id": "VENDOR-CITRIX",
      "name": "Citrix Systems",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 271.8,
      "y": 693.5
    },
    {
      "id": "CVE-2025-58434",
      "name": "CVE-2025-58434: FlowiseAI Unauthenticated Full Account Takeover",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2025/cve-2025-58434/",
      "tags": [
        "cve",
        "2025",
        "high",
        "auto-ingested"
      ],
      "x": 715.5,
      "y": 1217.6
    },
    {
      "id": "PROD-LOBECHAT",
      "name": "Lobe Chat Framework",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1604.5,
      "y": 475.8
    },
    {
      "id": "VENDOR-LOBEHUB",
      "name": "LobeHub",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 1336,
      "y": 459.6
    },
    {
      "id": "CVE-2025-59468",
      "name": "CVE-2025-59468: PostgreSQL Remote Code Execution via Malicious Password Parameter in Veeam Backup & Replication",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2025/cve-2025-59468/",
      "tags": [
        "cve",
        "2025",
        "critical",
        "auto-ingested"
      ],
      "x": 1438.8,
      "y": -62.9
    },
    {
      "id": "CVE-2025-59469",
      "name": "CVE-2025-59469: Arbitrary File Write as Root by Operators in Veeam Backup & Replication",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2025/cve-2025-59469/",
      "tags": [
        "cve",
        "2025",
        "high",
        "auto-ingested"
      ],
      "x": 1546.8,
      "y": 54.7
    },
    {
      "id": "CVE-2025-59470",
      "name": "CVE-2025-59470: PostgreSQL Remote Code Execution via Operator Role in Veeam Backup & Replication",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2025/cve-2025-59470/",
      "tags": [
        "cve",
        "2025",
        "critical",
        "auto-ingested"
      ],
      "x": 1812.8,
      "y": 172.9
    },
    {
      "id": "CVE-2025-59528",
      "name": "CVE-2025-59528: Flowise CustomMCP Node JavaScript Function Constructor Remote Code Execution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2025/cve-2025-59528/",
      "tags": [
        "cve",
        "2025",
        "critical",
        "auto-ingested"
      ],
      "x": 1309.9,
      "y": 1070
    },
    {
      "id": "CVE-2025-60710",
      "name": "CVE-2025-60710 - Elevation of Privilege in Host Process for Windows Tasks",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2025/cve-2025-60710/",
      "tags": [
        "cve",
        "2025",
        "high",
        "auto-ingested"
      ],
      "x": 587.8,
      "y": 1694.4
    },
    {
      "id": "CVE-2025-61882",
      "name": "CVE-2025-61882: Zero-Day RCE in Oracle E-Business Suite (BI Publisher / Concurrent Processing)",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2025/cve-2025-61882/",
      "tags": [
        "cve",
        "2025",
        "critical",
        "auto-ingested"
      ],
      "x": 1395.2,
      "y": 267.2
    },
    {
      "id": "CVE-2025-64504",
      "name": "CVE-2025-64504: Langfuse Cross-Organization Member Enumeration",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2025/cve-2025-64504/",
      "tags": [
        "cve",
        "2025",
        "high",
        "auto-ingested"
      ],
      "x": 1627,
      "y": 42.9
    },
    {
      "id": "CVE-2025-8088",
      "name": "CVE-2025-8088: WinRAR Path Traversal Vulnerability",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2025/cve-2025-8088/",
      "tags": [
        "cve",
        "2025",
        "high",
        "auto-ingested"
      ],
      "x": 511,
      "y": 1546.9
    },
    {
      "id": "CVE-2026-0257",
      "name": "CVE-2026-0257: Critical Authentication Bypass in Palo Alto Networks GlobalProtect Portal",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-0257/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 894.4,
      "y": 183.1
    },
    {
      "id": "CVE-2026-0300",
      "name": "CVE-2026-0300: Unauthenticated Stack Buffer Overflow to Root RCE in Palo Alto Networks PAN-OS User-ID Captive Portal",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-0300/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 954.4,
      "y": 635
    },
    {
      "id": "CVE-2026-0770",
      "name": "CVE-2026-0770: Unauthenticated Remote Code Execution in Langflow via Code Validation Sandbox Escape",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-0770/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1532.8,
      "y": 781
    },
    {
      "id": "CVE-2026-0915",
      "name": "CVE-2026-0915: glibc getnetbyaddr Stack Memory Leak to DNS Resolver",
      "type": "vulnerability",
      "severity": "MEDIUM",
      "cvss_score": 6.5,
      "doc_url": "/cve/2026/cve-2026-0915/",
      "tags": [
        "cve",
        "2026",
        "medium",
        "auto-ingested"
      ],
      "x": 463.1,
      "y": 1325.7
    },
    {
      "id": "PROD-GLIBC",
      "name": "GNU C Library (glibc)",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 337,
      "y": 1244.6
    },
    {
      "id": "VENDOR-GNU",
      "name": "GNU Project / FSF",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 277,
      "y": 1154.6
    },
    {
      "id": "CVE-2026-11393",
      "name": "CVE-2026-11393: AWS Bedrock AgentCore Multi-Agent Collaboration Poisoning via Triple-Quote Injection RCE",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-11393/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1347.6,
      "y": 868
    },
    {
      "id": "PROD-AWS-AGENTCORE",
      "name": "AWS Bedrock AgentCore CLI",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 875.8,
      "y": 883.6
    },
    {
      "id": "CVE-2026-11940",
      "name": "CVE-2026-11940: CPython tarfile Extraction Filter Directory Traversal Bypass",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-11940/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1672.7,
      "y": 1445.5
    },
    {
      "id": "PROD-CPYTHON",
      "name": "CPython Interpreter & Standard Library",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1588.4,
      "y": 1431.6
    },
    {
      "id": "VENDOR-PYTHON",
      "name": "Python Software Foundation",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 1415.1,
      "y": 1568
    },
    {
      "id": "CVE-2026-11945",
      "name": "CVE-2026-11945: PostgreSQL Anonymizer Rules Import Function SQL Injection",
      "type": "vulnerability",
      "severity": "MEDIUM",
      "cvss_score": 6.5,
      "doc_url": "/cve/2026/cve-2026-11945/",
      "tags": [
        "cve",
        "2026",
        "medium",
        "auto-ingested"
      ],
      "x": 1470.8,
      "y": 1720.5
    },
    {
      "id": "PROD-POSTGRESQL-ANON",
      "name": "PostgreSQL Anonymizer (anon)",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1298.1,
      "y": 1692.7
    },
    {
      "id": "VENDOR-DALIBO",
      "name": "Dalibo",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 1257,
      "y": 1617.3
    },
    {
      "id": "CVE-2026-11972",
      "name": "CVE-2026-11972: CPython tarfile Streaming Mode EOF Denial of Service",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-11972/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1431.3,
      "y": 1140
    },
    {
      "id": "CVE-2026-12045",
      "name": "CVE-2026-12045: pgAdmin 4 AI Assistant Read-Only Transaction Bypass to RCE",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-12045/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1271.1,
      "y": 1269.9
    },
    {
      "id": "PROD-PGADMIN",
      "name": "pgAdmin PostgreSQL Tools",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1031.9,
      "y": 1416.9
    },
    {
      "id": "VENDOR-PGADMIN",
      "name": "pgAdmin Development Team",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 591.6,
      "y": 1268.7
    },
    {
      "id": "CVE-2026-12289",
      "name": "CVE-2026-12289: Mozilla Firefox WebRender Graphics Privilege Escalation",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-12289/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1894,
      "y": 176.6
    },
    {
      "id": "CVE-2026-12293",
      "name": "CVE-2026-12293: Mozilla Firefox WebGPU Use-After-Free Code Execution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-12293/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1229.6,
      "y": 1068.8
    },
    {
      "id": "CVE-2026-12304",
      "name": "CVE-2026-12304: Mozilla Firefox Cross-Origin Cookie Leakage & SOP Bypass",
      "type": "vulnerability",
      "severity": "MEDIUM",
      "cvss_score": 6.5,
      "doc_url": "/cve/2026/cve-2026-12304/",
      "tags": [
        "cve",
        "2026",
        "medium",
        "auto-ingested"
      ],
      "x": 1980.1,
      "y": 167.5
    },
    {
      "id": "CVE-2026-12645",
      "name": "CVE-2026-12645: Authenticated Remote Code Execution in Ivanti Neurons for ITSM via Missing Authorization in Workflow Handlers",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-12645/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1127,
      "y": 511.2
    },
    {
      "id": "PROD-IVANTI-ITSM",
      "name": "Ivanti Neurons for ITSM",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 931.4,
      "y": 294
    },
    {
      "id": "CVE-2026-12646",
      "name": "CVE-2026-12646: Authenticated Remote Code Execution in Ivanti Neurons for ITSM via Missing Authorization in Business Logic Actions",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-12646/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 799.5,
      "y": 496.5
    },
    {
      "id": "CVE-2026-12647",
      "name": "CVE-2026-12647: Authenticated Remote Code Execution in Ivanti Neurons for ITSM via Missing Authorization in Automation Engine",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-12647/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1137.2,
      "y": 370.9
    },
    {
      "id": "CVE-2026-12648",
      "name": "CVE-2026-12648: Authenticated Remote Code Execution in Ivanti Neurons for ITSM via Deserialization of Untrusted Data",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-12648/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 919.3,
      "y": 565.4
    },
    {
      "id": "CVE-2026-12650",
      "name": "CVE-2026-12650: Authenticated Remote Code Execution with Scope Elevation in Ivanti Neurons for ITSM via Insecure Deserialization",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-12650/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 687.9,
      "y": 390
    },
    {
      "id": "CVE-2026-12651",
      "name": "CVE-2026-12651: Authenticated Remote Code Execution in Ivanti Neurons for ITSM via Data Deserialization",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-12651/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1059.4,
      "y": 363.9
    },
    {
      "id": "CVE-2026-12744",
      "name": "CVE-2026-12744: Unauthenticated Remote Code Execution in Ivanti Neurons for ITSM via Insecure .NET Object Deserialization",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-12744/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 937.4,
      "y": 433.5
    },
    {
      "id": "CVE-2026-12745",
      "name": "CVE-2026-12745: Secondary Unauthenticated Remote Code Execution in Ivanti Neurons for ITSM via Deserialization Flaw",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-12745/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 966.1,
      "y": 502.5
    },
    {
      "id": "CVE-2026-1340",
      "name": "CVE-2026-1340: Unauthenticated Remote Code Execution in Ivanti EPMM",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-1340/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 520.8,
      "y": 14.9
    },
    {
      "id": "PROD-IVANTI-EPMM",
      "name": "Ivanti Endpoint Manager Mobile (EPMM)",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 584.6,
      "y": 105.1
    },
    {
      "id": "CVE-2026-14894",
      "name": "CVE-2026-14894: Super Forms WordPress Plugin Unauthenticated Arbitrary File Upload to Remote Code Execution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-14894/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1085.4,
      "y": 1787.1
    },
    {
      "id": "CVE-2026-15308",
      "name": "CVE-2026-15308: CPython HTMLParser.feed() Unterminated Markup CPU Exhaustion DoS",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-15308/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1424.9,
      "y": 1422.5
    },
    {
      "id": "CVE-2026-15718",
      "name": "CVE-2026-15718: Mozilla Firefox WebAssembly Invalid Pointer Dereference",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-15718/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1969.2,
      "y": 525.5
    },
    {
      "id": "CVE-2026-15719",
      "name": "CVE-2026-15719: Mozilla Firefox Site Isolation Bypass via DOM Navigation",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-15719/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1560.7,
      "y": 190.7
    },
    {
      "id": "CVE-2026-16356",
      "name": "CVE-2026-16356: Mozilla Firefox Use-After-Free in Accessibility APIs",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-16356/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 562.5,
      "y": 1608.9
    },
    {
      "id": "CVE-2026-18486",
      "name": "CVE-2026-18486: IBM ContextForge MCP Gateway jq Filter Credential Theft",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-18486/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 630.8,
      "y": 766.7
    },
    {
      "id": "PROD-CONTEXTFORGE",
      "name": "IBM ContextForge MCP Gateway",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 313,
      "y": 619.8
    },
    {
      "id": "VENDOR-IBM",
      "name": "IBM Corporation",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 107.9,
      "y": 700.1
    },
    {
      "id": "CVE-2026-18503",
      "name": "CVE-2026-18503: CPython csv.Sniffer Super-Linear ReDoS CPU Consumption",
      "type": "vulnerability",
      "severity": "MEDIUM",
      "cvss_score": 6.5,
      "doc_url": "/cve/2026/cve-2026-18503/",
      "tags": [
        "cve",
        "2026",
        "medium",
        "auto-ingested"
      ],
      "x": 1472.9,
      "y": 1209.7
    },
    {
      "id": "CVE-2026-18851",
      "name": "CVE-2026-18851: Authenticated Privilege Escalation to Administrator in Ivanti Endpoint Manager Mobile via Missing Authorization",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-18851/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 699.1,
      "y": 311.5
    },
    {
      "id": "CVE-2026-2006",
      "name": "CVE-2026-2006: PostgreSQL Multibyte Character Length Validation Buffer Overrun RCE",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-2006/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1751.5,
      "y": 1427.1
    },
    {
      "id": "VENDOR-POSTGRESQL",
      "name": "PostgreSQL Global Development Group",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 990.3,
      "y": 1197.9
    },
    {
      "id": "CVE-2026-2007",
      "name": "CVE-2026-2007: PostgreSQL pg_trgm Heap Buffer Overflow Pattern Corruption",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-2007/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1622.7,
      "y": 1509.2
    },
    {
      "id": "CVE-2026-20079",
      "name": "CVE-2026-20079: Cisco Secure FMC Authentication Bypass to Root RCE",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-20079/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1024.1,
      "y": 988.9
    },
    {
      "id": "PROD-CISCO-FMC",
      "name": "Cisco Secure Firewall Management Center",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1147.6,
      "y": 1196.8
    },
    {
      "id": "CVE-2026-20122",
      "name": "CVE-2026-20122: Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-20122/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 2108.3,
      "y": 577.6
    },
    {
      "id": "CVE-2026-20127",
      "name": "CVE-2026-20127: Cisco Catalyst SD-WAN Authentication Bypass",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-20127/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1572.4,
      "y": -19.6
    },
    {
      "id": "CVE-2026-20128",
      "name": "CVE-2026-20128: Cisco Catalyst SD-WAN Manager DCA Credential Disclosure and Privilege Escalation Vulnerability",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-20128/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1844.7,
      "y": 709.8
    },
    {
      "id": "CVE-2026-20133",
      "name": "CVE-2026-20133: Cisco Catalyst SD-WAN Manager Sensitive Information Disclosure Vulnerability",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-20133/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1294.7,
      "y": -236.9
    },
    {
      "id": "CVE-2026-20147",
      "name": "CVE-2026-20147: Cisco ISE Remote Code Execution Vulnerability",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-20147/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1190.6,
      "y": 1131.8
    },
    {
      "id": "CVE-2026-20180",
      "name": "CVE-2026-20180: Cisco ISE Multiple Remote Code Execution Vulnerability",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-20180/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 890.8,
      "y": 1466.3
    },
    {
      "id": "CVE-2026-20184",
      "name": "CVE-2026-20184: Cisco Webex SSO Impersonation Vulnerability",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-20184/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1904.7,
      "y": 316.6
    },
    {
      "id": "CVE-2026-20186",
      "name": "CVE-2026-20186 - Cisco ISE Command Injection",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-20186/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1060.6,
      "y": 1497.9
    },
    {
      "id": "CVE-2026-20192",
      "name": "CVE-2026-20192: Cisco Identity Services Engine Unauthenticated Authorization Bypass",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-20192/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 799.9,
      "y": 935.2
    },
    {
      "id": "CVE-2026-20205",
      "name": "CVE-2026-20205: Sensitive Information Disclosure in Splunk MCP Server",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-20205/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1272.8,
      "y": -114.9
    },
    {
      "id": "CVE-2026-20307",
      "name": "CVE-2026-20307: Cisco Identity Services Engine Insecure Java Deserialization RCE",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-20307/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 871.8,
      "y": 968.5
    },
    {
      "id": "CVE-2026-20324",
      "name": "CVE-2026-20324: Cisco Secure Firewall Management Center sftunnel OS Command Injection RCE",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-20324/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1104.9,
      "y": 995.4
    },
    {
      "id": "CVE-2026-21510",
      "name": "CVE-2026-21510: Windows Shell Security Feature Bypass",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-21510/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 419.4,
      "y": 1393.8
    },
    {
      "id": "CVE-2026-21643",
      "name": "CVE-2026-21643: Fortinet FortiClient EMS SQL Injection",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-21643/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 227.8,
      "y": 476.8
    },
    {
      "id": "CVE-2026-21962",
      "name": "CVE-2026-21962: Critical Authentication & Access Control Bypass in Oracle WebLogic Server Proxy Plug-in",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-21962/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 876,
      "y": 632.3
    },
    {
      "id": "PROD-WEBLOGIC",
      "name": "Oracle WebLogic Server",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 754.3,
      "y": 701.1
    },
    {
      "id": "VENDOR-ORACLE",
      "name": "Oracle Corporation",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 979.5,
      "y": 361.5
    },
    {
      "id": "CVE-2026-22153",
      "name": "CVE-2026-22153: FortiOS LDAP Authentication Bypass in Agentless VPN & FSSO",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-22153/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 266.6,
      "y": 403.9
    },
    {
      "id": "CVE-2026-22778",
      "name": "CVE-2026-22778: vLLM Multimodal Video URL Heap Overflow and ASLR Bypass RCE",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-22778/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1272,
      "y": 1134.2
    },
    {
      "id": "CVE-2026-22807",
      "name": "CVE-2026-22807: vLLM Dynamic Module Auto-Map Pre-Auth Remote Code Execution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-22807/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1392.5,
      "y": 1206.8
    },
    {
      "id": "CVE-2026-23246",
      "name": "CVE-2026-23246: Linux Kernel mac80211 Wi-Fi 7 MLO Reconfiguration link_id Array Index Overflow",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-23246/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 315.3,
      "y": 912.2
    },
    {
      "id": "CVE-2026-23269",
      "name": "CVE-2026-23269: Linux Kernel AppArmor DFA Policy Unpack Out-of-Bounds State Validation",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-23269/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 554,
      "y": 905.9
    },
    {
      "id": "CVE-2026-23288",
      "name": "CVE-2026-23288: Linux Kernel AMD XDNA NPU Command Ring Out-of-Bounds Write",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-23288/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 437.2,
      "y": 977.8
    },
    {
      "id": "CVE-2026-23432",
      "name": "CVE-2026-23432: Linux Kernel Hyper-V mshv Guest Memory Mapping Use-After-Free",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-23432/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 632.7,
      "y": 908.6
    },
    {
      "id": "CVE-2026-2360",
      "name": "CVE-2026-2360: PostgreSQL Anonymizer Operator search_path Superuser Privilege Escalation",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-2360/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1336.2,
      "y": 1772.4
    },
    {
      "id": "CVE-2026-23772",
      "name": "CVE-2026-23772: Privilege Escalation in Dell Storage Manager",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-23772/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 826.5,
      "y": 1817.7
    },
    {
      "id": "CVE-2026-24858",
      "name": "CVE-2026-24858: Critical FortiCloud SSO Authentication Bypass (Active In-The-Wild Exploitation)",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-24858/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 486.2,
      "y": 329.5
    },
    {
      "id": "CVE-2026-25089",
      "name": "CVE-2026-25089: Unauthenticated Remote OS Command Injection in Fortinet FortiSandbox Web Interface",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-25089/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 636.1,
      "y": 628.9
    },
    {
      "id": "CVE-2026-25724",
      "name": "CVE-2026-25724: Anthropic Claude Code Agentic Permission Bypass via Symlink Traversal",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-25724/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1630.8,
      "y": 682
    },
    {
      "id": "CVE-2026-25750",
      "name": "CVE-2026-25750: URL Parameter Injection Vulnerability in LangSmith Studio",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-25750/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 2156.7,
      "y": 915.6
    },
    {
      "id": "CVE-2026-27825",
      "name": "CVE-2026-27825: mcp-atlassian Confluence Download Attachment Arbitrary File Write RCE",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-27825/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1979.9,
      "y": 1078.1
    },
    {
      "id": "CVE-2026-27826",
      "name": "CVE-2026-27826: mcp-atlassian Unvalidated Header SSRF to Cloud Instance Metadata",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-27826/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1766.6,
      "y": 1274.9
    },
    {
      "id": "CVE-2026-28326",
      "name": "CVE-2026-28326: SolarWinds Access Rights Manager Hard-coded Key Remote Code Execution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-28326/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 678.5,
      "y": 562.6
    },
    {
      "id": "PROD-SOLARWINDS-ARM",
      "name": "SolarWinds Access Rights Manager",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 531.8,
      "y": 400.8
    },
    {
      "id": "VENDOR-SOLARWINDS",
      "name": "SolarWinds",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 398.5,
      "y": 469.3
    },
    {
      "id": "CVE-2026-3055",
      "name": "CVE-2026-3055: NetScaler Memory Overread (SAML IdP)",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-3055/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 337.2,
      "y": 185.2
    },
    {
      "id": "CVE-2026-30615",
      "name": "CVE-2026-30615: Windsurf MCP Prompt Injection RCE",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-30615/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 2088.9,
      "y": 869.8
    },
    {
      "id": "CVE-2026-30617",
      "name": "CVE-2026-30617: Remote Code Execution in LangChain-ChatChat",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-30617/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1924.5,
      "y": 1238.7
    },
    {
      "id": "CVE-2026-30623",
      "name": "CVE-2026-30623: LiteLLM Authenticated MCP RCE",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-30623/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1730.6,
      "y": 587.2
    },
    {
      "id": "CVE-2026-30624",
      "name": "CVE-2026-30624: Agent Zero External MCP Servers Command Injection",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-30624/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1232.8,
      "y": -185
    },
    {
      "id": "CVE-2026-31223",
      "name": "CVE-2026-31223: Snorkel AI BaseLabeler pickle.load Insecure Deserialization RCE",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-31223/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1228.2,
      "y": 1333.6
    },
    {
      "id": "PROD-SNORKEL",
      "name": "Snorkel Programmatic Labeling",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 988.9,
      "y": 1339.4
    },
    {
      "id": "VENDOR-SNORKEL",
      "name": "Snorkel AI",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 655.6,
      "y": 1063.9
    },
    {
      "id": "CVE-2026-31368",
      "name": "CVE-2026-31368: Database Initialization Failure",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-31368/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1513.6,
      "y": 124.9
    },
    {
      "id": "CVE-2026-31377",
      "name": "CVE-2026-31377: Apache Doris Frontend Meta Service Unauthenticated Access and Metadata Exfiltration",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-31377/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1456.2,
      "y": 789.7
    },
    {
      "id": "PROD-APACHE-DORIS",
      "name": "Apache Doris MPP Database",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1232.1,
      "y": 729.1
    },
    {
      "id": "CVE-2026-31430",
      "name": "CVE-2026-31430: Linux Kernel X.509 Certificate Parser Empty Extension Out-of-Bounds Read",
      "type": "vulnerability",
      "severity": "MEDIUM",
      "cvss_score": 6.5,
      "doc_url": "/cve/2026/cve-2026-31430/",
      "tags": [
        "cve",
        "2026",
        "medium",
        "auto-ingested"
      ],
      "x": 277.3,
      "y": 983.7
    },
    {
      "id": "CVE-2026-31431",
      "name": "CVE-2026-31431: Linux Kernel",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-31431/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 569.8,
      "y": 1054.7
    },
    {
      "id": "CVE-2026-31633",
      "name": "CVE-2026-31633: Linux Kernel AF_RXRPC rxgk Token Handling Integer Overflow",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-31633/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 116.7,
      "y": 989.4
    },
    {
      "id": "CVE-2026-31718",
      "name": "CVE-2026-31718: Linux Kernel ksmbd Durable File Handle Scavenger Use-After-Free",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-31718/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 591.3,
      "y": 977.5
    },
    {
      "id": "CVE-2026-31845",
      "name": "CVE-2026-31845: Reflected XSS in Rukovoditel CRM",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-31845/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1518.5,
      "y": -80
    },
    {
      "id": "CVE-2026-3195",
      "name": "CVE-2026-3195: QEMU virtio-snd PCM Input Buffer Heap Overflow (Incomplete CVE-2024-7730 Fix)",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-3195/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 251.9,
      "y": 1233.3
    },
    {
      "id": "PROD-QEMU",
      "name": "QEMU Machine Emulator",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 190.5,
      "y": 1148.4
    },
    {
      "id": "VENDOR-QEMU",
      "name": "QEMU Project",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 108.8,
      "y": 1084.9
    },
    {
      "id": "CVE-2026-32201",
      "name": "CVE-2026-32201: Microsoft SharePoint Server Spoofing Vulnerability",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-32201/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1609.9,
      "y": -253.6
    },
    {
      "id": "CVE-2026-32626",
      "name": "CVE-2026-32626: AnythingLLM Desktop Streaming Phase XSS to Electron Host RCE",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-32626/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1109.6,
      "y": 1265.8
    },
    {
      "id": "CVE-2026-32997",
      "name": "CVE-2026-32997: Arbitrary File Write in Linux-based Veeam Backup & Replication",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-32997/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1849.2,
      "y": 102
    },
    {
      "id": "CVE-2026-33017",
      "name": "CVE-2026-33017: Unauthenticated RCE in Langflow via build_public_tmp Endpoint",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-33017/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1434,
      "y": 661.4
    },
    {
      "id": "CVE-2026-33626",
      "name": "CVE-2026-33626: LMDeploy Vision-Language SSRF & Cloud Metadata Exfiltration",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-33626/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1945.6,
      "y": 616.2
    },
    {
      "id": "PROD-LMDEPLOY",
      "name": "LMDeploy Serving Engine",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1764.9,
      "y": 725.4
    },
    {
      "id": "VENDOR-OPENMMLAB",
      "name": "OpenMMLab",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 1624.5,
      "y": 930.6
    },
    {
      "id": "CVE-2026-33634",
      "name": "CVE-2026-33634: Supply Chain Compromise in Aqua Security Trivy GitHub Actions Workflow",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-33634/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1102.5,
      "y": 1130.1
    },
    {
      "id": "CVE-2026-33825",
      "name": "CVE-2026-33825: Microsoft Defender",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-33825/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 679.1,
      "y": 1756.8
    },
    {
      "id": "CVE-2026-34183",
      "name": "CVE-2026-34183: OpenSSL QUIC PATH_CHALLENGE Unbounded Memory Growth DoS",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-34183/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 753.2,
      "y": 62.3
    },
    {
      "id": "PROD-OPENSSL",
      "name": "OpenSSL Cryptographic Library",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 578.6,
      "y": 193.6
    },
    {
      "id": "VENDOR-OPENSSL",
      "name": "OpenSSL Project",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 310,
      "y": 473.4
    },
    {
      "id": "CVE-2026-34197",
      "name": "CVE-2026-34197: Apache ActiveMQ Classic Remote Code Execution",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-34197/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 960.7,
      "y": -242.5
    },
    {
      "id": "CVE-2026-34621",
      "name": "CVE-2026-34621: Acrobat Reader Prototype Pollution",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-34621/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1375.2,
      "y": -259.8
    },
    {
      "id": "CVE-2026-35188",
      "name": "CVE-2026-35188: OpenSSL Double-Free in TLS OCSP Stapling Verification",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-35188/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 452.2,
      "y": 59.7
    },
    {
      "id": "CVE-2026-35385",
      "name": "CVE-2026-35385: OpenSSH scp Legacy Protocol Setuid File Installation",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-35385/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 36.2,
      "y": 1045
    },
    {
      "id": "PROD-OPENSSH",
      "name": "OpenSSH Suite",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 70,
      "y": 917.5
    },
    {
      "id": "VENDOR-OPENBSD",
      "name": "OpenBSD Foundation",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 26,
      "y": 843
    },
    {
      "id": "CVE-2026-37008",
      "name": "CVE-2026-37008: CrewAI CodeInterpreterTool Python Sandbox Escape & Host Takeover",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-37008/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1618.3,
      "y": 1649.7
    },
    {
      "id": "CVE-2026-37338",
      "name": "CVE-2026-37338: SQL Injection in SourceCodester Simple Music Cloud Community System",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-37338/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 672.3,
      "y": 698.8
    },
    {
      "id": "PROD-MYSQL",
      "name": "Oracle MySQL Server & Database Engine",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 793.6,
      "y": 775.2
    },
    {
      "id": "CVE-2026-39808",
      "name": "CVE-2026-39808: Root OS Command Injection in Fortinet FortiSandbox Administrative API",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-39808/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 760,
      "y": 565.2
    },
    {
      "id": "CVE-2026-39842",
      "name": "CVE-2026-39842: Expression Injection in OpenRemote IoT Platform",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-39842/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1031.4,
      "y": 1634.4
    },
    {
      "id": "CVE-2026-39884",
      "name": "CVE-2026-39884: Argument Injection in mcp-server-kubernetes",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-39884/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1084.3,
      "y": -261.3
    },
    {
      "id": "CVE-2026-40170",
      "name": "CVE-2026-40170: ngtcp2 stack buffer overflow",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-40170/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1448.7,
      "y": -223.5
    },
    {
      "id": "CVE-2026-40192",
      "name": "CVE-2026-40192: Pillow FITS Image GZIP Decompression Bomb Denial of Service",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-40192/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1023.1,
      "y": 1131.8
    },
    {
      "id": "PROD-PILLOW",
      "name": "Pillow Python Imaging Library",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 742.2,
      "y": 995.2
    },
    {
      "id": "VENDOR-PILLOW",
      "name": "Pillow Community",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 435.5,
      "y": 835.1
    },
    {
      "id": "CVE-2026-40227",
      "name": "CVE-2026-40227: systemd IPC API Array Null Element Assertion Crash",
      "type": "vulnerability",
      "severity": "MEDIUM",
      "cvss_score": 6.5,
      "doc_url": "/cve/2026/cve-2026-40227/",
      "tags": [
        "cve",
        "2026",
        "medium",
        "auto-ingested"
      ],
      "x": 271.4,
      "y": 545.9
    },
    {
      "id": "PROD-SYSTEMD",
      "name": "systemd System Manager",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 144.2,
      "y": 622.3
    },
    {
      "id": "VENDOR-SYSTEMD",
      "name": "systemd Community",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 84.7,
      "y": 559.9
    },
    {
      "id": "CVE-2026-40933",
      "name": "CVE-2026-40933: Flowise MCP Adapter Stdio Command Injection RCE",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-40933/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 843.9,
      "y": 1177.9
    },
    {
      "id": "CVE-2026-41035",
      "name": "CVE-2026-41035: rsync receiver use-after-free",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-41035/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1529.3,
      "y": -238.7
    },
    {
      "id": "CVE-2026-41254",
      "name": "CVE-2026-41254: Integer Overflow in Little CMS (lcms2) Affecting Java 2D Color Management",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-41254/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 514.5,
      "y": 693.8
    },
    {
      "id": "PROD-LCMS2",
      "name": "Little CMS (lcms2)",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 356.4,
      "y": 544.2
    },
    {
      "id": "VENDOR-LCMS",
      "name": "Little CMS Project",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 306.8,
      "y": 331.6
    },
    {
      "id": "CVE-2026-41703",
      "name": "CVE-2026-41703: VMware ESXi Out-of-Bounds Read in VM Lifecycle Handling",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-41703/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1733.1,
      "y": -238.5
    },
    {
      "id": "CVE-2026-41709",
      "name": "CVE-2026-41709: VMware ESXi Insufficient Logging & Forensic Evasion",
      "type": "vulnerability",
      "severity": "MEDIUM",
      "cvss_score": 6.5,
      "doc_url": "/cve/2026/cve-2026-41709/",
      "tags": [
        "cve",
        "2026",
        "medium",
        "auto-ingested"
      ],
      "x": 1587.1,
      "y": -175.3
    },
    {
      "id": "CVE-2026-41843",
      "name": "CVE-2026-41843: Path Traversal in Spring Framework Versioned Static Resource Resolution",
      "type": "vulnerability",
      "severity": "MEDIUM",
      "cvss_score": 6.5,
      "doc_url": "/cve/2026/cve-2026-41843/",
      "tags": [
        "cve",
        "2026",
        "medium",
        "auto-ingested"
      ],
      "x": 644.1,
      "y": 489.4
    },
    {
      "id": "PROD-SPRING-FRAMEWORK",
      "name": "Spring Framework",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 632.3,
      "y": 262.3
    },
    {
      "id": "VENDOR-VMWARE-SPRING",
      "name": "Broadcom / Spring",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 438.4,
      "y": 262.3
    },
    {
      "id": "CVE-2026-41849",
      "name": "CVE-2026-41849: Integer Overflow Denial of Service via SpEL String Multiplication in Spring Framework",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-41849/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 761.2,
      "y": 359.7
    },
    {
      "id": "CVE-2026-42016",
      "name": "CVE-2026-42016: Privilege Escalation in JFrog Artifactory via Token Scope Authorization Validation Bypass",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-42016/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1353.7,
      "y": -181.3
    },
    {
      "id": "PROD-ARTIFACTORY",
      "name": "JFrog Artifactory",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1209.4,
      "y": -266.8
    },
    {
      "id": "VENDOR-JFROG",
      "name": "JFrog Ltd",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 1030.5,
      "y": -198.3
    },
    {
      "id": "CVE-2026-42018",
      "name": "CVE-2026-42018: Anonymous User Token Generation Exposure in JFrog Artifactory",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-42018/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1313.3,
      "y": -316
    },
    {
      "id": "CVE-2026-42208",
      "name": "CVE-2026-42208: LiteLLM Proxy API Key SQL Injection",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-42208/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1903.2,
      "y": 478.5
    },
    {
      "id": "CVE-2026-42249",
      "name": "CVE-2026-42249: Ollama Windows Auto-Updater HTTP Header Path Traversal RCE",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-42249/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 746.3,
      "y": 1802.6
    },
    {
      "id": "CVE-2026-42271",
      "name": "CVE-2026-42271: Unauthenticated Remote OS Command Injection in LiteLLM Proxy Test Endpoints",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-42271/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1546.5,
      "y": 923.6
    },
    {
      "id": "CVE-2026-43114",
      "name": "CVE-2026-43114: Linux Kernel Netfilter nft_set_pipapo AVX2 Lookup Expiry Bypass",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-43114/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 269.9,
      "y": 1064.5
    },
    {
      "id": "CVE-2026-43133",
      "name": "CVE-2026-43133: Linux Kernel KVM nSVM VMLOAD/VMSAVE Emulation Hypervisor Escape",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-43133/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 357.2,
      "y": 981.3
    },
    {
      "id": "CVE-2026-43386",
      "name": "CVE-2026-43386: Linux Kernel Realtek rtl8723bs Wi-Fi WMM IE Parsing Out-of-Bounds Read",
      "type": "vulnerability",
      "severity": "MEDIUM",
      "cvss_score": 6.5,
      "doc_url": "/cve/2026/cve-2026-43386/",
      "tags": [
        "cve",
        "2026",
        "medium",
        "auto-ingested"
      ],
      "x": 188.5,
      "y": 1062.5
    },
    {
      "id": "CVE-2026-4372",
      "name": "CVE-2026-4372: Hugging Face Transformers Configuration Injection RCE via Attention Implementation",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-4372/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1114,
      "y": 647.5
    },
    {
      "id": "PROD-HF-TRANSFORMERS",
      "name": "Hugging Face Transformers Library",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 855.1,
      "y": 255.5
    },
    {
      "id": "VENDOR-HUGGINGFACE",
      "name": "Hugging Face Inc.",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 659.9,
      "y": 170.3
    },
    {
      "id": "CVE-2026-44963",
      "name": "CVE-2026-44963: Remote Code Execution in Veeam Backup & Replication via .NET Remoting ObjRef Deserialization",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-44963/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1599.1,
      "y": -95.2
    },
    {
      "id": "CVE-2026-4519",
      "name": "CVE-2026-4519: CPython webbrowser.open() Leading Dash Argument Injection",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-4519/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1503.9,
      "y": 996.9
    },
    {
      "id": "CVE-2026-45321",
      "name": "CVE-2026-45321: Large-Scale Supply Chain Compromise Across 42 Packages in the TanStack NPM Ecosystem",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-45321/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1400.8,
      "y": 598.2
    },
    {
      "id": "VENDOR-GITLAB",
      "name": "GitLab Inc.",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 1417.1,
      "y": 470.3
    },
    {
      "id": "CVE-2026-46850",
      "name": "CVE-2026-46850: Remote Code Execution via Code Injection in MySQL Shell for VS Code",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-46850/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1095.4,
      "y": 437.3
    },
    {
      "id": "PROD-MYSQL-SHELL",
      "name": "Oracle MySQL Shell & VS Code Extension",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1098.7,
      "y": 291.1
    },
    {
      "id": "CVE-2026-46860",
      "name": "CVE-2026-46860: Unauthenticated Remote Administrative Takeover in MySQL Router",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-46860/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1349.6,
      "y": 112.3
    },
    {
      "id": "PROD-MYSQL-ROUTER",
      "name": "Oracle MySQL Router",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1062.8,
      "y": 0.7
    },
    {
      "id": "CVE-2026-46861",
      "name": "CVE-2026-46861: Privilege Escalation and Cluster Takeover in MySQL NDB Operator",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-46861/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1174.2,
      "y": -130.3
    },
    {
      "id": "PROD-MYSQL-NDB",
      "name": "Oracle MySQL NDB Cluster",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 996.2,
      "y": 59.2
    },
    {
      "id": "CVE-2026-46862",
      "name": "CVE-2026-46862: Unauthenticated Remote Denial of Service via TLS in MySQL Router",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-46862/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 982.7,
      "y": -25.1
    },
    {
      "id": "CVE-2026-46870",
      "name": "CVE-2026-46870: Access Control Bypass and Workstation Compromise in MySQL Shell for VS Code",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-46870/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1268.9,
      "y": 98.6
    },
    {
      "id": "CVE-2026-47057",
      "name": "CVE-2026-47057: Remote Denial of Service in Oracle Java SE Scripting Engine",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-47057/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1238,
      "y": 239.3
    },
    {
      "id": "PROD-ORACLE-JAVA",
      "name": "Oracle Java SE & OpenJDK Runtime",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1054.7,
      "y": 214.2
    },
    {
      "id": "CVE-2026-47058",
      "name": "CVE-2026-47058: Out-of-Bounds Memory Corruption in Java Scripting DataView Implementation",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-47058/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 839.8,
      "y": 563.5
    },
    {
      "id": "CVE-2026-47063",
      "name": "CVE-2026-47063: Existential Forgery and JAR Verification Bypass in Oracle Java SE Libraries",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-47063/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 832,
      "y": 333.6
    },
    {
      "id": "CVE-2026-47876",
      "name": "CVE-2026-47876: VMware ESXi VMXNET3 Out-of-Bounds Write Virtual Machine Escape",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-47876/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1812.6,
      "y": -46.5
    },
    {
      "id": "CVE-2026-48710",
      "name": "CVE-2026-48710: Starlette & FastAPI BadHost Path Smuggling & Auth Bypass",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-48710/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 2163.1,
      "y": 637.5
    },
    {
      "id": "PROD-STARLETTE",
      "name": "Starlette / FastAPI ASGI Framework",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 2024.7,
      "y": 590.6
    },
    {
      "id": "VENDOR-KLUDEX",
      "name": "Kludex",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 1748.2,
      "y": 508
    },
    {
      "id": "CVE-2026-48746",
      "name": "CVE-2026-48746: vLLM OpenAI API Authentication Middleware Bypass via ASGI Request Handling Inconsistency",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-48746/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1310.6,
      "y": 935.2
    },
    {
      "id": "CVE-2026-49179",
      "name": "CVE-2026-49179: Windows Active Directory Domain Services Remote Code Execution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-49179/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 521.9,
      "y": 1750.7
    },
    {
      "id": "CVE-2026-49869",
      "name": "CVE-2026-49869: Authentication Bypass to Remote Code Execution in Kestra OSS via Path Suffix Whitelisting",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-49869/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1313.4,
      "y": 1203.7
    },
    {
      "id": "CVE-2026-5002",
      "name": "CVE-2026-5002: Critical Prompt Injection in localGPT",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-5002/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1058.7,
      "y": 1710.2
    },
    {
      "id": "CVE-2026-5027",
      "name": "CVE-2026-5027: Langflow Multipart Form Files Path Traversal and Arbitrary File Overwrite RCE",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-5027/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1481.4,
      "y": 719.9
    },
    {
      "id": "CVE-2026-50346",
      "name": "CVE-2026-50346: Windows Netlogon RPC Runtime Elevation of Privilege",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-50346/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 599.7,
      "y": 1775.2
    },
    {
      "id": "CVE-2026-50391",
      "name": "CVE-2026-50391: Windows Group Policy Client Elevation of Privilege",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-50391/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 378.1,
      "y": 1606.8
    },
    {
      "id": "CVE-2026-50481",
      "name": "CVE-2026-50481: Azure Active Directory Immutable Data Manipulation Privilege Escalation",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-50481/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 430.5,
      "y": 1684.1
    },
    {
      "id": "CVE-2026-50500",
      "name": "CVE-2026-50500: Windows Netlogon Secure Channel Use-After-Free Elevation of Privilege",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-50500/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 510.7,
      "y": 1670.4
    },
    {
      "id": "CVE-2026-50522",
      "name": "CVE-2026-50522: Remote Code Execution in Microsoft SharePoint Server via .NET Deserialization",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-50522/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 889.8,
      "y": 1045.9
    },
    {
      "id": "CVE-2026-5059",
      "name": "CVE-2026-5059: aws-mcp-server RCE",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-5059/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 701.3,
      "y": 1358.3
    },
    {
      "id": "CVE-2026-52924",
      "name": "CVE-2026-52924: Linux Kernel SCTP Stale COOKIE-ECHO Outqueue Purge Use-After-Free",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-52924/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 197.3,
      "y": 981.6
    },
    {
      "id": "CVE-2026-52933",
      "name": "CVE-2026-52933: Linux Kernel io_uring/poll Signed Comparison Ownership Privilege Escalation",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-52933/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 401.5,
      "y": 1048.2
    },
    {
      "id": "CVE-2026-53266",
      "name": "CVE-2026-53266: Linux Kernel Netfilter ebtables SNAT ARP Out-of-Bounds Write & Privilege Escalation",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-53266/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 192.4,
      "y": 840
    },
    {
      "id": "CVE-2026-5364",
      "name": "CVE-2026-5364: Arbitrary File Upload in Drag and Drop File Upload for Contact Form 7",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-5364/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 925.1,
      "y": 1755.6
    },
    {
      "id": "CVE-2026-54236",
      "name": "CVE-2026-54236: vLLM Multimodal Image Processing Unhandled Exception Memory Pointer Disclosure",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-54236/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1272.9,
      "y": 871
    },
    {
      "id": "CVE-2026-54291",
      "name": "CVE-2026-54291: pgjdbc Silent SCRAM Channel-Binding Authentication Downgrade",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-54291/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1349.8,
      "y": 1273.8
    },
    {
      "id": "PROD-PGJDBC",
      "name": "PostgreSQL JDBC Driver",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1072.7,
      "y": 923.4
    },
    {
      "id": "VENDOR-PGJDBC",
      "name": "PostgreSQL JDBC Project",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 716.5,
      "y": 631.1
    },
    {
      "id": "CVE-2026-55040",
      "name": "CVE-2026-55040: Authentication Bypass and Privilege Escalation in Microsoft SharePoint Server via JWT Signature Spoofing",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-55040/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 461.3,
      "y": 1468.7
    },
    {
      "id": "CVE-2026-55653",
      "name": "CVE-2026-55653: OpenSSH DH-GEX Client Path Double-Free in FIPS Known-Group Validation",
      "type": "vulnerability",
      "severity": "MEDIUM",
      "cvss_score": 6.5,
      "doc_url": "/cve/2026/cve-2026-55653/",
      "tags": [
        "cve",
        "2026",
        "medium",
        "auto-ingested"
      ],
      "x": 2.7,
      "y": 970.2
    },
    {
      "id": "CVE-2026-57967",
      "name": "CVE-2026-57967: Unauthenticated Remote Session Hijacking via CORE Protocol Reattachment in Apache ActiveMQ Artemis",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-57967/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 845.4,
      "y": 1739.1
    },
    {
      "id": "CVE-2026-58070",
      "name": "CVE-2026-58070: Cleartext Guest OS Credentials Disclosure in Veeam Backup Support Logs",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-58070/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1826.8,
      "y": 326.5
    },
    {
      "id": "CVE-2026-5809",
      "name": "CVE-2026-5809: Arbitrary File Deletion in wpForo Forum",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-5809/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 978.4,
      "y": 1694.3
    },
    {
      "id": "CVE-2026-58480",
      "name": "CVE-2026-58480: Blocksy Companion Pro Unauthenticated Arbitrary File Upload Remote Code Execution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-58480/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 2079.9,
      "y": 435.3
    },
    {
      "id": "PROD-WP-BLOCKSY",
      "name": "Blocksy Companion Pro",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1919.5,
      "y": 398.3
    },
    {
      "id": "VENDOR-CREATIVETHEMES",
      "name": "Creative Themes",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 1748.3,
      "y": 317.3
    },
    {
      "id": "CVE-2026-58599",
      "name": "CVE-2026-58599: Microsoft HEVC Video Extensions Heap Buffer Overflow Remote Code Execution",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-58599/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 459.4,
      "y": 1608.1
    },
    {
      "id": "CVE-2026-58644",
      "name": "CVE-2026-58644: Remote Code Execution in Microsoft SharePoint Server via Workflow Event Receiver Deserialization",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-58644/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 766.2,
      "y": 1158.6
    },
    {
      "id": "CVE-2026-58704",
      "name": "CVE-2026-58704: Zero-Click Adjacent Privilege Escalation in Google Pixel Cellular Modem",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-58704/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 191,
      "y": 551
    },
    {
      "id": "CVE-2026-59310",
      "name": "CVE-2026-59310: Remote Code Execution in VMware vCenter Server via Syslog Service Directory Traversal",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-59310/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1536.6,
      "y": 1648
    },
    {
      "id": "CVE-2026-5966",
      "name": "CVE-2026-5966: Arbitrary File Deletion in ThreatSonar Anti-Ransomware",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-5966/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 380.6,
      "y": 1465.1
    },
    {
      "id": "CVE-2026-59837",
      "name": "CVE-2026-59837: Stack-Based Buffer Overflow in FortiOS Log Report Generation",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-59837/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 751.2,
      "y": 434.2
    },
    {
      "id": "CVE-2026-59839",
      "name": "CVE-2026-59839: FortiOS CLI Path Traversal Arbitrary File Deletion & Code Execution",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-59839/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 774.1,
      "y": 281.9
    },
    {
      "id": "CVE-2026-59840",
      "name": "CVE-2026-59840: Buffer Over-read in Fortinet FortiOS and FortiProxy",
      "type": "vulnerability",
      "severity": "MEDIUM",
      "cvss_score": 6.5,
      "doc_url": "/cve/2026/cve-2026-59840/",
      "tags": [
        "cve",
        "2026",
        "medium",
        "auto-ingested"
      ],
      "x": 545.5,
      "y": 273
    },
    {
      "id": "CVE-2026-60137",
      "name": "CVE-2026-60137: WordPress Core Facilitated SQL Injection via WP_Query author__not_in",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-60137/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1005.1,
      "y": 1771.4
    },
    {
      "id": "CVE-2026-60163",
      "name": "CVE-2026-60163: Local Privilege Escalation and Takeover in MySQL Group Replication",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-60163/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1000.1,
      "y": 913.4
    },
    {
      "id": "CVE-2026-60316",
      "name": "CVE-2026-60316: Server and Cluster Takeover via MySQL X Plugin Protocol",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-60316/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 434.9,
      "y": 692.3
    },
    {
      "id": "CVE-2026-60592",
      "name": "CVE-2026-60592: Unauthenticated Network Denial of Service and Data Tampering in NDB Operator",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-60592/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 832.7,
      "y": 51.7
    },
    {
      "id": "CVE-2026-60623",
      "name": "CVE-2026-60623: Data Tampering and Information Disclosure in MySQL Connector/J",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-60623/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1172,
      "y": 444.6
    },
    {
      "id": "PROD-MYSQL-CONNECTOR",
      "name": "Oracle MySQL Connector/J",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 898.5,
      "y": 369.9
    },
    {
      "id": "CVE-2026-6100",
      "name": "CVE-2026-6100: CPython Decompressor Use-After-Free under Memory Pressure",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-6100/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1496.5,
      "y": 1577.2
    },
    {
      "id": "CVE-2026-6105",
      "name": "CVE-2026-6105: Improper Authorization in perfree go-fastdfs-web",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-6105/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1667.4,
      "y": -190
    },
    {
      "id": "CVE-2026-61094",
      "name": "CVE-2026-61094: System Compromise via Binary Log Replication Subsystem in MySQL Server",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-61094/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 987.2,
      "y": 703.9
    },
    {
      "id": "CVE-2026-61308",
      "name": "CVE-2026-61308: Information Disclosure Across Boundaries via HTTP Networking in Java SE",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-61308/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 820.7,
      "y": 131.5
    },
    {
      "id": "CVE-2026-6138",
      "name": "CVE-2026-6138: Critical Remote OS Command Injection in Totolink A7100RU",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-6138/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1893,
      "y": -58.3
    },
    {
      "id": "CVE-2026-62574",
      "name": "CVE-2026-62574: Local Privilege Escalation via Install Component in Oracle Java SE and GraalVM",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-62574/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1039.9,
      "y": -81.5
    },
    {
      "id": "CVE-2026-62752",
      "name": "CVE-2026-62752: Windows Kerberos Security Authority Elevation of Privilege",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-62752/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 595.4,
      "y": 1533.9
    },
    {
      "id": "CVE-2026-6276",
      "name": "CVE-2026-6276: curl Stale Custom Host Header Cookie Leak",
      "type": "vulnerability",
      "severity": "MEDIUM",
      "cvss_score": 6.5,
      "doc_url": "/cve/2026/cve-2026-6276/",
      "tags": [
        "cve",
        "2026",
        "medium",
        "auto-ingested"
      ],
      "x": 150.7,
      "y": 770.2
    },
    {
      "id": "PROD-SUDO",
      "name": "Sudo Privilege Manager",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 47,
      "y": 638.7
    },
    {
      "id": "VENDOR-SUDO",
      "name": "Sudo Project",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 1,
      "y": 562.8
    },
    {
      "id": "CVE-2026-62785",
      "name": "CVE-2026-62785: Windows LDAP Service Remote Code Execution on Domain Controllers",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-62785/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 420.2,
      "y": 1537.2
    },
    {
      "id": "CVE-2026-62818",
      "name": "CVE-2026-62818: Windows Active Directory Certificate Services (AD CS) Remote Code Execution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-62818/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 338.9,
      "y": 1535
    },
    {
      "id": "CVE-2026-63030",
      "name": "CVE-2026-63030: WordPress Core REST API Batch Route Confusion to Remote Code Execution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-63030/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 713.7,
      "y": 1571.6
    },
    {
      "id": "CVE-2026-63077",
      "name": "CVE-2026-63077: Authentication Bypass to Remote Code Execution in JetBrains TeamCity via Agent Polling Protocol",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-63077/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 816,
      "y": 1019.9
    },
    {
      "id": "CVE-2026-64268",
      "name": "CVE-2026-64268: Linux Kernel Soft-iWARP (siw) RDMA Read Response Out-of-Bounds Write",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-64268/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 111.6,
      "y": 842.4
    },
    {
      "id": "CVE-2026-6443",
      "name": "CVE-2026-6443: WordPress Essential Plugin Supply Chain Attack",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-6443/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 792.2,
      "y": 1586.8
    },
    {
      "id": "CVE-2026-6473",
      "name": "CVE-2026-6473: PostgreSQL Server Memory Allocation Integer Wraparound OOB Write",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-6473/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1447.5,
      "y": 1642.5
    },
    {
      "id": "CVE-2026-6476",
      "name": "CVE-2026-6476: PostgreSQL pg_createsubscriber Subscription Name SQL Injection",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-6476/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1549,
      "y": 1358.5
    },
    {
      "id": "CVE-2026-64849",
      "name": "CVE-2026-64849: Critical Server-Side Request Forgery (SSRF) in MLflow Webhook Notifications",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-64849/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1470.1,
      "y": 1354.1
    },
    {
      "id": "CVE-2026-6490",
      "name": "CVE-2026-6490: QueryMine SMS SQL Injection",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-6490/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 665.4,
      "y": 982.3
    },
    {
      "id": "CVE-2026-6507",
      "name": "CVE-2026-6507: dnsmasq Out-of-Bounds Write",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-6507/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1760,
      "y": -123.7
    },
    {
      "id": "CVE-2026-65182",
      "name": "CVE-2026-65182: Security Constraint Order Bypass and Authorization Failure in Apache Tomcat",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-65182/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1230.2,
      "y": 1540.9
    },
    {
      "id": "CVE-2026-65381",
      "name": "CVE-2026-65381: Apple macOS Entitlement Verification Sandbox Escape & Local Privilege Escalation",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-65381/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1492.3,
      "y": -3.1
    },
    {
      "id": "PROD-APPLE-MACOS",
      "name": "Apple macOS Operating System",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1291.9,
      "y": 175.7
    },
    {
      "id": "CVE-2026-65400",
      "name": "CVE-2026-65400: Unauthenticated Remote Desktop Takeover in Apple macOS Screen Sharing",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-65400/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1254.1,
      "y": 451.7
    },
    {
      "id": "CVE-2026-6560",
      "name": "CVE-2026-6560: H3C Magic B0 Router Buffer Overflow",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-6560/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 2036.2,
      "y": 108.9
    },
    {
      "id": "CVE-2026-65777",
      "name": "CVE-2026-65777: Active Directory Cross-Realm Security Feature Bypass",
      "type": "vulnerability",
      "severity": "MEDIUM",
      "cvss_score": 6.5,
      "doc_url": "/cve/2026/cve-2026-65777/",
      "tags": [
        "cve",
        "2026",
        "medium",
        "auto-ingested"
      ],
      "x": 339.3,
      "y": 1392.7
    },
    {
      "id": "CVE-2026-65927",
      "name": "CVE-2026-65927: Access Control Bypass via RewriteValve Off-By-One Error in Apache Tomcat",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-65927/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 685.9,
      "y": 1141.4
    },
    {
      "id": "CVE-2026-6595",
      "name": "CVE-2026-6595: SQL Injection in School Management System",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-6595/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1971.2,
      "y": -35.5
    },
    {
      "id": "CVE-2026-6596",
      "name": "CVE-2026-6596: Arbitrary File Upload in Langflow",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-6596/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1502.7,
      "y": 642.6
    },
    {
      "id": "CVE-2026-6602",
      "name": "CVE-2026-6602: Arbitrary File Upload in rickxy Hospital Management System",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-6602/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1996.1,
      "y": 437.4
    },
    {
      "id": "CVE-2026-6603",
      "name": "CVE-2026-6603: Remote Code Execution in AgentScope Framework",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-6603/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1579.1,
      "y": 1578.1
    },
    {
      "id": "CVE-2026-6604",
      "name": "CVE-2026-6604: AgentScope Blind SSRF via Prompt Injection",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-6604/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1789.7,
      "y": 1540.7
    },
    {
      "id": "CVE-2026-6605",
      "name": "CVE-2026-6605: AgentScope SSRF Vulnerability",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-6605/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1712,
      "y": 1516.2
    },
    {
      "id": "CVE-2026-6615",
      "name": "CVE-2026-6615: TransformerOptimus SuperAGI Path Traversal",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-6615/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1173.6,
      "y": 1598.6
    },
    {
      "id": "CVE-2026-6638",
      "name": "CVE-2026-6638: PostgreSQL REFRESH PUBLICATION Table Name SQL Injection",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-6638/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1681.3,
      "y": 1285.4
    },
    {
      "id": "CVE-2026-67593",
      "name": "CVE-2026-67593: Apache ActiveMQ Artemis Pre-Authentication Queue Deletion via Openwire",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-67593/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 2033.5,
      "y": -88.4
    },
    {
      "id": "CVE-2026-68200",
      "name": "CVE-2026-68200: Linux Kernel ALSA Timer User Trigger Concurrent ioctl Use-After-Free",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-68200/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 231.7,
      "y": 765.7
    },
    {
      "id": "CVE-2026-69518",
      "name": "CVE-2026-69518: Windows Remote Desktop Clipboard Virtual Channel Remote Code Execution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-69518/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 299.2,
      "y": 1463.5
    },
    {
      "id": "CVE-2026-69579",
      "name": "CVE-2026-69579: Windows Message Queuing (MSMQ) Unauthenticated Remote Code Execution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-69579/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 300.5,
      "y": 1321.5
    },
    {
      "id": "CVE-2026-69595",
      "name": "CVE-2026-69595: Windows Services for NFS ONCRPC XDR Driver Remote Code Execution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-69595/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 382.2,
      "y": 1320.9
    },
    {
      "id": "CVE-2026-69603",
      "name": "CVE-2026-69603: Windows Hyper-V Guest-to-Host Escape Remote Code Execution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-69603/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 510.4,
      "y": 1260.6
    },
    {
      "id": "CVE-2026-69649",
      "name": "CVE-2026-69649: Windows Raw Image Extension Thumbnail Preview Remote Code Execution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-69649/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 427.4,
      "y": 1252.7
    },
    {
      "id": "CVE-2026-69676",
      "name": "CVE-2026-69676: Windows Kerberos Authentication Bypass & Remote Code Execution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-69676/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 576.8,
      "y": 1405.9
    },
    {
      "id": "CVE-2026-69730",
      "name": "CVE-2026-69730: Windows DNS Server Unauthenticated Remote Code Execution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-69730/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 666.2,
      "y": 1677.1
    },
    {
      "id": "CVE-2026-69845",
      "name": "CVE-2026-69845: Windows DHCP Server Heap Buffer Overflow Remote Code Execution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-69845/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 671.4,
      "y": 1281.9
    },
    {
      "id": "CVE-2026-69851",
      "name": "CVE-2026-69851: Microsoft Entra ID Server-Side Request Forgery Privilege Escalation",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-69851/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 641.5,
      "y": 1600.4
    },
    {
      "id": "CVE-2026-70477",
      "name": "CVE-2026-70477: Flowise AI CSV Agent Prompt Injection to Unsandboxed Pyodide Host RCE",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-70477/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 826,
      "y": 1315.6
    },
    {
      "id": "CVE-2026-71133",
      "name": "CVE-2026-71133: Unauthenticated Identity Federation Compromise in Oracle Access Manager Authentication Engine",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-71133/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 731,
      "y": 1437.4
    },
    {
      "id": "CVE-2026-7141",
      "name": "CVE-2026-7141: vLLM KV Cache Handler RCE",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-7141/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1350.5,
      "y": 1001.5
    },
    {
      "id": "CVE-2026-7210",
      "name": "CVE-2026-7210: CPython Expat and ElementTree Insufficient Entropy Hash-Flooding DoS",
      "type": "vulnerability",
      "severity": "MEDIUM",
      "cvss_score": 6.5,
      "doc_url": "/cve/2026/cve-2026-7210/",
      "tags": [
        "cve",
        "2026",
        "medium",
        "auto-ingested"
      ],
      "x": 1513.5,
      "y": 1285.3
    },
    {
      "id": "CVE-2026-7273",
      "name": "CVE-2026-7273: Zyxel GS1900 Smart Switches CGI Stack Buffer Overflow RCE",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-7273/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1159.7,
      "y": 10.7
    },
    {
      "id": "PROD-ZYXEL-GS1900",
      "name": "Zyxel GS1900 Smart Switch",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 969.5,
      "y": -129.8
    },
    {
      "id": "VENDOR-ZYXEL",
      "name": "Zyxel Communications",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 842.8,
      "y": -110.1
    },
    {
      "id": "CVE-2026-72961",
      "name": "CVE-2026-72961: Windows Hyper-V Guest-to-Host Elevation of Privilege",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-72961/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 543.6,
      "y": 1333.1
    },
    {
      "id": "CVE-2026-72979",
      "name": "CVE-2026-72979: Windows DHCP Server Use-After-Free Remote Code Execution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-72979/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 637.2,
      "y": 1203.4
    },
    {
      "id": "CVE-2026-72982",
      "name": "CVE-2026-72982: Windows Netlogon Unauthenticated Remote Code Execution (Domain Controller Takeover)",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-72982/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 498.7,
      "y": 1398.7
    },
    {
      "id": "CVE-2026-73009",
      "name": "CVE-2026-73009: Windows Secure Socket Tunneling Protocol (SSTP) VPN Remote Code Execution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-73009/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 623.3,
      "y": 1343.4
    },
    {
      "id": "CVE-2026-73431",
      "name": "CVE-2026-73431: CIRCL Vulnerability-Lookup Stateless Token Replay Account Takeover",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-73431/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 779.3,
      "y": 1376.3
    },
    {
      "id": "CVE-2026-73498",
      "name": "CVE-2026-73498: mcp-atlassian Confluence Upload Attachment Arbitrary File Exfiltration",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-73498/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1900.4,
      "y": 1315.8
    },
    {
      "id": "CVE-2026-74512",
      "name": "CVE-2026-74512: Linux Kernel Audit Subsystem Rule Deletion Premature Free Use-After-Free",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-74512/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 154.8,
      "y": 912.1
    },
    {
      "id": "CVE-2026-74521",
      "name": "CVE-2026-74521: Linux Kernel ksmbd Binary ClientGUID strncmp Comparison Flaw",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-74521/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 447.8,
      "y": 404.3
    },
    {
      "id": "CVE-2026-74957",
      "name": "CVE-2026-74957: Mozilla Firefox Safe Browsing Mitigation Bypass",
      "type": "vulnerability",
      "severity": "MEDIUM",
      "cvss_score": 6.5,
      "doc_url": "/cve/2026/cve-2026-74957/",
      "tags": [
        "cve",
        "2026",
        "medium",
        "auto-ingested"
      ],
      "x": 2056.5,
      "y": 196.3
    },
    {
      "id": "CVE-2026-74963",
      "name": "CVE-2026-74963: Mozilla Firefox Same-Origin Policy Bypass in Cookie Engine",
      "type": "vulnerability",
      "severity": "MEDIUM",
      "cvss_score": 6.5,
      "doc_url": "/cve/2026/cve-2026-74963/",
      "tags": [
        "cve",
        "2026",
        "medium",
        "auto-ingested"
      ],
      "x": 2066,
      "y": 32.9
    },
    {
      "id": "CVE-2026-74976",
      "name": "CVE-2026-74976: Mozilla Firefox SpiderMonkey JIT Miscompilation & Type Confusion",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-74976/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 2137.7,
      "y": 377.6
    },
    {
      "id": "CVE-2026-75650",
      "name": "CVE-2026-75650: Unauthenticated Remote Code Execution via",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-75650/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 653.1,
      "y": 1418.8
    },
    {
      "id": "CVE-2026-75874",
      "name": "CVE-2026-75874: Mozilla Firefox Critical Sandbox Escape via Remote Settings Client",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-75874/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 2129.3,
      "y": 499.8
    },
    {
      "id": "CVE-2026-76460",
      "name": "CVE-2026-76460: Unauthenticated REST API Authentication Bypass in Cisco Identity Services Engine (ISE)",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-76460/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1306,
      "y": 1340.7
    },
    {
      "id": "CVE-2026-76461",
      "name": "CVE-2026-76461: Zero-Click Remote Code Execution via AsyncOS Email Parsing SQL Injection in Cisco Secure Email Gateway",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-76461/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1113.7,
      "y": 1438.4
    },
    {
      "id": "CVE-2026-76674",
      "name": "CVE-2026-76674: HPE Aruba EdgeConnect SD-WAN Buffer Overflow System Takeover",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-76674/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1302.3,
      "y": 389.6
    },
    {
      "id": "PROD-ARUBA-EDGECONNECT",
      "name": "HPE Aruba EdgeConnect SD-WAN",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1015.4,
      "y": 433
    },
    {
      "id": "VENDOR-HPE-ARUBA",
      "name": "Hewlett Packard Enterprise / Aruba",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 713.2,
      "y": 231
    },
    {
      "id": "CVE-2026-77248",
      "name": "CVE-2026-77248: mcp-atlassian Unauthenticated Arbitrary File Read and Attachment Exfiltration",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-77248/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 2009.2,
      "y": 962.8
    },
    {
      "id": "CVE-2026-77254",
      "name": "CVE-2026-77254: mcp-atlassian Missing Authentication on HTTP Transport Endpoint",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-77254/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1845.9,
      "y": 1257.6
    },
    {
      "id": "CVE-2026-77257",
      "name": "CVE-2026-77257: mcp-atlassian Jira Upload Attachment Path Traversal",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-77257/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1820.2,
      "y": 1334.7
    },
    {
      "id": "CVE-2026-77258",
      "name": "CVE-2026-77258: mcp-atlassian Confluence Attachment Handler Missing Safe Path Validation",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-77258/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 2081.6,
      "y": 654.6
    },
    {
      "id": "CVE-2026-77266",
      "name": "CVE-2026-77266: mcp-atlassian Absolute Path Traversal Bypass in Attachment Operations",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-77266/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1867.1,
      "y": 632.9
    },
    {
      "id": "CVE-2026-77267",
      "name": "CVE-2026-77267: mcp-atlassian Header-Based SSRF in Fetcher Constructor",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-77267/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 2046.8,
      "y": 1033.7
    },
    {
      "id": "CVE-2026-77268",
      "name": "CVE-2026-77268: mcp-atlassian World-Readable Permissions on OAuth Fallback Tokens",
      "type": "vulnerability",
      "severity": "MEDIUM",
      "cvss_score": 6.5,
      "doc_url": "/cve/2026/cve-2026-77268/",
      "tags": [
        "cve",
        "2026",
        "medium",
        "auto-ingested"
      ],
      "x": 2035.2,
      "y": 809
    },
    {
      "id": "CVE-2026-77269",
      "name": "CVE-2026-77269: mcp-atlassian Incomplete Fix for Path Traversal in Attachment Uploads",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-77269/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 2114.9,
      "y": 792.8
    },
    {
      "id": "CVE-2026-77270",
      "name": "CVE-2026-77270: mcp-atlassian Blind Path Trust in File Dispatcher",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-77270/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 2137.5,
      "y": 714.8
    },
    {
      "id": "CVE-2026-77272",
      "name": "CVE-2026-77272: mcp-atlassian Reflected XSS in OAuth Callback Error Response",
      "type": "vulnerability",
      "severity": "MEDIUM",
      "cvss_score": 6.5,
      "doc_url": "/cve/2026/cve-2026-77272/",
      "tags": [
        "cve",
        "2026",
        "medium",
        "auto-ingested"
      ],
      "x": 2058.3,
      "y": 732.1
    },
    {
      "id": "CVE-2026-77493",
      "name": "CVE-2026-77493: Windows Graphics Component Preview Pane Zero-Click Remote Code Execution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-77493/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 477.4,
      "y": 1188.8
    },
    {
      "id": "CVE-2026-77521",
      "name": "CVE-2026-77521: MaxKB Enterprise AI Platform SandboxShellBackend Command Injection and Container Breakout",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-77521/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1240.4,
      "y": 23.6
    },
    {
      "id": "PROD-MAXKB",
      "name": "MaxKB Enterprise AI Platform",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 968,
      "y": 142.1
    },
    {
      "id": "VENDOR-MAXKB",
      "name": "1Panel / MaxKB Community",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 614.5,
      "y": 415.3
    },
    {
      "id": "CVE-2026-7814",
      "name": "CVE-2026-7814: pgAdmin 4 Stored XSS via Database Object Names in Browser Tree",
      "type": "vulnerability",
      "severity": "MEDIUM",
      "cvss_score": 6.5,
      "doc_url": "/cve/2026/cve-2026-7814/",
      "tags": [
        "cve",
        "2026",
        "medium",
        "auto-ingested"
      ],
      "x": 1190.4,
      "y": 1265.5
    },
    {
      "id": "CVE-2026-78234",
      "name": "CVE-2026-78234: Hawtio Operator OpenShift Service CA Signing Key Theft and Cluster Takeover",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-78234/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1509.1,
      "y": 338.4
    },
    {
      "id": "PROD-CAMEL-K",
      "name": "Apache Camel K",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1184.2,
      "y": 302.4
    },
    {
      "id": "CVE-2026-78445",
      "name": "CVE-2026-78445: Windows Services for NFS Memory Corruption Remote Code Execution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-78445/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 841.7,
      "y": 1526.3
    },
    {
      "id": "CVE-2026-78509",
      "name": "CVE-2026-78509: Windows Shell Preview Pane Remote Code Execution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-78509/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 748.9,
      "y": 1299.3
    },
    {
      "id": "CVE-2026-78510",
      "name": "CVE-2026-78510: Microsoft Outlook Reading Pane Zero-Click Remote Code Execution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-78510/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 950,
      "y": 1266.3
    },
    {
      "id": "CVE-2026-80083",
      "name": "CVE-2026-80083: Windows Hyper-V Virtual Switch Guest-to-Host Remote Code Execution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-80083/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 762.3,
      "y": 1511.2
    },
    {
      "id": "CVE-2026-80351",
      "name": "CVE-2026-80351: Remote Code Execution via Dynamic Maven Configuration Eval Injection in Apache Camel K",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-80351/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1544.7,
      "y": 267.4
    },
    {
      "id": "CVE-2026-80352",
      "name": "CVE-2026-80352: Kubernetes Operator Privilege Escalation via Master Trait YAML Injection in Apache Camel K",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-80352/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1295.3,
      "y": -36.7
    },
    {
      "id": "CVE-2026-80354",
      "name": "CVE-2026-80354: Apache Camel K Operator Authorization Bypass via Maven Profiles ValueSources",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-80354/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 912.8,
      "y": -65.7
    },
    {
      "id": "CVE-2026-81963",
      "name": "CVE-2026-81963: Windows Update Stack Elevation of Privilege (Actively Exploited Zero-Day)",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-81963/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 557.7,
      "y": 1194.5
    },
    {
      "id": "CVE-2026-8206",
      "name": "CVE-2026-8206: Kirki Customizer Framework Unauthenticated Privilege Escalation to Account Takeover",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-8206/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 2058.6,
      "y": 357.9
    },
    {
      "id": "PROD-WP-KIRKI",
      "name": "Kirki Customizer Framework",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1946,
      "y": 244.3
    },
    {
      "id": "VENDOR-THEMEUM",
      "name": "Themeum",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 1723.9,
      "y": 34
    },
    {
      "id": "CVE-2026-82329",
      "name": "CVE-2026-82329: JFrog Artifactory Phantom Join-Key Authentication Bypass",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-82329/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1237.6,
      "y": -347.4
    },
    {
      "id": "CVE-2026-82331",
      "name": "CVE-2026-82331: Apache BuildStream Tar Plugin Link Resolution and Host File Overwrite",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-82331/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1379.2,
      "y": 796.7
    },
    {
      "id": "PROD-APACHE-BUILDSTREAM",
      "name": "Apache BuildStream",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1146.4,
      "y": 720.2
    },
    {
      "id": "CVE-2026-82474",
      "name": "CVE-2026-82474: Sudo Intercept Policy Bypass via execveat",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-82474/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 69.1,
      "y": 772.6
    },
    {
      "id": "CVE-2026-8293",
      "name": "CVE-2026-8293: Really Simple Security Authentication Bypass via 2FA Challenge Skip",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-8293/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 2148.9,
      "y": 215.1
    },
    {
      "id": "PROD-WP-RSS",
      "name": "Really Simple Security",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 2112.7,
      "y": 292.5
    },
    {
      "id": "VENDOR-REALLYSIMPLE",
      "name": "Really Simple Plugins",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 2027.9,
      "y": 273.4
    },
    {
      "id": "CVE-2026-83020",
      "name": "CVE-2026-83020: Unauthenticated Remote Code Execution in Oracle Platform Security for Java (OPSS)",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-83020/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 870.7,
      "y": 1254.9
    },
    {
      "id": "CVE-2026-83021",
      "name": "CVE-2026-83021: Unauthenticated Remote Code Execution in Oracle WebLogic Server Web Container",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-83021/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 476.6,
      "y": 622.8
    },
    {
      "id": "CVE-2026-83059",
      "name": "CVE-2026-83059: Unauthenticated Remote Compromise in Oracle Internet Directory (OID) LDAP Server",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-83059/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 951.5,
      "y": 1617
    },
    {
      "id": "CVE-2026-83099",
      "name": "CVE-2026-83099: Unauthenticated Remote Code Execution in Oracle Forms Services",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-83099/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1661.4,
      "y": 1580.4
    },
    {
      "id": "CVE-2026-83527",
      "name": "CVE-2026-83527: Unauthenticated Administrative Authentication Bypass in Ivanti Sentry via Alternate Routing Path",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-83527/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 790.6,
      "y": 204.6
    },
    {
      "id": "PROD-IVANTI-SENTRY",
      "name": "Ivanti Sentry",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 694.5,
      "y": 0.6
    },
    {
      "id": "CVE-2026-83548",
      "name": "CVE-2026-83548: SonicWall SMA1000 Remote Unauthenticated SSRF & Edge Gateway Takeover",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-83548/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 762.9,
      "y": -49.9
    },
    {
      "id": "PROD-SONICWALL-SMA",
      "name": "SonicWall SMA1000 Gateway",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 671.6,
      "y": 86.2
    },
    {
      "id": "VENDOR-SONICWALL",
      "name": "SonicWall",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 496.7,
      "y": 206.4
    },
    {
      "id": "CVE-2026-83549",
      "name": "CVE-2026-83549: SonicWall SMA 1000 Series AMC OS Command Injection & Chain Exploitation",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-83549/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 636.5,
      "y": -62.1
    },
    {
      "id": "CVE-2026-84285",
      "name": "CVE-2026-84285: Tuleap Enterprise ALM Workspace Export OS Command Injection",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-84285/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1160.1,
      "y": 583.8
    },
    {
      "id": "PROD-TULEAP",
      "name": "Tuleap Enterprise ALM",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 881.7,
      "y": 491.6
    },
    {
      "id": "VENDOR-ENALEAN",
      "name": "Enalean / Dassault Systèmes",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 564.8,
      "y": 480.2
    },
    {
      "id": "CVE-2026-8452",
      "name": "CVE-2026-8452: Unauthenticated Heap Buffer Overflow to Root RCE in NetScaler ADC & Gateway via SAML Canonicalization",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-8452/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 222.8,
      "y": 335
    },
    {
      "id": "CVE-2026-84779",
      "name": "CVE-2026-84779: WordPress Agentimus MCP Endpoint Broken Access Control",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-84779/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1319.1,
      "y": 251.8
    },
    {
      "id": "PROD-AGENTIMUS",
      "name": "Agentimus AI SEO & MCP Plugin",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1187.1,
      "y": 89
    },
    {
      "id": "VENDOR-AGENTIMUS",
      "name": "Agentimus",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 896,
      "y": 102
    },
    {
      "id": "CVE-2026-84869",
      "name": "CVE-2026-84869: Unrestricted File Transfer and Remote Execution in ConnectWise ScreenConnect Client via Active Session Authorization Bypass",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-84869/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1432.9,
      "y": 130.1
    },
    {
      "id": "PROD-SCREENCONNECT",
      "name": "ConnectWise ScreenConnect",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1355.6,
      "y": -96.9
    },
    {
      "id": "VENDOR-CONNECTWISE",
      "name": "ConnectWise",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 1147,
      "y": -207.5
    },
    {
      "id": "CVE-2026-84939",
      "name": "CVE-2026-84939: Path Traversal to Remote Template Injection and Code Execution via Malformed Locale in Apache FreeMarker",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-84939/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1520.2,
      "y": 568.8
    },
    {
      "id": "CVE-2026-85046",
      "name": "CVE-2026-85046: Google Chromium V8 Maglev/TurboFan Type Confusion Zero-Day",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-85046/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1929.9,
      "y": 103.9
    },
    {
      "id": "PROD-CHROMIUM",
      "name": "Google Chromium / V8 Engine",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1682.4,
      "y": 107.5
    },
    {
      "id": "VENDOR-GOOGLE",
      "name": "Google LLC",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 1427.4,
      "y": -143.8
    },
    {
      "id": "PROD-CHECKPOINT-MGMT",
      "name": "Check Point Security Management",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1377.6,
      "y": 190.1
    },
    {
      "id": "VENDOR-CHECKPOINT",
      "name": "Check Point Software",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 1127.8,
      "y": 150.9
    },
    {
      "id": "CVE-2026-85165",
      "name": "CVE-2026-85165: n8n Expression Sandbox Escape via Prototype Resolution",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-85165/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1699.6,
      "y": 251.7
    },
    {
      "id": "PROD-N8N",
      "name": "n8n Workflow Automation",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1425.4,
      "y": 48.1
    },
    {
      "id": "VENDOR-N8N",
      "name": "n8n GmbH",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 1093.2,
      "y": -143.9
    },
    {
      "id": "CVE-2026-85166",
      "name": "CVE-2026-85166: n8n Workflow Tool Sub-Workflow Credential Authorization Bypass",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-85166/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1621.3,
      "y": 262.6
    },
    {
      "id": "CVE-2026-85168",
      "name": "CVE-2026-85168: Git Node Merge-Driver & Content-Filter Command Injection in n8n",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-85168/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1652.1,
      "y": -33.1
    },
    {
      "id": "CVE-2026-85654",
      "name": "CVE-2026-85654: awslabs dynamodb-mcp-server CDK Generator Template Injection RCE",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-85654/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 384.3,
      "y": 1174.6
    },
    {
      "id": "CVE-2026-85706",
      "name": "CVE-2026-85706: Unauthenticated Path Traversal to Arbitrary File Read in GitLab CE/EE Repository Commits API",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-85706/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1322.8,
      "y": 595.5
    },
    {
      "id": "CVE-2026-85788",
      "name": "CVE-2026-85788: awslabs mysql-mcp-server Comment-Bypass Mutation Vulnerability",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-85788/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 938.8,
      "y": 769.6
    },
    {
      "id": "CVE-2026-85880",
      "name": "CVE-2026-85880: Windows ALPC Heap Buffer Overflow Privilege Escalation (Actively Exploited Zero-Day)",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-85880/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 811.2,
      "y": 1450.8
    },
    {
      "id": "CVE-2026-86218",
      "name": "CVE-2026-86218: Pre-Authentication Remote Code Execution via Static Code Injection in N-able N-central",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-86218/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1429.4,
      "y": 337.4
    },
    {
      "id": "PROD-N-CENTRAL",
      "name": "N-able N-central RMM",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1218.9,
      "y": 380
    },
    {
      "id": "VENDOR-N-ABLE",
      "name": "N-able",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 970.3,
      "y": 223.4
    },
    {
      "id": "CVE-2026-86296",
      "name": "CVE-2026-86296: D-Link DIR-822A udhcpcd Stack-Based Buffer Overflow RCE",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-86296/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 190.1,
      "y": 695.4
    },
    {
      "id": "CVE-2026-86297",
      "name": "CVE-2026-86297: D-Link DIR-605 L2TP Parser Off-by-One Buffer Overflow",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-86297/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 438.3,
      "y": 550.3
    },
    {
      "id": "CVE-2026-8643",
      "name": "CVE-2026-8643: pip console_scripts Out-of-Directory Arbitrary File Overwrite",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-8643/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1732.6,
      "y": 1348.2
    },
    {
      "id": "PROD-PIP",
      "name": "pip Python Package Installer",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1389.5,
      "y": 1069.9
    },
    {
      "id": "VENDOR-PYPA",
      "name": "Python Packaging Authority",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 1014.4,
      "y": 773.7
    },
    {
      "id": "CVE-2026-86510",
      "name": "CVE-2026-86510: D-Link DIR-822A L2TP Parser Out-of-Bounds Write RCE",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-86510/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 228.9,
      "y": 623.3
    },
    {
      "id": "CVE-2026-86711",
      "name": "CVE-2026-86711: Electerm Desktop runGlobalAsync Electron IPC Handler Arbitrary Command Execution",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-86711/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1779.3,
      "y": 244.1
    },
    {
      "id": "CVE-2026-8719",
      "name": "CVE-2026-8719: Privilege Escalation in AI Engine",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-8719/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1200,
      "y": 1675.9
    },
    {
      "id": "CVE-2026-87230",
      "name": "CVE-2026-87230: Unauthenticated Remote Financial Ledger Compromise in Oracle Hyperion Financial Management",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-87230/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 898.8,
      "y": 1678.3
    },
    {
      "id": "CVE-2026-87886",
      "name": "CVE-2026-87886: Local Privilege Escalation via Insecure Permissions in Acronis Backup Plugin for cPanel & Plesk",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-87886/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1859.4,
      "y": 250
    },
    {
      "id": "CVE-2026-87911",
      "name": "CVE-2026-87911: awslabs postgres-mcp-server SQL Parser Desync to Command Injection",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-87911/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 593.6,
      "y": 696.4
    },
    {
      "id": "CVE-2026-87983",
      "name": "CVE-2026-87983: Mistral Vibe Arbitrary File Read via Quoted Absolute Paths in Auto-Approved Commands",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-87983/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1898.9,
      "y": 768.5
    },
    {
      "id": "PROD-MISTRAL-VIBE",
      "name": "Mistral Vibe Coding Agent",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1811,
      "y": 565.1
    },
    {
      "id": "VENDOR-MISTRAL",
      "name": "Mistral AI",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 1596.3,
      "y": 118.4
    },
    {
      "id": "CVE-2026-87984",
      "name": "CVE-2026-87984: Mistral Vibe Arbitrary File Write via Shell Redirection Target Omission",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-87984/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 2009,
      "y": 884.7
    },
    {
      "id": "CVE-2026-87985",
      "name": "CVE-2026-87985: Mistral Vibe Arbitrary Remote Code Execution via ANSI-C Quoting in find -exec",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-87985/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1685.4,
      "y": 736.2
    },
    {
      "id": "CVE-2026-87986",
      "name": "CVE-2026-87986: Mistral Vibe Command Injection via Parser Syntax Error Node Bypass",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-87986/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1657,
      "y": 802.7
    },
    {
      "id": "CVE-2026-87987",
      "name": "CVE-2026-87987: Mistral Vibe Remote Code Execution via Environment Variable Assignment Stripping",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-87987/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1709.4,
      "y": 663
    },
    {
      "id": "CVE-2026-87988",
      "name": "CVE-2026-87988: Mistral Vibe Arbitrary Read/Write via Discrepancy Between Auto-Approved Commands and Path Control List",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-87988/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1922.4,
      "y": 692.1
    },
    {
      "id": "CVE-2026-87999",
      "name": "CVE-2026-87999: Open WebUI Azure WireServer Metadata Filter Bypass SSRF",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-87999/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1383.3,
      "y": 398.6
    },
    {
      "id": "PROD-OPENWEBUI",
      "name": "Open WebUI Platform",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1206.2,
      "y": 517.4
    },
    {
      "id": "VENDOR-OPENWEBUI",
      "name": "Open WebUI Community",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 1194.7,
      "y": 654.7
    },
    {
      "id": "CVE-2026-8932",
      "name": "CVE-2026-8932: curl Incomplete mTLS Configuration Matching in Connection Reuse",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-8932/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 133.5,
      "y": 493
    },
    {
      "id": "CVE-2026-9048",
      "name": "CVE-2026-9048: Slider Revolution Sensitive Information Exposure via slider.get.full",
      "type": "vulnerability",
      "severity": "MEDIUM",
      "cvss_score": 6.5,
      "doc_url": "/cve/2026/cve-2026-9048/",
      "tags": [
        "cve",
        "2026",
        "medium",
        "auto-ingested"
      ],
      "x": 2298.9,
      "y": 496.3
    },
    {
      "id": "PROD-WP-SLIDERREV",
      "name": "Slider Revolution",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 2208.3,
      "y": 533.1
    },
    {
      "id": "VENDOR-THEMEPUNCH",
      "name": "ThemePunch",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 2188.5,
      "y": 443
    },
    {
      "id": "CVE-2026-9050",
      "name": "CVE-2026-9050: Slider Revolution Missing Authorization to Arbitrary Plugin Deactivation",
      "type": "vulnerability",
      "severity": "MEDIUM",
      "cvss_score": 6.5,
      "doc_url": "/cve/2026/cve-2026-9050/",
      "tags": [
        "cve",
        "2026",
        "medium",
        "auto-ingested"
      ],
      "x": 2249.3,
      "y": 387
    },
    {
      "id": "CVE-2026-90562",
      "name": "CVE-2026-90562: Authentication Bypass and Administrative Takeover via Low Entropy Password Recovery in LangBot",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-90562/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1351.5,
      "y": 1138.6
    },
    {
      "id": "CVE-2026-90680",
      "name": "CVE-2026-90680: D-Link DIR-823G HNAP1 SetStaticRouteSettings Buffer Overflow",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-90680/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 271.7,
      "y": 836.6
    },
    {
      "id": "CVE-2026-90692",
      "name": "CVE-2026-90692: D-Link DIR-878 SetDynamicDNSIPv6Settings Stack Overflow RCE",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-90692/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 395.7,
      "y": 909.7
    },
    {
      "id": "CVE-2026-90693",
      "name": "CVE-2026-90693: D-Link DIR-878 SetWan3Settings Stack-Based Buffer Overflow RCE",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-90693/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 556.9,
      "y": 625.5
    },
    {
      "id": "CVE-2026-90699",
      "name": "CVE-2026-90699: D-Link DWR-M920 formPinManageSetup OS Command Injection",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-90699/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 523.7,
      "y": 1121.2
    },
    {
      "id": "CVE-2026-90702",
      "name": "CVE-2026-90702: D-Link DWR-M921 formDiskFormat OS Command Injection",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-90702/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 591.5,
      "y": 836.2
    },
    {
      "id": "CVE-2026-90711",
      "name": "CVE-2026-90711: Client IP Address Spoofing and Trust Boundary Bypass via IPv4-Mapped IPv6 CIDR Parsing Flaw in proxy-addr",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-90711/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1948.4,
      "y": 1008.9
    },
    {
      "id": "CVE-2026-90770",
      "name": "CVE-2026-90770: Spug Deployment Platform ping_check OS Command Injection RCE",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-90770/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1034.2,
      "y": 640.8
    },
    {
      "id": "CVE-2026-90777",
      "name": "CVE-2026-90777: Arbitrary Code Execution via Insecure torch.load Checkpoint Deserialization in ESPnet",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-90777/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1082,
      "y": 578.1
    },
    {
      "id": "PROD-CHECKPOINT",
      "name": "Check Point Security Management Server & Gaia OS",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1269.4,
      "y": 314.6
    },
    {
      "id": "CVE-2026-90894",
      "name": "CVE-2026-90894: Parallels Desktop ParaShells Virtual Machine Host Escape & LPE",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-90894/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1321.9,
      "y": 731.4
    },
    {
      "id": "PROD-PARALLELS",
      "name": "Parallels Desktop for Mac",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 1115.7,
      "y": 855.8
    },
    {
      "id": "VENDOR-PARALLELS",
      "name": "Parallels International",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 1000.4,
      "y": 572.2
    },
    {
      "id": "CVE-2026-91749",
      "name": "CVE-2026-91749: Google Chrome Web Workers Subsystem Use-After-Free Remote Code Execution",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-91749/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1679.4,
      "y": -109.5
    },
    {
      "id": "CVE-2026-91843",
      "name": "CVE-2026-91843: Check Point Security Management Server Stack Buffer Overflow RCE",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-91843/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1479,
      "y": 195.1
    },
    {
      "id": "CVE-2026-9186",
      "name": "CVE-2026-9186: Langflow Localhost Restriction Bypass Arbitrary IDE mcp.json Overwrite",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-9186/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1653.1,
      "y": 608.1
    },
    {
      "id": "CVE-2026-92574",
      "name": "CVE-2026-92574: CRI-O Container Checkpoint-Restore Destination Security Context Bypass",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-92574/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1594.9,
      "y": 553.2
    },
    {
      "id": "CVE-2026-93372",
      "name": "CVE-2026-93372: Google Chrome Android WebGL Heap Buffer Overflow GPU Sandbox Escape",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-93372/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1767.5,
      "y": 105.4
    },
    {
      "id": "CVE-2026-93616",
      "name": "CVE-2026-93616: Check Point Multi-Domain Security Management Web Service Traversal and RCE",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-93616/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1320.3,
      "y": 39.1
    },
    {
      "id": "CVE-2026-93952",
      "name": "CVE-2026-93952: Arista VeloCloud Orchestrator Authentication Bypass and Remote Code Execution",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-93952/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1150.9,
      "y": 931.4
    },
    {
      "id": "PROD-VELOCLOUD",
      "name": "Arista VeloCloud Orchestrator",
      "type": "product",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "product",
        "auto-ingested"
      ],
      "x": 739.9,
      "y": 1079.3
    },
    {
      "id": "VENDOR-ARISTA",
      "name": "Arista Networks",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 441.5,
      "y": 1117.9
    },
    {
      "id": "CVE-2026-94089",
      "name": "CVE-2026-94089: D-Link DIR-868L webfa_authentication.cgi Stack Buffer Overflow RCE",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-94089/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 552.8,
      "y": 764.8
    },
    {
      "id": "CVE-2026-94127",
      "name": "CVE-2026-94127: F5 BIG-IP APM TMM Heap-Based Buffer Overflow Remote Code Execution",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-94127/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 1285.8,
      "y": 1480.6
    },
    {
      "id": "VENDOR-F5",
      "name": "F5 Networks",
      "type": "vendor",
      "severity": null,
      "cvss_score": null,
      "doc_url": null,
      "tags": [
        "vendor",
        "auto-ingested"
      ],
      "x": 1352,
      "y": 1624.6
    },
    {
      "id": "CVE-2026-95675",
      "name": "CVE-2026-95675: D-Link DAP-1360 Web Management OS Command Injection Root RCE",
      "type": "vulnerability",
      "severity": "HIGH",
      "cvss_score": 8.5,
      "doc_url": "/cve/2026/cve-2026-95675/",
      "tags": [
        "cve",
        "2026",
        "high",
        "auto-ingested"
      ],
      "x": 605,
      "y": 1128.2
    },
    {
      "id": "CVE-2026-9586",
      "name": "CVE-2026-9586: Unauthenticated SQL Injection to Remote Code Execution in Sangoma Switchvox PBX",
      "type": "vulnerability",
      "severity": "CRITICAL",
      "cvss_score": 9.8,
      "doc_url": "/cve/2026/cve-2026-9586/",
      "tags": [
        "cve",
        "2026",
        "critical",
        "auto-ingested"
      ],
      "x": 1179.5,
      "y": 1396.3
    },
    {
      "id": "STUDY-AGENT-TO-AGENT-LATERAL-MOVEMENT",
      "name": "AI Security Research: Agent-to-Agent Lateral Movement & Swarm Compromise",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/agent-to-agent-lateral-movement/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2509.1,
      "y": 1062.7
    },
    {
      "id": "STUDY-AGENTPOISON-RED-TEAMING-LLM-MEMO",
      "name": "AgentPoison: Red-teaming LLM Agents via Memory and Knowledge Base Poisoning",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/agentpoison-red-teaming-llm-memory-rag/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 1605,
      "y": 756.1
    },
    {
      "id": "STUDY-AI-AGENT-CYBER-CAPABILITY-LADDER",
      "name": "The 10-Level AI Cyber Capability Ladder: A Living Taxonomy of Autonomous Agent Capabilities",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/ai-agent-cyber-capability-ladder/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2672.6,
      "y": 1099.6
    },
    {
      "id": "STUDY-AI-AGENT-MISCONFIGURATIONS",
      "name": "AI Security Research: Agent Misconfigurations & The Cloud Security Crisis of 2026",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/ai-agent-misconfigurations/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2722.1,
      "y": 1223
    },
    {
      "id": "STUDY-AI-CYBERSECURITY-BENCHMARKS-COMP",
      "name": "AI Cybersecurity Benchmarks Compared: CyberGym vs ExploitGym vs ExploitBench vs SRE-Bench",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/ai-cybersecurity-benchmarks-compared/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2660.7,
      "y": 1326.7
    },
    {
      "id": "STUDY-ALIGNMENT-LAYER-RLHF-JAILBREAKS",
      "name": "AI Security Research: The Alignment Layer & RLHF Failures",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/alignment-layer-rlhf-jailbreaks/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2586.1,
      "y": 1207.4
    },
    {
      "id": "STUDY-ARE-PROMPT-INJECTIONS-IMPOSSIBLE",
      "name": "Are Prompt Injections Impossible to Solve? The Contextual Integrity Impossibility Debate",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/are-prompt-injections-impossible-to-solve/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 1980.4,
      "y": 1296.4
    },
    {
      "id": "STUDY-CAN-AI-AGENTS-DEFEND-REAL-SYSTEM",
      "name": "Can AI Agents Defend Real Systems? Autonomous SOCs, Malware Analysis, and Automated Remediation",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/can-ai-agents-defend-real-systems-pillar/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2558.3,
      "y": 1445.8
    },
    {
      "id": "STUDY-CYBERSECURITY-SIMULATIONS-LLM-UT",
      "name": "Can LLMs Accelerate Cyber Ranges and Attack Simulations? Analyzing arXiv:2608.16422",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/cybersecurity-simulations-llm-utility/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2515.1,
      "y": 1306.2
    },
    {
      "id": "STUDY-DIRECT-PROMPT-INJECTION",
      "name": "AI Security Research: Direct Prompt Injection and Agentic Jailbreaks",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/direct-prompt-injection/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2466.1,
      "y": 1177.1
    },
    {
      "id": "STUDY-EXPLOITBENCH-CAPABILITY-LADDER-A",
      "name": "ExploitBench: How Far Can an AI Agent Go When Exploiting a Vulnerability?",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/exploitbench-capability-ladder-analysis/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2422.9,
      "y": 1406.9
    },
    {
      "id": "STUDY-EXPLOITGYM-AI-AGENT-VULNERABILIT",
      "name": "Can an AI Agent Really Exploit a Real Vulnerability? ExploitGym Puts LLMs to the Test",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/exploitgym-ai-agent-vulnerability-exploitation/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2381.3,
      "y": 1260.3
    },
    {
      "id": "STUDY-FUNCTION-HIJACKING-ATTACKS",
      "name": "AI Security Research: Function Hijacking Attacks (FHA)",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/function-hijacking-attacks/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2303,
      "y": 1344.9
    },
    {
      "id": "STUDY-GENERATIVE-AI-CYBERSECURITY-PRIV",
      "name": "The State of Generative AI in Cybersecurity & Privacy: 2026 Landscape, Frontiers, and Gaps",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/generative-ai-cybersecurity-privacy-state-of-art/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2211.9,
      "y": 1376.4
    },
    {
      "id": "STUDY-GPU-MEMORY-KV-CACHE-FORENSICS",
      "name": "Artifact Analysis: GPU Memory Forensics & Hunting in the KV Cache",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/gpu-memory-kv-cache-forensics/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2209.4,
      "y": 1292.6
    },
    {
      "id": "STUDY-HOW-TO-ATTACK-AN-AI-AGENT-PILLAR",
      "name": "How Do You Attack an AI Agent? The Complete Anatomy of Agentic Exploitation",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/how-to-attack-an-ai-agent-pillar/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 1876.8,
      "y": 1394
    },
    {
      "id": "STUDY-INDIRECT-PROMPT-INJECTION",
      "name": "AI Security Research: The Rising Threat of Indirect Prompt Injection",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/indirect-prompt-injection/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2308.6,
      "y": 1174.6
    },
    {
      "id": "STUDY-LEAST-PRIVILEGE-CAPABILITY-SECUR",
      "name": "AI Security Research: Least Privilege & Capability-Oriented Architecture for AI Agents",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/least-privilege-capability-security/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2039.8,
      "y": 1354.6
    },
    {
      "id": "STUDY-LLM-MEDIATED-WEB-ATTACKS-ARXIV-2",
      "name": "LLM-Mediated Web Attacks: Prompt Injection as a Confused Deputy for Classic Exploitation",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/llm-mediated-web-attacks-arxiv-2608-10281/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 1872.9,
      "y": 1179.8
    },
    {
      "id": "STUDY-LLM-UNRELIABILITY-CYBER-THREAT-I",
      "name": "Can You Trust LLMs with Cyber Threat Intelligence? Empirical Limits and Hallucinations (arXiv:2503.23175)",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/llm-unreliability-cyber-threat-intelligence/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2232.9,
      "y": 1139.7
    },
    {
      "id": "STUDY-MATHEMATICS-OF-ATTENTION",
      "name": "AI Security Research: The Mathematics of Attention & Tensor-Level Hijack Detection",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/mathematics-of-attention/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2136.6,
      "y": 1252.6
    },
    {
      "id": "STUDY-MCP-MODEL-CONTEXT-PROTOCOL-SECUR",
      "name": "AI Security Research: MCP and the Expansion of the AI Attack Surface",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/mcp-model-context-protocol-security/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2151.5,
      "y": 1157.6
    },
    {
      "id": "STUDY-MCP-SECURITY-HYBRID-ANALYSIS-MTG",
      "name": "Is MCP a Major New Attack Surface for AI Agents? Hybrid Analysis with MTGuard",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/mcp-security-hybrid-analysis-mtguard/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2000.4,
      "y": 1211.2
    },
    {
      "id": "STUDY-NETWORK-CENTRIC-AGENT-SECURITY",
      "name": "AI Security Architecture: Rethinking Agent Security as a Networking Problem",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/network-centric-agent-security/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2253.4,
      "y": 1050
    },
    {
      "id": "STUDY-OWASPIFICATION-AGENTIC-AI",
      "name": "AI Security Research: The OWASPification of Agentic AI",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/owaspification-agentic-ai/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2281,
      "y": 970.7
    },
    {
      "id": "STUDY-PIMINER-AGENT-AGAINST-AGENT-RED-",
      "name": "Can One AI Hack Another AI? PIMiner and the Rise of Autonomous Prompt Injection",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/piminer-agent-against-agent-red-teaming/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2126.8,
      "y": 1017.9
    },
    {
      "id": "STUDY-PROMPT-INJECTION-VS-TOOL-POISONI",
      "name": "Prompt Injection vs Tool Poisoning vs RAG Poisoning vs MCP Attacks: A Comparative Attack Taxonomy",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/prompt-injection-vs-tool-poisoning-vs-rag-vs-mcp/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2217.9,
      "y": 860.6
    },
    {
      "id": "STUDY-RAG-POISONING",
      "name": "AI Security Research: RAG Poisoning and Knowledge Base Manipulation",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/rag-poisoning/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2313.4,
      "y": 893.4
    },
    {
      "id": "STUDY-RUNTIME-SECURITY-AI-AGENTS",
      "name": "AI Security Research: Runtime Security & Detection for AI Agents",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/runtime-security-ai-agents/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2368.4,
      "y": 1072
    },
    {
      "id": "STUDY-SEMANTIC-EXECUTION-LAYERS",
      "name": "AI Security Research: Semantic Execution Layers & Probabilistic Interpreters",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/semantic-execution-layers/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2406.8,
      "y": 941.6
    },
    {
      "id": "STUDY-SRE-BENCH-REVERSE-ENGINEERING-LI",
      "name": "Can AI Agents Really Perform Reverse Engineering? SRE-Bench Reveals Their Limits",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/sre-bench-reverse-engineering-limits/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2482.5,
      "y": 823.9
    },
    {
      "id": "STUDY-SYSEVOLVE-AUTONOMOUS-CYBER-CO-EV",
      "name": "SysEvolve: Autonomous Attack-Defense Co-Evolution in Cyber Ranges — Analyzing arXiv:2608.15012",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/sysevolve-autonomous-cyber-co-evolution/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 1978.5,
      "y": 750.2
    },
    {
      "id": "STUDY-TOKENIZATION-LAYER-EXPLOITATION",
      "name": "AI Security Research: The Tokenization Layer and BPE Exploitation",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/tokenization-layer-exploitation/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2518,
      "y": 935.2
    },
    {
      "id": "STUDY-TOOL-INJECTION-ARCHITECTURE",
      "name": "AI Security Research: Tool Injection as the Convergence Layer of LLM Exploitation",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/tool-injection-architecture/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2632.4,
      "y": 857.1
    },
    {
      "id": "STUDY-TOOL-POISONING-SEMANTIC-SUPPLY-C",
      "name": "AI Security Research: Tool Poisoning & The Semantic Supply Chain",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/tool-poisoning-semantic-supply-chain/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2619.7,
      "y": 1006.4
    },
    {
      "id": "STUDY-TRAINING-DATA-POISONING",
      "name": "AI Security Research: Training Data Poisoning & Backdoors",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/training-data-poisoning/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2728.5,
      "y": 929.6
    },
    {
      "id": "STUDY-TRUST-BOUNDARY-COLLAPSE",
      "name": "AI Security Research: Trust Boundary Collapse in Agentic AI",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/trust-boundary-collapse/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2811.5,
      "y": 1001.8
    },
    {
      "id": "STUDY-VULNERABILITIES-AGENTIC-LLMS-SUR",
      "name": "Agentic LLM Vulnerabilities: The 4-Layer Taxonomy & Systematic Review (arXiv:2608.10530)",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/vulnerabilities-agentic-llms-survey/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2872.5,
      "y": 1097.9
    },
    {
      "id": "STUDY-WHAT-CAN-AI-AGENTS-DO-CYBERSECUR",
      "name": "What Can AI Agents Actually Do in Cybersecurity in 2026? A Systematic Mapping of Capabilities, Benchmarks, and Limits",
      "type": "research_study",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/ai-security/core-studies/what-can-ai-agents-do-cybersecurity-2026/",
      "tags": [
        "ai-security",
        "research-study",
        "empirical-benchmark"
      ],
      "x": 2844.3,
      "y": 1219.5
    },
    {
      "id": "TOOL-AGENTTHREAT-STUDIO",
      "name": "AgentThreat Studio",
      "type": "tool",
      "severity": null,
      "cvss_score": null,
      "doc_url": "/tools/agent-threat-studio/",
      "tags": [
        "tool",
        "agentic-security",
        "threat-modeling",
        "mitre-atlas",
        "client-side"
      ],
      "x": 1810.2,
      "y": 1045.9
    }
  ],
  "links": [
    {
      "id": "REL-001",
      "source": "CVE-2026-59822",
      "target": "PROD-LITELLM",
      "relation": "affects",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Directly confirmed by vendor advisory GHSA-59822 and federal advisory in CISA KEV."
    },
    {
      "id": "REL-002",
      "source": "PROD-LITELLM",
      "target": "VENDOR-BERRIAI",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "LiteLLM is developed and maintained by BerriAI."
    },
    {
      "id": "REL-003",
      "source": "CVE-2026-22708",
      "target": "PROD-CURSOR",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed by Pillar Security vulnerability analysis and verified against Cursor < 2.3."
    },
    {
      "id": "REL-004",
      "source": "PROD-CURSOR",
      "target": "VENDOR-ANYSPHERE",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Cursor is produced and operated by Anysphere."
    },
    {
      "id": "REL-005",
      "source": "CVE-2026-41264",
      "target": "PROD-LANGGRAPH",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "LangChain official advisory documents deep research loop vulnerabilities affecting LangGraph state runners."
    },
    {
      "id": "REL-006",
      "source": "PROD-LANGGRAPH",
      "target": "VENDOR-LANGCHAIN",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "LangGraph is designed and copyrighted by LangChain Inc."
    },
    {
      "id": "REL-007",
      "source": "CVE-2026-46580",
      "target": "PROD-THEIA",
      "relation": "affects",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Addressed in official Eclipse Theia version 1.71.0 patch commit and advisory."
    },
    {
      "id": "REL-008",
      "source": "PROD-THEIA",
      "target": "VENDOR-ECLIPSE",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Eclipse Theia is a project of the Eclipse Foundation."
    },
    {
      "id": "REL-009",
      "source": "EXP-2026-59822-POC",
      "target": "CVE-2026-59822",
      "relation": "exploits",
      "confidence": 0.96,
      "confidence_level": "VERY_HIGH",
      "rationale": "Public PoC exploits the blank Bearer authentication validation flaw."
    },
    {
      "id": "REL-010",
      "source": "ACTOR-VOID-ARACHNE",
      "target": "EXP-2026-59822-POC",
      "relation": "uses",
      "confidence": 0.88,
      "confidence_level": "HIGH",
      "rationale": "Telemetry shows automated exploitation payloads identical to the public PoC origin."
    },
    {
      "id": "REL-011",
      "source": "ACTOR-VOID-ARACHNE",
      "target": "CAMP-MCP-RECON-2026",
      "relation": "used_in",
      "confidence": 0.85,
      "confidence_level": "HIGH",
      "rationale": "Attributed scanning behavior aligns with Operation MCP Harvester reconnaissance activity."
    },
    {
      "id": "REL-012",
      "source": "CVE-2026-59822",
      "target": "AAP-003",
      "relation": "exploits",
      "confidence": 0.94,
      "confidence_level": "HIGH",
      "rationale": "Hijacking MCP endpoints enables attackers to supply crafted tool execution parameters."
    },
    {
      "id": "REL-013",
      "source": "CVE-2026-41264",
      "target": "AAP-001",
      "relation": "exploits",
      "confidence": 0.95,
      "confidence_level": "VERY_HIGH",
      "rationale": "Deep research loop processes external web markdown that contains indirect injection instructions."
    },
    {
      "id": "REL-014",
      "source": "CVE-2026-22708",
      "target": "AAP-002",
      "relation": "exploits",
      "confidence": 0.94,
      "confidence_level": "HIGH",
      "rationale": "Injecting export BASH_ENV into the shell environment establishes persistent execution across agent steps."
    },
    {
      "id": "REL-015",
      "source": "CVE-2026-46580",
      "target": "AAP-001",
      "relation": "exploits",
      "confidence": 0.96,
      "confidence_level": "VERY_HIGH",
      "rationale": "Workspace prompt templates override assistant system prompts via untrusted repository files."
    },
    {
      "id": "REL-016",
      "source": "CVE-2026-22708",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Abuses bash built-in commands (export, typeset) to manipulate shell startup scripts."
    },
    {
      "id": "REL-017",
      "source": "CVE-2026-22708",
      "target": "T1574",
      "relation": "uses",
      "confidence": 0.95,
      "confidence_level": "VERY_HIGH",
      "rationale": "BASH_ENV environment variable directly hijacks the execution flow of benign commands."
    },
    {
      "id": "REL-018",
      "source": "CVE-2026-46580",
      "target": "T1566",
      "relation": "uses",
      "confidence": 0.93,
      "confidence_level": "HIGH",
      "rationale": "Entices developers to clone and open untrusted repositories containing malicious prompt templates."
    },
    {
      "id": "REL-019",
      "source": "CVE-2026-59822",
      "target": "T1552",
      "relation": "uses",
      "confidence": 0.92,
      "confidence_level": "HIGH",
      "rationale": "Unauthenticated MCP access allows scraping upstream model API keys and internal environment variables."
    },
    {
      "id": "REL-020",
      "source": "CVE-2026-22708",
      "target": "ART-BASH-ENV",
      "relation": "leaves_artifact",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Terminal process tree and /proc/<PID>/environ exhibit compromised BASH_ENV variables."
    },
    {
      "id": "REL-021",
      "source": "CVE-2026-59822",
      "target": "ART-MCP-AUTH-HEADER",
      "relation": "leaves_artifact",
      "confidence": 0.97,
      "confidence_level": "VERY_HIGH",
      "rationale": "Access logs record HTTP POST requests with missing or dummy Authorization headers."
    },
    {
      "id": "REL-022",
      "source": "CVE-2026-46580",
      "target": "ART-THEIA-PROMPT",
      "relation": "leaves_artifact",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Disk inspection reveals .prompts/*.prompttemplate artifacts in repo workspace root."
    },
    {
      "id": "REL-023",
      "source": "CVE-2026-59822",
      "target": "DET-SIGMA-042",
      "relation": "detected_by",
      "confidence": 0.95,
      "confidence_level": "VERY_HIGH",
      "rationale": "Sigma rule SIG-MCP-042 flags unauthenticated session establishment requests."
    },
    {
      "id": "REL-024",
      "source": "CVE-2026-22708",
      "target": "DET-SIGMA-CURSOR",
      "relation": "detected_by",
      "confidence": 0.96,
      "confidence_level": "VERY_HIGH",
      "rationale": "Sigma rule SIG-CURSOR-ENV-01 flags shell processes spawning export BASH_ENV under IDE hierarchy."
    },
    {
      "id": "REL-025",
      "source": "CVE-2026-46580",
      "target": "DET-YARA-THEIA",
      "relation": "detected_by",
      "confidence": 0.97,
      "confidence_level": "VERY_HIGH",
      "rationale": "YARA signature detects suspicious prompt template files before IDE workspace ingestion."
    },
    {
      "id": "REL-026",
      "source": "MAL-SHADOWAGENT",
      "target": "CVE-2026-59822",
      "relation": "exploits",
      "confidence": 0.87,
      "confidence_level": "HIGH",
      "rationale": "ShadowAgent modular payload includes an automated LiteLLM MCP session hijacker."
    },
    {
      "id": "REL-027",
      "source": "CVE-2026-59822",
      "target": "AAP-004",
      "relation": "enables",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "Unauthenticated MCP access allows registering rogue tool definitions with weaponized descriptions."
    },
    {
      "id": "REL-028",
      "source": "CVE-2026-41264",
      "target": "AAP-005",
      "relation": "leads_to",
      "confidence": 0.91,
      "confidence_level": "VERY_HIGH",
      "rationale": "Autonomous web crawling ingests untrusted text chunks directly into the agent's RAG index."
    },
    {
      "id": "REL-029",
      "source": "CVE-2026-59822",
      "target": "AAP-006",
      "relation": "enables",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Compromising the MCP streaming proxy allows injecting spoofed responses into peer agent message flows."
    },
    {
      "id": "REL-030",
      "source": "CVE-2026-22708",
      "target": "AAP-007",
      "relation": "leads_to",
      "confidence": 0.95,
      "confidence_level": "VERY_HIGH",
      "rationale": "Auto-run shell command chaining results in autonomous cascading breakout from the IDE agent."
    },
    {
      "id": "REL-031",
      "source": "CVE-2026-41264",
      "target": "AAP-007",
      "relation": "leads_to",
      "confidence": 0.94,
      "confidence_level": "VERY_HIGH",
      "rationale": "Chaining context ingestion with OS tool capabilities leads to full host execution takeover."
    },
    {
      "id": "REL-032",
      "source": "CVE-2026-40087",
      "target": "PROD-LANGGRAPH",
      "relation": "affects",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Directly impacts langchain and langchain-core prompt template engine prior to versions 0.3.84 and 1.2.28."
    },
    {
      "id": "REL-033",
      "source": "CVE-2026-40087",
      "target": "AAP-001",
      "relation": "exploits",
      "confidence": 0.91,
      "confidence_level": "VERY_HIGH",
      "rationale": "Untrusted prompt template strings allow injecting format specifiers that subvert system prompt boundaries and access internal object properties."
    },
    {
      "id": "REL-034",
      "source": "CVE-2026-27966",
      "target": "PROD-LANGFLOW",
      "relation": "affects",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Directly impacts Langflow tabular CSV Agent node prior to version 1.8.0."
    },
    {
      "id": "REL-035",
      "source": "CVE-2026-27966",
      "target": "AAP-007",
      "relation": "leads_to",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Hardcoded allow_dangerous_code exposes Python REPL tool causing autonomous cascading command execution."
    },
    {
      "id": "REL-036",
      "source": "CVE-2026-33873",
      "target": "PROD-LANGFLOW",
      "relation": "affects",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Affects Langflow Agentic Assistant execution engine in releases prior to 1.9.0."
    },
    {
      "id": "REL-037",
      "source": "CVE-2026-33873",
      "target": "AAP-003",
      "relation": "exploits",
      "confidence": 0.94,
      "confidence_level": "VERY_HIGH",
      "rationale": "Abuses validation sink and dynamic class instantiation parameters to achieve server RCE."
    },
    {
      "id": "REL-038",
      "source": "CVE-2025-52573",
      "target": "PROD-IOS-SIMULATOR-MCP",
      "relation": "affects",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Directly compromises ios-simulator-mcp server tool implementation prior to version 1.3.3."
    },
    {
      "id": "REL-039",
      "source": "CVE-2025-52573",
      "target": "AAP-003",
      "relation": "exploits",
      "confidence": 0.97,
      "confidence_level": "VERY_HIGH",
      "rationale": "Exploits shell parameter concatenation in MCP tool arguments to trigger host OS commands."
    },
    {
      "id": "REL-040",
      "source": "CVE-2025-32711",
      "target": "PROD-M365-COPILOT",
      "relation": "affects",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Directly impacts Microsoft 365 Copilot cloud orchestration and background indexing."
    },
    {
      "id": "REL-041",
      "source": "CVE-2025-32711",
      "target": "AAP-002",
      "relation": "exploits",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Leverages zero-click indirect prompt injection during autonomous document ingestion."
    },
    {
      "id": "REL-042",
      "source": "CVE-2025-53773",
      "target": "PROD-GITHUB-COPILOT",
      "relation": "affects",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Directly compromises GitHub Copilot for VS Code agent tool permissions."
    },
    {
      "id": "REL-043",
      "source": "CVE-2025-53773",
      "target": "AAP-007",
      "relation": "leads_to",
      "confidence": 0.96,
      "confidence_level": "VERY_HIGH",
      "rationale": "Modifying workspace auto-approve settings allows the agent to execute unconstrained host shell commands."
    },
    {
      "id": "REL-044",
      "source": "CVE-2025-66389",
      "target": "PROD-GITHUB-COPILOT",
      "relation": "affects",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Directly impacts GitHub Copilot 1.372.0 fetch_webpage file handler."
    },
    {
      "id": "REL-045",
      "source": "CVE-2025-66389",
      "target": "AAP-003",
      "relation": "exploits",
      "confidence": 0.96,
      "confidence_level": "VERY_HIGH",
      "rationale": "Manipulates tool parameter URI scheme to traverse outside workspace boundaries."
    },
    {
      "id": "REL-046",
      "source": "CVE-2026-24307",
      "target": "PROD-M365-COPILOT",
      "relation": "affects",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Directly compromises Microsoft 365 Copilot input parsing engine."
    },
    {
      "id": "REL-047",
      "source": "CVE-2026-24307",
      "target": "AAP-001",
      "relation": "exploits",
      "confidence": 0.94,
      "confidence_level": "VERY_HIGH",
      "rationale": "Type validation confusion enables bypassing prompt restrictions to read cross-tenant context."
    },
    {
      "id": "REL-048",
      "source": "CVE-2025-59417",
      "target": "PROD-LOBE-CHAT",
      "relation": "affects",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Directly compromises Lobe Chat SVGRender component in releases prior to 1.129.4."
    },
    {
      "id": "REL-049",
      "source": "CVE-2025-59417",
      "target": "AAP-007",
      "relation": "leads_to",
      "confidence": 0.95,
      "confidence_level": "VERY_HIGH",
      "rationale": "Client-side script execution in desktop/Electron context escalates to host command execution."
    },
    {
      "id": "REL-050",
      "source": "CVE-2025-49150",
      "target": "PROD-CURSOR",
      "relation": "affects",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Impacts default schema download configuration in Cursor IDE prior to version 0.51.0."
    },
    {
      "id": "REL-051",
      "source": "CVE-2025-49150",
      "target": "AAP-002",
      "relation": "exploits",
      "confidence": 0.95,
      "confidence_level": "VERY_HIGH",
      "rationale": "Agent prompt injection causes JSON $schema injection leading to out-of-band HTTP exfiltration."
    },
    {
      "id": "REL-052",
      "source": "CVE-2024-5184",
      "target": "PROD-EMAILGPT",
      "relation": "affects",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Directly impacts EmailGPT service and browser extension API handling."
    },
    {
      "id": "REL-053",
      "source": "CVE-2024-5184",
      "target": "AAP-001",
      "relation": "exploits",
      "confidence": 0.96,
      "confidence_level": "VERY_HIGH",
      "rationale": "Direct conversational prompt injection overrides service guardrails to leak system prompt."
    },
    {
      "id": "REL-054",
      "source": "CVE-2026-86060",
      "target": "PROD-MIKROTIK-ROUTEROS",
      "relation": "affects",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Argument delimiter injection in SSH login path escalates session privileges to full admin on RouterOS."
    },
    {
      "id": "REL-055",
      "source": "CVE-2026-86060",
      "target": "CAMP-MIKROTRICK-2026",
      "relation": "used_in",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Actively exploited in the wild as the second stage of the MikroTrick campaign."
    },
    {
      "id": "REL-056",
      "source": "CVE-2026-67277",
      "target": "PROD-MIKROTIK-ROUTEROS",
      "relation": "affects",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Missing authentication and integer underflow in bandwidth-test (btest) service on RouterOS."
    },
    {
      "id": "REL-057",
      "source": "CVE-2026-85102",
      "target": "PROD-CHECKPOINT-GAIA",
      "relation": "affects",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Directly disclosed in Check Point advisory sk1000117 affecting Quantum Security Gateways."
    },
    {
      "id": "REL-058",
      "source": "CVE-2026-85103",
      "target": "PROD-CHECKPOINT-GAIA",
      "relation": "affects",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Directly disclosed in Check Point advisory sk1000118 affecting Gateways and Security Management Servers."
    },
    {
      "id": "REL-059",
      "source": "CVE-2026-81578",
      "target": "PROD-PAPERCUT-NG-MF",
      "relation": "affects",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Directly confirmed by PaperCut Security Bulletin and active exploitation in KEV."
    },
    {
      "id": "REL-060",
      "source": "CVE-2026-82078",
      "target": "PROD-PAPERCUT-NG-MF",
      "relation": "affects",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Directly confirmed by PaperCut Security Bulletin and chained in RCE attacks."
    },
    {
      "id": "REL-061",
      "source": "CAMP-PAPERCUT-AI-2026",
      "target": "CVE-2026-81578",
      "relation": "exploits",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "GreyNoise telemetry confirmed automated AI agents exploited CVE-2026-81578 for initial access."
    },
    {
      "id": "REL-062",
      "source": "CAMP-PAPERCUT-AI-2026",
      "target": "CVE-2026-82078",
      "relation": "exploits",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "GreyNoise telemetry confirmed automated AI agents chained CVE-2026-82078 to achieve RCE."
    },
    {
      "id": "REL-AUTO-PROD-OFFICE-VENDOR-MICROSOFT",
      "source": "PROD-OFFICE",
      "target": "VENDOR-MICROSOFT",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Microsoft Office & 365 Apps is developed and maintained by Microsoft Corporation."
    },
    {
      "id": "REL-AUTO-CVE-2009-0238-PROD-OFFICE",
      "source": "CVE-2009-0238",
      "target": "PROD-OFFICE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Office & 365 Apps documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-WINDOWS-VENDOR-MICROSOFT",
      "source": "PROD-WINDOWS",
      "target": "VENDOR-MICROSOFT",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Microsoft Windows & Windows Server is developed and maintained by Microsoft Corporation."
    },
    {
      "id": "REL-AUTO-CVE-2012-1854-PROD-WINDOWS",
      "source": "CVE-2012-1854",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-PANOS-VENDOR-PALOALTO",
      "source": "PROD-PANOS",
      "target": "VENDOR-PALOALTO",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Palo Alto Networks PAN-OS is developed and maintained by Palo Alto Networks."
    },
    {
      "id": "REL-AUTO-CVE-2020-2021-PROD-PANOS",
      "source": "CVE-2020-2021",
      "target": "PROD-PANOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Palo Alto Networks PAN-OS documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-FORTIOS-VENDOR-FORTINET",
      "source": "PROD-FORTIOS",
      "target": "VENDOR-FORTINET",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Fortinet FortiOS Gateway is developed and maintained by Fortinet."
    },
    {
      "id": "REL-AUTO-CVE-2020-3452-PROD-FORTIOS",
      "source": "CVE-2020-3452",
      "target": "PROD-FORTIOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Fortinet FortiOS Gateway documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-PAPERCUT-VENDOR-PAPERCUT",
      "source": "PROD-PAPERCUT",
      "target": "VENDOR-PAPERCUT",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "PaperCut MF/NG is developed and maintained by PaperCut Software."
    },
    {
      "id": "REL-AUTO-CVE-2021-42278-PROD-PAPERCUT",
      "source": "CVE-2021-42278",
      "target": "PROD-PAPERCUT",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in PaperCut MF/NG documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2021-42287-PROD-PAPERCUT",
      "source": "CVE-2021-42287",
      "target": "PROD-PAPERCUT",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in PaperCut MF/NG documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2022-42475-PROD-FORTIOS",
      "source": "CVE-2022-42475",
      "target": "PROD-FORTIOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Fortinet FortiOS Gateway documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2023-20198-PROD-FORTIOS",
      "source": "CVE-2023-20198",
      "target": "PROD-FORTIOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Fortinet FortiOS Gateway documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-VEEAM-VBR-VENDOR-VEEAM",
      "source": "PROD-VEEAM-VBR",
      "target": "VENDOR-VEEAM",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Veeam Backup & Replication is developed and maintained by Veeam Software."
    },
    {
      "id": "REL-AUTO-CVE-2023-27532-PROD-VEEAM-VBR",
      "source": "CVE-2023-27532",
      "target": "PROD-VEEAM-VBR",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Veeam Backup & Replication documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2023-27532-T1552",
      "source": "CVE-2023-27532",
      "target": "T1552",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552."
    },
    {
      "id": "REL-AUTO-CVE-2023-27997-PROD-FORTIOS",
      "source": "CVE-2023-27997",
      "target": "PROD-FORTIOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Fortinet FortiOS Gateway documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2024-0012-PROD-PANOS",
      "source": "CVE-2024-0012",
      "target": "PROD-PANOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Palo Alto Networks PAN-OS documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2024-20353-PROD-FORTIOS",
      "source": "CVE-2024-20353",
      "target": "PROD-FORTIOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Fortinet FortiOS Gateway documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2024-20359-PROD-FORTIOS",
      "source": "CVE-2024-20359",
      "target": "PROD-FORTIOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Fortinet FortiOS Gateway documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2024-21762-PROD-FORTIOS",
      "source": "CVE-2024-21762",
      "target": "PROD-FORTIOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Fortinet FortiOS Gateway documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2024-3400-PROD-PANOS",
      "source": "CVE-2024-3400",
      "target": "PROD-PANOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Palo Alto Networks PAN-OS documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2024-47575-PROD-FORTIOS",
      "source": "CVE-2024-47575",
      "target": "PROD-FORTIOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Fortinet FortiOS Gateway documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-EMAILGPT-VENDOR-EMAILGPT",
      "source": "PROD-EMAILGPT",
      "target": "VENDOR-EMAILGPT",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "EmailGPT Service is developed and maintained by EmailGPT OpenSource."
    },
    {
      "id": "REL-AUTO-CVE-2024-5184-PROD-EMAILGPT",
      "source": "CVE-2024-5184",
      "target": "PROD-EMAILGPT",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in EmailGPT Service documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2024-5184-AAP-001",
      "source": "CVE-2024-5184",
      "target": "AAP-001",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2024-5184 weaponizes the agentic attack pattern formalized under AAP-001."
    },
    {
      "id": "REL-AUTO-CVE-2024-5184-T1059",
      "source": "CVE-2024-5184",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-PROD-SIMPLEHELP-VENDOR-SIMPLEHELP",
      "source": "PROD-SIMPLEHELP",
      "target": "VENDOR-SIMPLEHELP",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "SimpleHelp Remote Access is developed and maintained by SimpleHelp Ltd."
    },
    {
      "id": "REL-AUTO-CVE-2024-57728-PROD-SIMPLEHELP",
      "source": "CVE-2024-57728",
      "target": "PROD-SIMPLEHELP",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in SimpleHelp Remote Access documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-IVANTI-CONNECT-VENDOR-IVANTI",
      "source": "PROD-IVANTI-CONNECT",
      "target": "VENDOR-IVANTI",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Ivanti Connect Secure VPN is developed and maintained by Ivanti."
    },
    {
      "id": "REL-AUTO-CVE-2025-0282-PROD-IVANTI-CONNECT",
      "source": "CVE-2025-0282",
      "target": "PROD-IVANTI-CONNECT",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Ivanti Connect Secure VPN documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-0282-T1059",
      "source": "CVE-2025-0282",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2025-20188-T1059",
      "source": "CVE-2025-20188",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-PROD-CISCO-ISE-VENDOR-CISCO",
      "source": "PROD-CISCO-ISE",
      "target": "VENDOR-CISCO",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Cisco Identity Services Engine (ISE) is developed and maintained by Cisco Systems."
    },
    {
      "id": "REL-AUTO-CVE-2025-20281-PROD-CISCO-ISE",
      "source": "CVE-2025-20281",
      "target": "PROD-CISCO-ISE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Cisco Identity Services Engine (ISE) documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-20281-T1059",
      "source": "CVE-2025-20281",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-PROD-CISCO-SEG-VENDOR-CISCO",
      "source": "PROD-CISCO-SEG",
      "target": "VENDOR-CISCO",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Cisco Secure Email Gateway (AsyncOS) is developed and maintained by Cisco Systems."
    },
    {
      "id": "REL-AUTO-CVE-2025-20393-PROD-CISCO-SEG",
      "source": "CVE-2025-20393",
      "target": "PROD-CISCO-SEG",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Cisco Secure Email Gateway (AsyncOS) documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-20393-T1059",
      "source": "CVE-2025-20393",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2025-20393-T1566",
      "source": "CVE-2025-20393",
      "target": "T1566",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1566."
    },
    {
      "id": "REL-AUTO-CVE-2025-21333-PROD-WINDOWS",
      "source": "CVE-2025-21333",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-22457-PROD-IVANTI-CONNECT",
      "source": "CVE-2025-22457",
      "target": "PROD-IVANTI-CONNECT",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Ivanti Connect Secure VPN documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-22457-T1059",
      "source": "CVE-2025-22457",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2025-23304-PROD-PANOS",
      "source": "CVE-2025-23304",
      "target": "PROD-PANOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Palo Alto Networks PAN-OS documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-24054-PROD-WINDOWS",
      "source": "CVE-2025-24054",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-24472-PROD-FORTIOS",
      "source": "CVE-2025-24472",
      "target": "PROD-FORTIOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Fortinet FortiOS Gateway documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-APACHE-TOMCAT-VENDOR-APACHE",
      "source": "PROD-APACHE-TOMCAT",
      "target": "VENDOR-APACHE",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Apache Tomcat is developed and maintained by Apache Software Foundation."
    },
    {
      "id": "REL-AUTO-CVE-2025-24813-PROD-APACHE-TOMCAT",
      "source": "CVE-2025-24813",
      "target": "PROD-APACHE-TOMCAT",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Apache Tomcat documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-24813-T1059",
      "source": "CVE-2025-24813",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2025-25249-PROD-FORTIOS",
      "source": "CVE-2025-25249",
      "target": "PROD-FORTIOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Fortinet FortiOS Gateway documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-25257-PROD-FORTIOS",
      "source": "CVE-2025-25257",
      "target": "PROD-FORTIOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Fortinet FortiOS Gateway documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-25257-T1059",
      "source": "CVE-2025-25257",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-PROD-FLOWISE-VENDOR-FLOWISE",
      "source": "PROD-FLOWISE",
      "target": "VENDOR-FLOWISE",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Flowise AI Workflow Builder is developed and maintained by FlowiseAI."
    },
    {
      "id": "REL-AUTO-CVE-2025-26319-PROD-FLOWISE",
      "source": "CVE-2025-26319",
      "target": "PROD-FLOWISE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Flowise AI Workflow Builder documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-26319-AAP-005",
      "source": "CVE-2025-26319",
      "target": "AAP-005",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2025-26319 weaponizes the agentic attack pattern formalized under AAP-005."
    },
    {
      "id": "REL-AUTO-CVE-2025-29824-PROD-WINDOWS",
      "source": "CVE-2025-29824",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-30733-PROD-OFFICE",
      "source": "CVE-2025-30733",
      "target": "PROD-OFFICE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Office & 365 Apps documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-30733-T1552",
      "source": "CVE-2025-30733",
      "target": "T1552",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552."
    },
    {
      "id": "REL-AUTO-CVE-2025-32433-T1059",
      "source": "CVE-2025-32433",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-PROD-LANGFLOW-VENDOR-LANGFLOW",
      "source": "PROD-LANGFLOW",
      "target": "VENDOR-LANGFLOW",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Langflow Visual AI Builder is developed and maintained by DataStax / Langflow."
    },
    {
      "id": "REL-AUTO-CVE-2025-3248-PROD-LANGFLOW",
      "source": "CVE-2025-3248",
      "target": "PROD-LANGFLOW",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Langflow Visual AI Builder documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-3248-AAP-007",
      "source": "CVE-2025-3248",
      "target": "AAP-007",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2025-3248 weaponizes the agentic attack pattern formalized under AAP-007."
    },
    {
      "id": "REL-AUTO-CVE-2025-3248-T1059",
      "source": "CVE-2025-3248",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-PROD-M365-COPILOT-VENDOR-MICROSOFT",
      "source": "PROD-M365-COPILOT",
      "target": "VENDOR-MICROSOFT",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Microsoft 365 Copilot is developed and maintained by Microsoft Corporation."
    },
    {
      "id": "REL-AUTO-CVE-2025-32711-PROD-M365-COPILOT",
      "source": "CVE-2025-32711",
      "target": "PROD-M365-COPILOT",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft 365 Copilot documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-32724-PROD-WINDOWS",
      "source": "CVE-2025-32724",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-LINUX-KERNEL-VENDOR-LINUX",
      "source": "PROD-LINUX-KERNEL",
      "target": "VENDOR-LINUX",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Linux Kernel Core is developed and maintained by Linux Foundation."
    },
    {
      "id": "REL-AUTO-CVE-2025-39682-PROD-LINUX-KERNEL",
      "source": "CVE-2025-39682",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-39964-PROD-LINUX-KERNEL",
      "source": "CVE-2025-39964",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-42944-PROD-WINDOWS",
      "source": "CVE-2025-42944",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-42944-T1059",
      "source": "CVE-2025-42944",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-PROD-VLLM-VENDOR-VLLM",
      "source": "PROD-VLLM",
      "target": "VENDOR-VLLM",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "vLLM Inference Engine is developed and maintained by vLLM Project."
    },
    {
      "id": "REL-AUTO-CVE-2025-47277-PROD-VLLM",
      "source": "CVE-2025-47277",
      "target": "PROD-VLLM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in vLLM Inference Engine documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-49113-T1059",
      "source": "CVE-2025-49113",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-PROD-CURSOR-VENDOR-ANYSPHERE",
      "source": "PROD-CURSOR",
      "target": "VENDOR-ANYSPHERE",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Cursor AI Code Editor is developed and maintained by Anysphere."
    },
    {
      "id": "REL-AUTO-CVE-2025-49150-PROD-CURSOR",
      "source": "CVE-2025-49150",
      "target": "PROD-CURSOR",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Cursor AI Code Editor documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-49150-AAP-003",
      "source": "CVE-2025-49150",
      "target": "AAP-003",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2025-49150 weaponizes the agentic attack pattern formalized under AAP-003."
    },
    {
      "id": "REL-AUTO-CVE-2025-49704-PROD-WINDOWS",
      "source": "CVE-2025-49704",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-49704-T1059",
      "source": "CVE-2025-49704",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-PROD-IOS-SIMULATOR-VENDOR-APPLE",
      "source": "PROD-IOS-SIMULATOR",
      "target": "VENDOR-APPLE",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Apple iOS Simulator MCP Server is developed and maintained by Apple Inc."
    },
    {
      "id": "REL-AUTO-CVE-2025-52573-PROD-IOS-SIMULATOR",
      "source": "CVE-2025-52573",
      "target": "PROD-IOS-SIMULATOR",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Apple iOS Simulator MCP Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-52573-AAP-003",
      "source": "CVE-2025-52573",
      "target": "AAP-003",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2025-52573 weaponizes the agentic attack pattern formalized under AAP-003."
    },
    {
      "id": "REL-AUTO-CVE-2025-52573-AAP-004",
      "source": "CVE-2025-52573",
      "target": "AAP-004",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2025-52573 weaponizes the agentic attack pattern formalized under AAP-004."
    },
    {
      "id": "REL-AUTO-PROD-AWS-MCP-SERVER-VENDOR-AMAZON",
      "source": "PROD-AWS-MCP-SERVER",
      "target": "VENDOR-AMAZON",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "AWS MCP Server Suite is developed and maintained by Amazon Web Services / MCP Community."
    },
    {
      "id": "REL-AUTO-CVE-2025-5277-PROD-AWS-MCP-SERVER",
      "source": "CVE-2025-5277",
      "target": "PROD-AWS-MCP-SERVER",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in AWS MCP Server Suite documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-5277-AAP-003",
      "source": "CVE-2025-5277",
      "target": "AAP-003",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2025-5277 weaponizes the agentic attack pattern formalized under AAP-003."
    },
    {
      "id": "REL-AUTO-CVE-2025-5277-AAP-001",
      "source": "CVE-2025-5277",
      "target": "AAP-001",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2025-5277 weaponizes the agentic attack pattern formalized under AAP-001."
    },
    {
      "id": "REL-AUTO-CVE-2025-5277-AAP-007",
      "source": "CVE-2025-5277",
      "target": "AAP-007",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2025-5277 weaponizes the agentic attack pattern formalized under AAP-007."
    },
    {
      "id": "REL-AUTO-CVE-2025-5277-T1059",
      "source": "CVE-2025-5277",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2025-5277-T1552",
      "source": "CVE-2025-5277",
      "target": "T1552",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552."
    },
    {
      "id": "REL-AUTO-CVE-2025-52970-PROD-FORTIOS",
      "source": "CVE-2025-52970",
      "target": "PROD-FORTIOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Fortinet FortiOS Gateway documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-53770-PROD-WINDOWS",
      "source": "CVE-2025-53770",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-53770-T1059",
      "source": "CVE-2025-53770",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-PROD-GITHUB-COPILOT-VENDOR-MICROSOFT",
      "source": "PROD-GITHUB-COPILOT",
      "target": "VENDOR-MICROSOFT",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "GitHub Copilot is developed and maintained by Microsoft / GitHub."
    },
    {
      "id": "REL-AUTO-CVE-2025-53773-PROD-GITHUB-COPILOT",
      "source": "CVE-2025-53773",
      "target": "PROD-GITHUB-COPILOT",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in GitHub Copilot documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-53844-PROD-FORTIOS",
      "source": "CVE-2025-53844",
      "target": "PROD-FORTIOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Fortinet FortiOS Gateway documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-CLAUDE-CODE-VENDOR-ANTHROPIC",
      "source": "PROD-CLAUDE-CODE",
      "target": "VENDOR-ANTHROPIC",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Claude Code Agentic CLI is developed and maintained by Anthropic."
    },
    {
      "id": "REL-AUTO-CVE-2025-54794-PROD-CLAUDE-CODE",
      "source": "CVE-2025-54794",
      "target": "PROD-CLAUDE-CODE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Claude Code Agentic CLI documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-54794-AAP-006",
      "source": "CVE-2025-54794",
      "target": "AAP-006",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2025-54794 weaponizes the agentic attack pattern formalized under AAP-006."
    },
    {
      "id": "REL-AUTO-CVE-2025-54795-PROD-CLAUDE-CODE",
      "source": "CVE-2025-54795",
      "target": "PROD-CLAUDE-CODE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Claude Code Agentic CLI documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-54795-AAP-002",
      "source": "CVE-2025-54795",
      "target": "AAP-002",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2025-54795 weaponizes the agentic attack pattern formalized under AAP-002."
    },
    {
      "id": "REL-AUTO-CVE-2025-54795-AAP-007",
      "source": "CVE-2025-54795",
      "target": "AAP-007",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2025-54795 weaponizes the agentic attack pattern formalized under AAP-007."
    },
    {
      "id": "REL-AUTO-CVE-2025-54795-T1059",
      "source": "CVE-2025-54795",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2025-55125-PROD-VEEAM-VBR",
      "source": "CVE-2025-55125",
      "target": "PROD-VEEAM-VBR",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Veeam Backup & Replication documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-55182-PROD-OFFICE",
      "source": "CVE-2025-55182",
      "target": "PROD-OFFICE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Office & 365 Apps documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-55182-T1059",
      "source": "CVE-2025-55182",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2025-55182-T1552",
      "source": "CVE-2025-55182",
      "target": "T1552",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552."
    },
    {
      "id": "REL-AUTO-PROD-NETSCALER-VENDOR-CITRIX",
      "source": "PROD-NETSCALER",
      "target": "VENDOR-CITRIX",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Citrix NetScaler ADC is developed and maintained by Citrix Systems."
    },
    {
      "id": "REL-AUTO-CVE-2025-5777-PROD-NETSCALER",
      "source": "CVE-2025-5777",
      "target": "PROD-NETSCALER",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Citrix NetScaler ADC documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-58434-PROD-FLOWISE",
      "source": "CVE-2025-58434",
      "target": "PROD-FLOWISE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Flowise AI Workflow Builder documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-LOBECHAT-VENDOR-LOBEHUB",
      "source": "PROD-LOBECHAT",
      "target": "VENDOR-LOBEHUB",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Lobe Chat Framework is developed and maintained by LobeHub."
    },
    {
      "id": "REL-AUTO-CVE-2025-59417-PROD-LOBECHAT",
      "source": "CVE-2025-59417",
      "target": "PROD-LOBECHAT",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Lobe Chat Framework documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-59417-AAP-003",
      "source": "CVE-2025-59417",
      "target": "AAP-003",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2025-59417 weaponizes the agentic attack pattern formalized under AAP-003."
    },
    {
      "id": "REL-AUTO-CVE-2025-59468-PROD-VEEAM-VBR",
      "source": "CVE-2025-59468",
      "target": "PROD-VEEAM-VBR",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Veeam Backup & Replication documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-59469-PROD-VEEAM-VBR",
      "source": "CVE-2025-59469",
      "target": "PROD-VEEAM-VBR",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Veeam Backup & Replication documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-59470-PROD-VEEAM-VBR",
      "source": "CVE-2025-59470",
      "target": "PROD-VEEAM-VBR",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Veeam Backup & Replication documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-59528-PROD-FLOWISE",
      "source": "CVE-2025-59528",
      "target": "PROD-FLOWISE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Flowise AI Workflow Builder documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-59528-AAP-007",
      "source": "CVE-2025-59528",
      "target": "AAP-007",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2025-59528 weaponizes the agentic attack pattern formalized under AAP-007."
    },
    {
      "id": "REL-AUTO-CVE-2025-59528-T1059",
      "source": "CVE-2025-59528",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2025-60710-PROD-WINDOWS",
      "source": "CVE-2025-60710",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-61882-T1059",
      "source": "CVE-2025-61882",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2025-66389-PROD-GITHUB-COPILOT",
      "source": "CVE-2025-66389",
      "target": "PROD-GITHUB-COPILOT",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in GitHub Copilot documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2025-66389-AAP-003",
      "source": "CVE-2025-66389",
      "target": "AAP-003",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2025-66389 weaponizes the agentic attack pattern formalized under AAP-003."
    },
    {
      "id": "REL-AUTO-CVE-2025-66389-AAP-002",
      "source": "CVE-2025-66389",
      "target": "AAP-002",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2025-66389 weaponizes the agentic attack pattern formalized under AAP-002."
    },
    {
      "id": "REL-AUTO-CVE-2025-8088-PROD-WINDOWS",
      "source": "CVE-2025-8088",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-0257-PROD-PANOS",
      "source": "CVE-2026-0257",
      "target": "PROD-PANOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Palo Alto Networks PAN-OS documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-0300-PROD-PANOS",
      "source": "CVE-2026-0300",
      "target": "PROD-PANOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Palo Alto Networks PAN-OS documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-0300-T1552",
      "source": "CVE-2026-0300",
      "target": "T1552",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552."
    },
    {
      "id": "REL-AUTO-CVE-2026-0770-PROD-LANGFLOW",
      "source": "CVE-2026-0770",
      "target": "PROD-LANGFLOW",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Langflow Visual AI Builder documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-0770-T1059",
      "source": "CVE-2026-0770",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-0770-T1552",
      "source": "CVE-2026-0770",
      "target": "T1552",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552."
    },
    {
      "id": "REL-AUTO-PROD-GLIBC-VENDOR-GNU",
      "source": "PROD-GLIBC",
      "target": "VENDOR-GNU",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "GNU C Library (glibc) is developed and maintained by GNU Project / FSF."
    },
    {
      "id": "REL-AUTO-CVE-2026-0915-PROD-GLIBC",
      "source": "CVE-2026-0915",
      "target": "PROD-GLIBC",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in GNU C Library (glibc) documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-AWS-AGENTCORE-VENDOR-AMAZON",
      "source": "PROD-AWS-AGENTCORE",
      "target": "VENDOR-AMAZON",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "AWS Bedrock AgentCore CLI is developed and maintained by Amazon Web Services."
    },
    {
      "id": "REL-AUTO-CVE-2026-11393-PROD-AWS-AGENTCORE",
      "source": "CVE-2026-11393",
      "target": "PROD-AWS-AGENTCORE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in AWS Bedrock AgentCore CLI documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-11393-AAP-003",
      "source": "CVE-2026-11393",
      "target": "AAP-003",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-11393 weaponizes the agentic attack pattern formalized under AAP-003."
    },
    {
      "id": "REL-AUTO-CVE-2026-11393-AAP-007",
      "source": "CVE-2026-11393",
      "target": "AAP-007",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-11393 weaponizes the agentic attack pattern formalized under AAP-007."
    },
    {
      "id": "REL-AUTO-CVE-2026-11393-T1059",
      "source": "CVE-2026-11393",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-11393-T1552",
      "source": "CVE-2026-11393",
      "target": "T1552",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552."
    },
    {
      "id": "REL-AUTO-PROD-CPYTHON-VENDOR-PYTHON",
      "source": "PROD-CPYTHON",
      "target": "VENDOR-PYTHON",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "CPython Interpreter & Standard Library is developed and maintained by Python Software Foundation."
    },
    {
      "id": "REL-AUTO-CVE-2026-11940-PROD-CPYTHON",
      "source": "CVE-2026-11940",
      "target": "PROD-CPYTHON",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in CPython Interpreter & Standard Library documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-POSTGRESQL-ANON-VENDOR-DALIBO",
      "source": "PROD-POSTGRESQL-ANON",
      "target": "VENDOR-DALIBO",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "PostgreSQL Anonymizer (anon) is developed and maintained by Dalibo."
    },
    {
      "id": "REL-AUTO-CVE-2026-11945-PROD-POSTGRESQL-ANON",
      "source": "CVE-2026-11945",
      "target": "PROD-POSTGRESQL-ANON",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in PostgreSQL Anonymizer (anon) documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-11972-PROD-CPYTHON",
      "source": "CVE-2026-11972",
      "target": "PROD-CPYTHON",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in CPython Interpreter & Standard Library documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-11972-T1059",
      "source": "CVE-2026-11972",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-PROD-PGADMIN-VENDOR-PGADMIN",
      "source": "PROD-PGADMIN",
      "target": "VENDOR-PGADMIN",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "pgAdmin PostgreSQL Tools is developed and maintained by pgAdmin Development Team."
    },
    {
      "id": "REL-AUTO-CVE-2026-12045-PROD-PGADMIN",
      "source": "CVE-2026-12045",
      "target": "PROD-PGADMIN",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in pgAdmin PostgreSQL Tools documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-12045-T1059",
      "source": "CVE-2026-12045",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-PROD-IVANTI-ITSM-VENDOR-IVANTI",
      "source": "PROD-IVANTI-ITSM",
      "target": "VENDOR-IVANTI",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Ivanti Neurons for ITSM is developed and maintained by Ivanti."
    },
    {
      "id": "REL-AUTO-CVE-2026-12645-PROD-IVANTI-ITSM",
      "source": "CVE-2026-12645",
      "target": "PROD-IVANTI-ITSM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Ivanti Neurons for ITSM documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-12645-T1059",
      "source": "CVE-2026-12645",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-12646-PROD-IVANTI-ITSM",
      "source": "CVE-2026-12646",
      "target": "PROD-IVANTI-ITSM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Ivanti Neurons for ITSM documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-12646-T1059",
      "source": "CVE-2026-12646",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-12647-PROD-IVANTI-ITSM",
      "source": "CVE-2026-12647",
      "target": "PROD-IVANTI-ITSM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Ivanti Neurons for ITSM documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-12647-T1059",
      "source": "CVE-2026-12647",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-12648-PROD-IVANTI-ITSM",
      "source": "CVE-2026-12648",
      "target": "PROD-IVANTI-ITSM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Ivanti Neurons for ITSM documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-12648-T1059",
      "source": "CVE-2026-12648",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-12650-PROD-IVANTI-ITSM",
      "source": "CVE-2026-12650",
      "target": "PROD-IVANTI-ITSM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Ivanti Neurons for ITSM documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-12650-T1059",
      "source": "CVE-2026-12650",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-12651-PROD-IVANTI-ITSM",
      "source": "CVE-2026-12651",
      "target": "PROD-IVANTI-ITSM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Ivanti Neurons for ITSM documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-12651-T1059",
      "source": "CVE-2026-12651",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-12744-PROD-IVANTI-ITSM",
      "source": "CVE-2026-12744",
      "target": "PROD-IVANTI-ITSM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Ivanti Neurons for ITSM documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-12744-T1059",
      "source": "CVE-2026-12744",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-12745-PROD-IVANTI-ITSM",
      "source": "CVE-2026-12745",
      "target": "PROD-IVANTI-ITSM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Ivanti Neurons for ITSM documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-12745-T1059",
      "source": "CVE-2026-12745",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-PROD-IVANTI-EPMM-VENDOR-IVANTI",
      "source": "PROD-IVANTI-EPMM",
      "target": "VENDOR-IVANTI",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Ivanti Endpoint Manager Mobile (EPMM) is developed and maintained by Ivanti."
    },
    {
      "id": "REL-AUTO-CVE-2026-1340-PROD-IVANTI-EPMM",
      "source": "CVE-2026-1340",
      "target": "PROD-IVANTI-EPMM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Ivanti Endpoint Manager Mobile (EPMM) documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-14894-PROD-OFFICE",
      "source": "CVE-2026-14894",
      "target": "PROD-OFFICE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Office & 365 Apps documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-15308-PROD-CPYTHON",
      "source": "CVE-2026-15308",
      "target": "PROD-CPYTHON",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in CPython Interpreter & Standard Library documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-15308-T1059",
      "source": "CVE-2026-15308",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-16356-PROD-WINDOWS",
      "source": "CVE-2026-16356",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-CONTEXTFORGE-VENDOR-IBM",
      "source": "PROD-CONTEXTFORGE",
      "target": "VENDOR-IBM",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "IBM ContextForge MCP Gateway is developed and maintained by IBM Corporation."
    },
    {
      "id": "REL-AUTO-CVE-2026-18486-PROD-CONTEXTFORGE",
      "source": "CVE-2026-18486",
      "target": "PROD-CONTEXTFORGE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in IBM ContextForge MCP Gateway documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-18503-PROD-CPYTHON",
      "source": "CVE-2026-18503",
      "target": "PROD-CPYTHON",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in CPython Interpreter & Standard Library documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-18503-T1059",
      "source": "CVE-2026-18503",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-18851-PROD-IVANTI-EPMM",
      "source": "CVE-2026-18851",
      "target": "PROD-IVANTI-EPMM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Ivanti Endpoint Manager Mobile (EPMM) documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-18851-T1059",
      "source": "CVE-2026-18851",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-19490-PROD-NETSCALER",
      "source": "CVE-2026-19490",
      "target": "PROD-NETSCALER",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Citrix NetScaler ADC documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-POSTGRESQL-VENDOR-POSTGRESQL",
      "source": "PROD-POSTGRESQL",
      "target": "VENDOR-POSTGRESQL",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "PostgreSQL Database Server is developed and maintained by PostgreSQL Global Development Group."
    },
    {
      "id": "REL-AUTO-CVE-2026-2006-PROD-POSTGRESQL",
      "source": "CVE-2026-2006",
      "target": "PROD-POSTGRESQL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in PostgreSQL Database Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-2007-PROD-POSTGRESQL",
      "source": "CVE-2026-2007",
      "target": "PROD-POSTGRESQL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in PostgreSQL Database Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-CISCO-FMC-VENDOR-CISCO",
      "source": "PROD-CISCO-FMC",
      "target": "VENDOR-CISCO",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Cisco Secure Firewall Management Center is developed and maintained by Cisco Systems."
    },
    {
      "id": "REL-AUTO-CVE-2026-20079-PROD-CISCO-FMC",
      "source": "CVE-2026-20079",
      "target": "PROD-CISCO-FMC",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Cisco Secure Firewall Management Center documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-20147-PROD-CISCO-ISE",
      "source": "CVE-2026-20147",
      "target": "PROD-CISCO-ISE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Cisco Identity Services Engine (ISE) documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-20180-PROD-CISCO-ISE",
      "source": "CVE-2026-20180",
      "target": "PROD-CISCO-ISE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Cisco Identity Services Engine (ISE) documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-20186-PROD-CISCO-ISE",
      "source": "CVE-2026-20186",
      "target": "PROD-CISCO-ISE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Cisco Identity Services Engine (ISE) documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-20192-PROD-CISCO-ISE",
      "source": "CVE-2026-20192",
      "target": "PROD-CISCO-ISE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Cisco Identity Services Engine (ISE) documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-20307-PROD-CISCO-ISE",
      "source": "CVE-2026-20307",
      "target": "PROD-CISCO-ISE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Cisco Identity Services Engine (ISE) documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-20324-PROD-CISCO-FMC",
      "source": "CVE-2026-20324",
      "target": "PROD-CISCO-FMC",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Cisco Secure Firewall Management Center documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-21510-PROD-WINDOWS",
      "source": "CVE-2026-21510",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-21643-PROD-FORTIOS",
      "source": "CVE-2026-21643",
      "target": "PROD-FORTIOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Fortinet FortiOS Gateway documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-21669-PROD-VEEAM-VBR",
      "source": "CVE-2026-21669",
      "target": "PROD-VEEAM-VBR",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Veeam Backup & Replication documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-21670-PROD-VEEAM-VBR",
      "source": "CVE-2026-21670",
      "target": "PROD-VEEAM-VBR",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Veeam Backup & Replication documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-21671-PROD-VEEAM-VBR",
      "source": "CVE-2026-21671",
      "target": "PROD-VEEAM-VBR",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Veeam Backup & Replication documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-21672-PROD-VEEAM-VBR",
      "source": "CVE-2026-21672",
      "target": "PROD-VEEAM-VBR",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Veeam Backup & Replication documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-21708-PROD-VEEAM-VBR",
      "source": "CVE-2026-21708",
      "target": "PROD-VEEAM-VBR",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Veeam Backup & Replication documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-WEBLOGIC-VENDOR-ORACLE",
      "source": "PROD-WEBLOGIC",
      "target": "VENDOR-ORACLE",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Oracle WebLogic Server is developed and maintained by Oracle Corporation."
    },
    {
      "id": "REL-AUTO-CVE-2026-21962-PROD-WEBLOGIC",
      "source": "CVE-2026-21962",
      "target": "PROD-WEBLOGIC",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Oracle WebLogic Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-21962-T1059",
      "source": "CVE-2026-21962",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-22153-PROD-FORTIOS",
      "source": "CVE-2026-22153",
      "target": "PROD-FORTIOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Fortinet FortiOS Gateway documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-22708-PROD-WINDOWS",
      "source": "CVE-2026-22708",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-22778-PROD-VLLM",
      "source": "CVE-2026-22778",
      "target": "PROD-VLLM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in vLLM Inference Engine documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-22807-PROD-VLLM",
      "source": "CVE-2026-22807",
      "target": "PROD-VLLM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in vLLM Inference Engine documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-22807-AAP-007",
      "source": "CVE-2026-22807",
      "target": "AAP-007",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-22807 weaponizes the agentic attack pattern formalized under AAP-007."
    },
    {
      "id": "REL-AUTO-CVE-2026-22807-AAP-004",
      "source": "CVE-2026-22807",
      "target": "AAP-004",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-22807 weaponizes the agentic attack pattern formalized under AAP-004."
    },
    {
      "id": "REL-AUTO-CVE-2026-23246-PROD-LINUX-KERNEL",
      "source": "CVE-2026-23246",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-23269-PROD-LINUX-KERNEL",
      "source": "CVE-2026-23269",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-23288-PROD-LINUX-KERNEL",
      "source": "CVE-2026-23288",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-23432-PROD-LINUX-KERNEL",
      "source": "CVE-2026-23432",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-2360-PROD-POSTGRESQL-ANON",
      "source": "CVE-2026-2360",
      "target": "PROD-POSTGRESQL-ANON",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in PostgreSQL Anonymizer (anon) documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-23772-PROD-WINDOWS",
      "source": "CVE-2026-23772",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-24307-PROD-M365-COPILOT",
      "source": "CVE-2026-24307",
      "target": "PROD-M365-COPILOT",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft 365 Copilot documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-24307-AAP-001",
      "source": "CVE-2026-24307",
      "target": "AAP-001",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-24307 weaponizes the agentic attack pattern formalized under AAP-001."
    },
    {
      "id": "REL-AUTO-CVE-2026-24858-PROD-FORTIOS",
      "source": "CVE-2026-24858",
      "target": "PROD-FORTIOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Fortinet FortiOS Gateway documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-25089-PROD-FORTIOS",
      "source": "CVE-2026-25089",
      "target": "PROD-FORTIOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Fortinet FortiOS Gateway documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-25089-T1059",
      "source": "CVE-2026-25089",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-25724-PROD-CLAUDE-CODE",
      "source": "CVE-2026-25724",
      "target": "PROD-CLAUDE-CODE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Claude Code Agentic CLI documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-25724-AAP-002",
      "source": "CVE-2026-25724",
      "target": "AAP-002",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-25724 weaponizes the agentic attack pattern formalized under AAP-002."
    },
    {
      "id": "REL-AUTO-CVE-2026-25724-AAP-003",
      "source": "CVE-2026-25724",
      "target": "AAP-003",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-25724 weaponizes the agentic attack pattern formalized under AAP-003."
    },
    {
      "id": "REL-AUTO-PROD-LANGGRAPH-VENDOR-LANGCHAIN",
      "source": "PROD-LANGGRAPH",
      "target": "VENDOR-LANGCHAIN",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "LangGraph Multi-Agent Runtime is developed and maintained by LangChain Inc."
    },
    {
      "id": "REL-AUTO-CVE-2026-25750-PROD-LANGGRAPH",
      "source": "CVE-2026-25750",
      "target": "PROD-LANGGRAPH",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in LangGraph Multi-Agent Runtime documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-27825-PROD-LANGGRAPH",
      "source": "CVE-2026-27825",
      "target": "PROD-LANGGRAPH",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in LangGraph Multi-Agent Runtime documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-27826-PROD-LANGGRAPH",
      "source": "CVE-2026-27826",
      "target": "PROD-LANGGRAPH",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in LangGraph Multi-Agent Runtime documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-27966-PROD-LANGFLOW",
      "source": "CVE-2026-27966",
      "target": "PROD-LANGFLOW",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Langflow Visual AI Builder documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-27966-AAP-007",
      "source": "CVE-2026-27966",
      "target": "AAP-007",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-27966 weaponizes the agentic attack pattern formalized under AAP-007."
    },
    {
      "id": "REL-AUTO-CVE-2026-27966-AAP-003",
      "source": "CVE-2026-27966",
      "target": "AAP-003",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-27966 weaponizes the agentic attack pattern formalized under AAP-003."
    },
    {
      "id": "REL-AUTO-PROD-SOLARWINDS-ARM-VENDOR-SOLARWINDS",
      "source": "PROD-SOLARWINDS-ARM",
      "target": "VENDOR-SOLARWINDS",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "SolarWinds Access Rights Manager is developed and maintained by SolarWinds."
    },
    {
      "id": "REL-AUTO-CVE-2026-28326-PROD-SOLARWINDS-ARM",
      "source": "CVE-2026-28326",
      "target": "PROD-SOLARWINDS-ARM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in SolarWinds Access Rights Manager documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-3055-PROD-NETSCALER",
      "source": "CVE-2026-3055",
      "target": "PROD-NETSCALER",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Citrix NetScaler ADC documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-LITELLM-VENDOR-BERRIAI",
      "source": "PROD-LITELLM",
      "target": "VENDOR-BERRIAI",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "LiteLLM Proxy & MCP Server is developed and maintained by BerriAI."
    },
    {
      "id": "REL-AUTO-CVE-2026-30615-PROD-LITELLM",
      "source": "CVE-2026-30615",
      "target": "PROD-LITELLM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in LiteLLM Proxy & MCP Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-30617-PROD-LANGGRAPH",
      "source": "CVE-2026-30617",
      "target": "PROD-LANGGRAPH",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in LangGraph Multi-Agent Runtime documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-30623-PROD-LITELLM",
      "source": "CVE-2026-30623",
      "target": "PROD-LITELLM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in LiteLLM Proxy & MCP Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-SNORKEL-VENDOR-SNORKEL",
      "source": "PROD-SNORKEL",
      "target": "VENDOR-SNORKEL",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Snorkel Programmatic Labeling is developed and maintained by Snorkel AI."
    },
    {
      "id": "REL-AUTO-CVE-2026-31223-PROD-SNORKEL",
      "source": "CVE-2026-31223",
      "target": "PROD-SNORKEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Snorkel Programmatic Labeling documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-31223-T1059",
      "source": "CVE-2026-31223",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-PROD-APACHE-DORIS-VENDOR-APACHE",
      "source": "PROD-APACHE-DORIS",
      "target": "VENDOR-APACHE",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Apache Doris MPP Database is developed and maintained by Apache Software Foundation."
    },
    {
      "id": "REL-AUTO-CVE-2026-31377-PROD-APACHE-DORIS",
      "source": "CVE-2026-31377",
      "target": "PROD-APACHE-DORIS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Apache Doris MPP Database documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-31377-AAP-003",
      "source": "CVE-2026-31377",
      "target": "AAP-003",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-31377 weaponizes the agentic attack pattern formalized under AAP-003."
    },
    {
      "id": "REL-AUTO-CVE-2026-31377-AAP-006",
      "source": "CVE-2026-31377",
      "target": "AAP-006",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-31377 weaponizes the agentic attack pattern formalized under AAP-006."
    },
    {
      "id": "REL-AUTO-CVE-2026-31430-PROD-LINUX-KERNEL",
      "source": "CVE-2026-31430",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-31431-PROD-LINUX-KERNEL",
      "source": "CVE-2026-31431",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-31633-PROD-LINUX-KERNEL",
      "source": "CVE-2026-31633",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-31718-PROD-LINUX-KERNEL",
      "source": "CVE-2026-31718",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-QEMU-VENDOR-QEMU",
      "source": "PROD-QEMU",
      "target": "VENDOR-QEMU",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "QEMU Machine Emulator is developed and maintained by QEMU Project."
    },
    {
      "id": "REL-AUTO-CVE-2026-3195-PROD-QEMU",
      "source": "CVE-2026-3195",
      "target": "PROD-QEMU",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in QEMU Machine Emulator documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-ANYTHINGLLM-VENDOR-MINTPLEX",
      "source": "PROD-ANYTHINGLLM",
      "target": "VENDOR-MINTPLEX",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "AnythingLLM Desktop & Workspace is developed and maintained by Mintplex Labs."
    },
    {
      "id": "REL-AUTO-CVE-2026-32626-PROD-ANYTHINGLLM",
      "source": "CVE-2026-32626",
      "target": "PROD-ANYTHINGLLM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in AnythingLLM Desktop & Workspace documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-32997-PROD-VEEAM-VBR",
      "source": "CVE-2026-32997",
      "target": "PROD-VEEAM-VBR",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Veeam Backup & Replication documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-33017-PROD-LANGFLOW",
      "source": "CVE-2026-33017",
      "target": "PROD-LANGFLOW",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Langflow Visual AI Builder documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-LMDEPLOY-VENDOR-OPENMMLAB",
      "source": "PROD-LMDEPLOY",
      "target": "VENDOR-OPENMMLAB",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "LMDeploy Serving Engine is developed and maintained by OpenMMLab."
    },
    {
      "id": "REL-AUTO-CVE-2026-33626-PROD-LMDEPLOY",
      "source": "CVE-2026-33626",
      "target": "PROD-LMDEPLOY",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in LMDeploy Serving Engine documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-33626-AAP-007",
      "source": "CVE-2026-33626",
      "target": "AAP-007",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-33626 weaponizes the agentic attack pattern formalized under AAP-007."
    },
    {
      "id": "REL-AUTO-CVE-2026-33634-PROD-OFFICE",
      "source": "CVE-2026-33634",
      "target": "PROD-OFFICE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Office & 365 Apps documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-33634-T1059",
      "source": "CVE-2026-33634",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-33634-T1552",
      "source": "CVE-2026-33634",
      "target": "T1552",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552."
    },
    {
      "id": "REL-AUTO-CVE-2026-33825-PROD-WINDOWS",
      "source": "CVE-2026-33825",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-33873-PROD-LANGFLOW",
      "source": "CVE-2026-33873",
      "target": "PROD-LANGFLOW",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Langflow Visual AI Builder documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-33873-AAP-003",
      "source": "CVE-2026-33873",
      "target": "AAP-003",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-33873 weaponizes the agentic attack pattern formalized under AAP-003."
    },
    {
      "id": "REL-AUTO-CVE-2026-33873-AAP-007",
      "source": "CVE-2026-33873",
      "target": "AAP-007",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-33873 weaponizes the agentic attack pattern formalized under AAP-007."
    },
    {
      "id": "REL-AUTO-PROD-OPENSSL-VENDOR-OPENSSL",
      "source": "PROD-OPENSSL",
      "target": "VENDOR-OPENSSL",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "OpenSSL Cryptographic Library is developed and maintained by OpenSSL Project."
    },
    {
      "id": "REL-AUTO-CVE-2026-34183-PROD-OPENSSL",
      "source": "CVE-2026-34183",
      "target": "PROD-OPENSSL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in OpenSSL Cryptographic Library documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-35188-PROD-OPENSSL",
      "source": "CVE-2026-35188",
      "target": "PROD-OPENSSL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in OpenSSL Cryptographic Library documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-OPENSSH-VENDOR-OPENBSD",
      "source": "PROD-OPENSSH",
      "target": "VENDOR-OPENBSD",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "OpenSSH Suite is developed and maintained by OpenBSD Foundation."
    },
    {
      "id": "REL-AUTO-CVE-2026-35385-PROD-OPENSSH",
      "source": "CVE-2026-35385",
      "target": "PROD-OPENSSH",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in OpenSSH Suite documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-37008-PROD-CPYTHON",
      "source": "CVE-2026-37008",
      "target": "PROD-CPYTHON",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in CPython Interpreter & Standard Library documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-MYSQL-VENDOR-ORACLE",
      "source": "PROD-MYSQL",
      "target": "VENDOR-ORACLE",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Oracle MySQL Server & Database Engine is developed and maintained by Oracle Corporation."
    },
    {
      "id": "REL-AUTO-CVE-2026-37338-PROD-MYSQL",
      "source": "CVE-2026-37338",
      "target": "PROD-MYSQL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Oracle MySQL Server & Database Engine documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-39808-PROD-FORTIOS",
      "source": "CVE-2026-39808",
      "target": "PROD-FORTIOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Fortinet FortiOS Gateway documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-39808-T1059",
      "source": "CVE-2026-39808",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-39842-PROD-OFFICE",
      "source": "CVE-2026-39842",
      "target": "PROD-OFFICE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Office & 365 Apps documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-40087-PROD-LANGGRAPH",
      "source": "CVE-2026-40087",
      "target": "PROD-LANGGRAPH",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in LangGraph Multi-Agent Runtime documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-40087-AAP-001",
      "source": "CVE-2026-40087",
      "target": "AAP-001",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-40087 weaponizes the agentic attack pattern formalized under AAP-001."
    },
    {
      "id": "REL-AUTO-CVE-2026-40087-AAP-002",
      "source": "CVE-2026-40087",
      "target": "AAP-002",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-40087 weaponizes the agentic attack pattern formalized under AAP-002."
    },
    {
      "id": "REL-AUTO-PROD-PILLOW-VENDOR-PILLOW",
      "source": "PROD-PILLOW",
      "target": "VENDOR-PILLOW",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Pillow Python Imaging Library is developed and maintained by Pillow Community."
    },
    {
      "id": "REL-AUTO-CVE-2026-40192-PROD-PILLOW",
      "source": "CVE-2026-40192",
      "target": "PROD-PILLOW",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Pillow Python Imaging Library documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-SYSTEMD-VENDOR-SYSTEMD",
      "source": "PROD-SYSTEMD",
      "target": "VENDOR-SYSTEMD",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "systemd System Manager is developed and maintained by systemd Community."
    },
    {
      "id": "REL-AUTO-CVE-2026-40227-PROD-SYSTEMD",
      "source": "CVE-2026-40227",
      "target": "PROD-SYSTEMD",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in systemd System Manager documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-40933-PROD-FLOWISE",
      "source": "CVE-2026-40933",
      "target": "PROD-FLOWISE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Flowise AI Workflow Builder documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-LCMS2-VENDOR-LCMS",
      "source": "PROD-LCMS2",
      "target": "VENDOR-LCMS",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Little CMS (lcms2) is developed and maintained by Little CMS Project."
    },
    {
      "id": "REL-AUTO-CVE-2026-41254-PROD-LCMS2",
      "source": "CVE-2026-41254",
      "target": "PROD-LCMS2",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Little CMS (lcms2) documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-41264-PROD-FLOWISE",
      "source": "CVE-2026-41264",
      "target": "PROD-FLOWISE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Flowise AI Workflow Builder documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-SPRING-FRAMEWORK-VENDOR-VMWARE-SPRING",
      "source": "PROD-SPRING-FRAMEWORK",
      "target": "VENDOR-VMWARE-SPRING",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Spring Framework is developed and maintained by Broadcom / Spring."
    },
    {
      "id": "REL-AUTO-CVE-2026-41843-PROD-SPRING-FRAMEWORK",
      "source": "CVE-2026-41843",
      "target": "PROD-SPRING-FRAMEWORK",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Spring Framework documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-41849-PROD-SPRING-FRAMEWORK",
      "source": "CVE-2026-41849",
      "target": "PROD-SPRING-FRAMEWORK",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Spring Framework documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-ARTIFACTORY-VENDOR-JFROG",
      "source": "PROD-ARTIFACTORY",
      "target": "VENDOR-JFROG",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "JFrog Artifactory is developed and maintained by JFrog Ltd."
    },
    {
      "id": "REL-AUTO-CVE-2026-42016-PROD-ARTIFACTORY",
      "source": "CVE-2026-42016",
      "target": "PROD-ARTIFACTORY",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in JFrog Artifactory documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-42018-PROD-ARTIFACTORY",
      "source": "CVE-2026-42018",
      "target": "PROD-ARTIFACTORY",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in JFrog Artifactory documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-42208-PROD-LITELLM",
      "source": "CVE-2026-42208",
      "target": "PROD-LITELLM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in LiteLLM Proxy & MCP Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-42249-PROD-WINDOWS",
      "source": "CVE-2026-42249",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-42271-PROD-LITELLM",
      "source": "CVE-2026-42271",
      "target": "PROD-LITELLM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in LiteLLM Proxy & MCP Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-42271-T1059",
      "source": "CVE-2026-42271",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-42271-T1552",
      "source": "CVE-2026-42271",
      "target": "T1552",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552."
    },
    {
      "id": "REL-AUTO-CVE-2026-43114-PROD-LINUX-KERNEL",
      "source": "CVE-2026-43114",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-43133-PROD-LINUX-KERNEL",
      "source": "CVE-2026-43133",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-43386-PROD-LINUX-KERNEL",
      "source": "CVE-2026-43386",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-HF-TRANSFORMERS-VENDOR-HUGGINGFACE",
      "source": "PROD-HF-TRANSFORMERS",
      "target": "VENDOR-HUGGINGFACE",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Hugging Face Transformers Library is developed and maintained by Hugging Face Inc.."
    },
    {
      "id": "REL-AUTO-CVE-2026-4372-PROD-HF-TRANSFORMERS",
      "source": "CVE-2026-4372",
      "target": "PROD-HF-TRANSFORMERS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Hugging Face Transformers Library documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-4372-AAP-005",
      "source": "CVE-2026-4372",
      "target": "AAP-005",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-4372 weaponizes the agentic attack pattern formalized under AAP-005."
    },
    {
      "id": "REL-AUTO-CVE-2026-44963-PROD-VEEAM-VBR",
      "source": "CVE-2026-44963",
      "target": "PROD-VEEAM-VBR",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Veeam Backup & Replication documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-4519-PROD-CPYTHON",
      "source": "CVE-2026-4519",
      "target": "PROD-CPYTHON",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in CPython Interpreter & Standard Library documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-4519-T1059",
      "source": "CVE-2026-4519",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-PROD-GITLAB-VENDOR-GITLAB",
      "source": "PROD-GITLAB",
      "target": "VENDOR-GITLAB",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "GitLab Community & Enterprise Edition is developed and maintained by GitLab Inc.."
    },
    {
      "id": "REL-AUTO-CVE-2026-45321-PROD-GITLAB",
      "source": "CVE-2026-45321",
      "target": "PROD-GITLAB",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in GitLab Community & Enterprise Edition documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-45321-T1059",
      "source": "CVE-2026-45321",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-45321-T1552",
      "source": "CVE-2026-45321",
      "target": "T1552",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552."
    },
    {
      "id": "REL-AUTO-PROD-THEIA-VENDOR-ECLIPSE",
      "source": "PROD-THEIA",
      "target": "VENDOR-ECLIPSE",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Eclipse Theia IDE is developed and maintained by Eclipse Foundation."
    },
    {
      "id": "REL-AUTO-CVE-2026-46580-PROD-THEIA",
      "source": "CVE-2026-46580",
      "target": "PROD-THEIA",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Eclipse Theia IDE documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-MYSQL-SHELL-VENDOR-ORACLE",
      "source": "PROD-MYSQL-SHELL",
      "target": "VENDOR-ORACLE",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Oracle MySQL Shell & VS Code Extension is developed and maintained by Oracle Corporation."
    },
    {
      "id": "REL-AUTO-CVE-2026-46850-PROD-MYSQL-SHELL",
      "source": "CVE-2026-46850",
      "target": "PROD-MYSQL-SHELL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Oracle MySQL Shell & VS Code Extension documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-MYSQL-ROUTER-VENDOR-ORACLE",
      "source": "PROD-MYSQL-ROUTER",
      "target": "VENDOR-ORACLE",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Oracle MySQL Router is developed and maintained by Oracle Corporation."
    },
    {
      "id": "REL-AUTO-CVE-2026-46860-PROD-MYSQL-ROUTER",
      "source": "CVE-2026-46860",
      "target": "PROD-MYSQL-ROUTER",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Oracle MySQL Router documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-MYSQL-NDB-VENDOR-ORACLE",
      "source": "PROD-MYSQL-NDB",
      "target": "VENDOR-ORACLE",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Oracle MySQL NDB Cluster is developed and maintained by Oracle Corporation."
    },
    {
      "id": "REL-AUTO-CVE-2026-46861-PROD-MYSQL-NDB",
      "source": "CVE-2026-46861",
      "target": "PROD-MYSQL-NDB",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Oracle MySQL NDB Cluster documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-46862-PROD-MYSQL-ROUTER",
      "source": "CVE-2026-46862",
      "target": "PROD-MYSQL-ROUTER",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Oracle MySQL Router documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-46870-PROD-MYSQL-SHELL",
      "source": "CVE-2026-46870",
      "target": "PROD-MYSQL-SHELL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Oracle MySQL Shell & VS Code Extension documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-ORACLE-JAVA-VENDOR-ORACLE",
      "source": "PROD-ORACLE-JAVA",
      "target": "VENDOR-ORACLE",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Oracle Java SE & OpenJDK Runtime is developed and maintained by Oracle Corporation."
    },
    {
      "id": "REL-AUTO-CVE-2026-47057-PROD-ORACLE-JAVA",
      "source": "CVE-2026-47057",
      "target": "PROD-ORACLE-JAVA",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Oracle Java SE & OpenJDK Runtime documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-47058-PROD-ORACLE-JAVA",
      "source": "CVE-2026-47058",
      "target": "PROD-ORACLE-JAVA",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Oracle Java SE & OpenJDK Runtime documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-47063-PROD-ORACLE-JAVA",
      "source": "CVE-2026-47063",
      "target": "PROD-ORACLE-JAVA",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Oracle Java SE & OpenJDK Runtime documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-STARLETTE-VENDOR-KLUDEX",
      "source": "PROD-STARLETTE",
      "target": "VENDOR-KLUDEX",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Starlette / FastAPI ASGI Framework is developed and maintained by Kludex."
    },
    {
      "id": "REL-AUTO-CVE-2026-48710-PROD-STARLETTE",
      "source": "CVE-2026-48710",
      "target": "PROD-STARLETTE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Starlette / FastAPI ASGI Framework documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-48746-PROD-VLLM",
      "source": "CVE-2026-48746",
      "target": "PROD-VLLM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in vLLM Inference Engine documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-48746-AAP-006",
      "source": "CVE-2026-48746",
      "target": "AAP-006",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-48746 weaponizes the agentic attack pattern formalized under AAP-006."
    },
    {
      "id": "REL-AUTO-CVE-2026-49179-PROD-WINDOWS",
      "source": "CVE-2026-49179",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-49869-PROD-CPYTHON",
      "source": "CVE-2026-49869",
      "target": "PROD-CPYTHON",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in CPython Interpreter & Standard Library documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-49869-T1059",
      "source": "CVE-2026-49869",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-49869-T1552",
      "source": "CVE-2026-49869",
      "target": "T1552",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552."
    },
    {
      "id": "REL-AUTO-CVE-2026-5002-PROD-OFFICE",
      "source": "CVE-2026-5002",
      "target": "PROD-OFFICE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Office & 365 Apps documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-5027-PROD-LANGFLOW",
      "source": "CVE-2026-5027",
      "target": "PROD-LANGFLOW",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Langflow Visual AI Builder documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-5027-AAP-007",
      "source": "CVE-2026-5027",
      "target": "AAP-007",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-5027 weaponizes the agentic attack pattern formalized under AAP-007."
    },
    {
      "id": "REL-AUTO-CVE-2026-5027-T1059",
      "source": "CVE-2026-5027",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-50346-PROD-WINDOWS",
      "source": "CVE-2026-50346",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-50391-PROD-WINDOWS",
      "source": "CVE-2026-50391",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-50481-PROD-WINDOWS",
      "source": "CVE-2026-50481",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-50500-PROD-WINDOWS",
      "source": "CVE-2026-50500",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-50522-PROD-WINDOWS",
      "source": "CVE-2026-50522",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-50522-T1059",
      "source": "CVE-2026-50522",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-50522-T1552",
      "source": "CVE-2026-50522",
      "target": "T1552",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552."
    },
    {
      "id": "REL-AUTO-CVE-2026-5059-PROD-AWS-MCP-SERVER",
      "source": "CVE-2026-5059",
      "target": "PROD-AWS-MCP-SERVER",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in AWS MCP Server Suite documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-52924-PROD-LINUX-KERNEL",
      "source": "CVE-2026-52924",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-52933-PROD-LINUX-KERNEL",
      "source": "CVE-2026-52933",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-53266-PROD-LINUX-KERNEL",
      "source": "CVE-2026-53266",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-5364-PROD-OFFICE",
      "source": "CVE-2026-5364",
      "target": "PROD-OFFICE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Office & 365 Apps documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-54236-PROD-VLLM",
      "source": "CVE-2026-54236",
      "target": "PROD-VLLM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in vLLM Inference Engine documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-54236-AAP-006",
      "source": "CVE-2026-54236",
      "target": "AAP-006",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-54236 weaponizes the agentic attack pattern formalized under AAP-006."
    },
    {
      "id": "REL-AUTO-PROD-PGJDBC-VENDOR-PGJDBC",
      "source": "PROD-PGJDBC",
      "target": "VENDOR-PGJDBC",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "PostgreSQL JDBC Driver is developed and maintained by PostgreSQL JDBC Project."
    },
    {
      "id": "REL-AUTO-CVE-2026-54291-PROD-PGJDBC",
      "source": "CVE-2026-54291",
      "target": "PROD-PGJDBC",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in PostgreSQL JDBC Driver documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-55040-PROD-WINDOWS",
      "source": "CVE-2026-55040",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-55653-PROD-OPENSSH",
      "source": "CVE-2026-55653",
      "target": "PROD-OPENSSH",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in OpenSSH Suite documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-57967-PROD-OFFICE",
      "source": "CVE-2026-57967",
      "target": "PROD-OFFICE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Office & 365 Apps documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-58070-PROD-VEEAM-VBR",
      "source": "CVE-2026-58070",
      "target": "PROD-VEEAM-VBR",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Veeam Backup & Replication documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-5809-PROD-OFFICE",
      "source": "CVE-2026-5809",
      "target": "PROD-OFFICE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Office & 365 Apps documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-WP-BLOCKSY-VENDOR-CREATIVETHEMES",
      "source": "PROD-WP-BLOCKSY",
      "target": "VENDOR-CREATIVETHEMES",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Blocksy Companion Pro is developed and maintained by Creative Themes."
    },
    {
      "id": "REL-AUTO-CVE-2026-58480-PROD-WP-BLOCKSY",
      "source": "CVE-2026-58480",
      "target": "PROD-WP-BLOCKSY",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Blocksy Companion Pro documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-58599-PROD-WINDOWS",
      "source": "CVE-2026-58599",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-58644-PROD-WINDOWS",
      "source": "CVE-2026-58644",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-58644-T1059",
      "source": "CVE-2026-58644",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-58704-PROD-LINUX-KERNEL",
      "source": "CVE-2026-58704",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-59310-PROD-CPYTHON",
      "source": "CVE-2026-59310",
      "target": "PROD-CPYTHON",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in CPython Interpreter & Standard Library documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-5966-PROD-WINDOWS",
      "source": "CVE-2026-5966",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-59822-PROD-LITELLM",
      "source": "CVE-2026-59822",
      "target": "PROD-LITELLM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in LiteLLM Proxy & MCP Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-59837-PROD-FORTIOS",
      "source": "CVE-2026-59837",
      "target": "PROD-FORTIOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Fortinet FortiOS Gateway documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-59839-PROD-FORTIOS",
      "source": "CVE-2026-59839",
      "target": "PROD-FORTIOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Fortinet FortiOS Gateway documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-59840-PROD-FORTIOS",
      "source": "CVE-2026-59840",
      "target": "PROD-FORTIOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Fortinet FortiOS Gateway documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-60137-PROD-OFFICE",
      "source": "CVE-2026-60137",
      "target": "PROD-OFFICE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Office & 365 Apps documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-60163-PROD-MYSQL",
      "source": "CVE-2026-60163",
      "target": "PROD-MYSQL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Oracle MySQL Server & Database Engine documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-60316-PROD-MYSQL",
      "source": "CVE-2026-60316",
      "target": "PROD-MYSQL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Oracle MySQL Server & Database Engine documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-60592-PROD-MYSQL-NDB",
      "source": "CVE-2026-60592",
      "target": "PROD-MYSQL-NDB",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Oracle MySQL NDB Cluster documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-MYSQL-CONNECTOR-VENDOR-ORACLE",
      "source": "PROD-MYSQL-CONNECTOR",
      "target": "VENDOR-ORACLE",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Oracle MySQL Connector/J is developed and maintained by Oracle Corporation."
    },
    {
      "id": "REL-AUTO-CVE-2026-60623-PROD-MYSQL-CONNECTOR",
      "source": "CVE-2026-60623",
      "target": "PROD-MYSQL-CONNECTOR",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Oracle MySQL Connector/J documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-6100-PROD-CPYTHON",
      "source": "CVE-2026-6100",
      "target": "PROD-CPYTHON",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in CPython Interpreter & Standard Library documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-61094-PROD-MYSQL",
      "source": "CVE-2026-61094",
      "target": "PROD-MYSQL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Oracle MySQL Server & Database Engine documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-61308-PROD-ORACLE-JAVA",
      "source": "CVE-2026-61308",
      "target": "PROD-ORACLE-JAVA",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Oracle Java SE & OpenJDK Runtime documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-62574-PROD-ORACLE-JAVA",
      "source": "CVE-2026-62574",
      "target": "PROD-ORACLE-JAVA",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Oracle Java SE & OpenJDK Runtime documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-62752-PROD-WINDOWS",
      "source": "CVE-2026-62752",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-SUDO-VENDOR-SUDO",
      "source": "PROD-SUDO",
      "target": "VENDOR-SUDO",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Sudo Privilege Manager is developed and maintained by Sudo Project."
    },
    {
      "id": "REL-AUTO-CVE-2026-6276-PROD-SUDO",
      "source": "CVE-2026-6276",
      "target": "PROD-SUDO",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Sudo Privilege Manager documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-62785-PROD-WINDOWS",
      "source": "CVE-2026-62785",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-62818-PROD-WINDOWS",
      "source": "CVE-2026-62818",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-63030-PROD-OFFICE",
      "source": "CVE-2026-63030",
      "target": "PROD-OFFICE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Office & 365 Apps documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-63077-PROD-WINDOWS",
      "source": "CVE-2026-63077",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-63077-T1059",
      "source": "CVE-2026-63077",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-63077-T1552",
      "source": "CVE-2026-63077",
      "target": "T1552",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552."
    },
    {
      "id": "REL-AUTO-CVE-2026-64268-PROD-LINUX-KERNEL",
      "source": "CVE-2026-64268",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-6443-PROD-OFFICE",
      "source": "CVE-2026-6443",
      "target": "PROD-OFFICE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Office & 365 Apps documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-6473-PROD-POSTGRESQL",
      "source": "CVE-2026-6473",
      "target": "PROD-POSTGRESQL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in PostgreSQL Database Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-6476-PROD-POSTGRESQL",
      "source": "CVE-2026-6476",
      "target": "PROD-POSTGRESQL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in PostgreSQL Database Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-64849-PROD-CPYTHON",
      "source": "CVE-2026-64849",
      "target": "PROD-CPYTHON",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in CPython Interpreter & Standard Library documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-64849-T1552",
      "source": "CVE-2026-64849",
      "target": "T1552",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552."
    },
    {
      "id": "REL-AUTO-CVE-2026-6490-PROD-MYSQL",
      "source": "CVE-2026-6490",
      "target": "PROD-MYSQL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Oracle MySQL Server & Database Engine documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-65182-PROD-APACHE-TOMCAT",
      "source": "CVE-2026-65182",
      "target": "PROD-APACHE-TOMCAT",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Apache Tomcat documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-APPLE-MACOS-VENDOR-APPLE",
      "source": "PROD-APPLE-MACOS",
      "target": "VENDOR-APPLE",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Apple macOS Operating System is developed and maintained by Apple Inc."
    },
    {
      "id": "REL-AUTO-CVE-2026-65381-PROD-APPLE-MACOS",
      "source": "CVE-2026-65381",
      "target": "PROD-APPLE-MACOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Apple macOS Operating System documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-65400-PROD-APPLE-MACOS",
      "source": "CVE-2026-65400",
      "target": "PROD-APPLE-MACOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Apple macOS Operating System documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-65400-T1059",
      "source": "CVE-2026-65400",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-65777-PROD-WINDOWS",
      "source": "CVE-2026-65777",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-65927-PROD-APACHE-TOMCAT",
      "source": "CVE-2026-65927",
      "target": "PROD-APACHE-TOMCAT",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Apache Tomcat documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-6596-PROD-LANGFLOW",
      "source": "CVE-2026-6596",
      "target": "PROD-LANGFLOW",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Langflow Visual AI Builder documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-6603-PROD-CPYTHON",
      "source": "CVE-2026-6603",
      "target": "PROD-CPYTHON",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in CPython Interpreter & Standard Library documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-6604-PROD-CPYTHON",
      "source": "CVE-2026-6604",
      "target": "PROD-CPYTHON",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in CPython Interpreter & Standard Library documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-6605-PROD-CPYTHON",
      "source": "CVE-2026-6605",
      "target": "PROD-CPYTHON",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in CPython Interpreter & Standard Library documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-6615-PROD-OFFICE",
      "source": "CVE-2026-6615",
      "target": "PROD-OFFICE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Office & 365 Apps documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-6638-PROD-POSTGRESQL",
      "source": "CVE-2026-6638",
      "target": "PROD-POSTGRESQL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in PostgreSQL Database Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-67277-PROD-FORTIOS",
      "source": "CVE-2026-67277",
      "target": "PROD-FORTIOS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Fortinet FortiOS Gateway documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-68200-PROD-LINUX-KERNEL",
      "source": "CVE-2026-68200",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-69518-PROD-WINDOWS",
      "source": "CVE-2026-69518",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-69579-PROD-WINDOWS",
      "source": "CVE-2026-69579",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-69595-PROD-WINDOWS",
      "source": "CVE-2026-69595",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-69603-PROD-WINDOWS",
      "source": "CVE-2026-69603",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-69649-PROD-WINDOWS",
      "source": "CVE-2026-69649",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-69676-PROD-WINDOWS",
      "source": "CVE-2026-69676",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-69730-PROD-WINDOWS",
      "source": "CVE-2026-69730",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-69845-PROD-WINDOWS",
      "source": "CVE-2026-69845",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-69851-PROD-OFFICE",
      "source": "CVE-2026-69851",
      "target": "PROD-OFFICE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Office & 365 Apps documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-70477-PROD-FLOWISE",
      "source": "CVE-2026-70477",
      "target": "PROD-FLOWISE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Flowise AI Workflow Builder documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-71133-PROD-OFFICE",
      "source": "CVE-2026-71133",
      "target": "PROD-OFFICE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Office & 365 Apps documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-7141-PROD-VLLM",
      "source": "CVE-2026-7141",
      "target": "PROD-VLLM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in vLLM Inference Engine documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-7210-PROD-CPYTHON",
      "source": "CVE-2026-7210",
      "target": "PROD-CPYTHON",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in CPython Interpreter & Standard Library documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-7210-T1059",
      "source": "CVE-2026-7210",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-PROD-ZYXEL-GS1900-VENDOR-ZYXEL",
      "source": "PROD-ZYXEL-GS1900",
      "target": "VENDOR-ZYXEL",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Zyxel GS1900 Smart Switch is developed and maintained by Zyxel Communications."
    },
    {
      "id": "REL-AUTO-CVE-2026-7273-PROD-ZYXEL-GS1900",
      "source": "CVE-2026-7273",
      "target": "PROD-ZYXEL-GS1900",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Zyxel GS1900 Smart Switch documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-72961-PROD-WINDOWS",
      "source": "CVE-2026-72961",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-72979-PROD-WINDOWS",
      "source": "CVE-2026-72979",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-72982-PROD-WINDOWS",
      "source": "CVE-2026-72982",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-73009-PROD-WINDOWS",
      "source": "CVE-2026-73009",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-73431-PROD-OFFICE",
      "source": "CVE-2026-73431",
      "target": "PROD-OFFICE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Office & 365 Apps documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-73498-PROD-LANGGRAPH",
      "source": "CVE-2026-73498",
      "target": "PROD-LANGGRAPH",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in LangGraph Multi-Agent Runtime documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-74512-PROD-LINUX-KERNEL",
      "source": "CVE-2026-74512",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-74521-PROD-LINUX-KERNEL",
      "source": "CVE-2026-74521",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-75650-PROD-OFFICE",
      "source": "CVE-2026-75650",
      "target": "PROD-OFFICE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Office & 365 Apps documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-76460-PROD-CISCO-ISE",
      "source": "CVE-2026-76460",
      "target": "PROD-CISCO-ISE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Cisco Identity Services Engine (ISE) documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-76461-PROD-CISCO-SEG",
      "source": "CVE-2026-76461",
      "target": "PROD-CISCO-SEG",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Cisco Secure Email Gateway (AsyncOS) documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-ARUBA-EDGECONNECT-VENDOR-HPE-ARUBA",
      "source": "PROD-ARUBA-EDGECONNECT",
      "target": "VENDOR-HPE-ARUBA",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "HPE Aruba EdgeConnect SD-WAN is developed and maintained by Hewlett Packard Enterprise / Aruba."
    },
    {
      "id": "REL-AUTO-CVE-2026-76674-PROD-ARUBA-EDGECONNECT",
      "source": "CVE-2026-76674",
      "target": "PROD-ARUBA-EDGECONNECT",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in HPE Aruba EdgeConnect SD-WAN documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-77248-PROD-LANGGRAPH",
      "source": "CVE-2026-77248",
      "target": "PROD-LANGGRAPH",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in LangGraph Multi-Agent Runtime documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-77254-PROD-LANGGRAPH",
      "source": "CVE-2026-77254",
      "target": "PROD-LANGGRAPH",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in LangGraph Multi-Agent Runtime documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-77257-PROD-LANGGRAPH",
      "source": "CVE-2026-77257",
      "target": "PROD-LANGGRAPH",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in LangGraph Multi-Agent Runtime documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-77258-PROD-LANGGRAPH",
      "source": "CVE-2026-77258",
      "target": "PROD-LANGGRAPH",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in LangGraph Multi-Agent Runtime documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-77266-PROD-LANGGRAPH",
      "source": "CVE-2026-77266",
      "target": "PROD-LANGGRAPH",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in LangGraph Multi-Agent Runtime documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-77267-PROD-LANGGRAPH",
      "source": "CVE-2026-77267",
      "target": "PROD-LANGGRAPH",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in LangGraph Multi-Agent Runtime documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-77268-PROD-LANGGRAPH",
      "source": "CVE-2026-77268",
      "target": "PROD-LANGGRAPH",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in LangGraph Multi-Agent Runtime documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-77269-PROD-LANGGRAPH",
      "source": "CVE-2026-77269",
      "target": "PROD-LANGGRAPH",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in LangGraph Multi-Agent Runtime documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-77270-PROD-LANGGRAPH",
      "source": "CVE-2026-77270",
      "target": "PROD-LANGGRAPH",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in LangGraph Multi-Agent Runtime documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-77272-PROD-LANGGRAPH",
      "source": "CVE-2026-77272",
      "target": "PROD-LANGGRAPH",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in LangGraph Multi-Agent Runtime documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-77493-PROD-WINDOWS",
      "source": "CVE-2026-77493",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-MAXKB-VENDOR-MAXKB",
      "source": "PROD-MAXKB",
      "target": "VENDOR-MAXKB",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "MaxKB Enterprise AI Platform is developed and maintained by 1Panel / MaxKB Community."
    },
    {
      "id": "REL-AUTO-CVE-2026-77521-PROD-MAXKB",
      "source": "CVE-2026-77521",
      "target": "PROD-MAXKB",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in MaxKB Enterprise AI Platform documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-7814-PROD-PGADMIN",
      "source": "CVE-2026-7814",
      "target": "PROD-PGADMIN",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in pgAdmin PostgreSQL Tools documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-7814-T1059",
      "source": "CVE-2026-7814",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-PROD-CAMEL-K-VENDOR-APACHE",
      "source": "PROD-CAMEL-K",
      "target": "VENDOR-APACHE",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Apache Camel K is developed and maintained by Apache Software Foundation."
    },
    {
      "id": "REL-AUTO-CVE-2026-78234-PROD-CAMEL-K",
      "source": "CVE-2026-78234",
      "target": "PROD-CAMEL-K",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Apache Camel K documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-78445-PROD-WINDOWS",
      "source": "CVE-2026-78445",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-78509-PROD-WINDOWS",
      "source": "CVE-2026-78509",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-78510-PROD-OFFICE",
      "source": "CVE-2026-78510",
      "target": "PROD-OFFICE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Office & 365 Apps documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-80083-PROD-WINDOWS",
      "source": "CVE-2026-80083",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-80351-PROD-CAMEL-K",
      "source": "CVE-2026-80351",
      "target": "PROD-CAMEL-K",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Apache Camel K documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-80352-PROD-CAMEL-K",
      "source": "CVE-2026-80352",
      "target": "PROD-CAMEL-K",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Apache Camel K documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-80354-PROD-CAMEL-K",
      "source": "CVE-2026-80354",
      "target": "PROD-CAMEL-K",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Apache Camel K documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-81578-PROD-PAPERCUT",
      "source": "CVE-2026-81578",
      "target": "PROD-PAPERCUT",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in PaperCut MF/NG documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-81963-PROD-WINDOWS",
      "source": "CVE-2026-81963",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-WP-KIRKI-VENDOR-THEMEUM",
      "source": "PROD-WP-KIRKI",
      "target": "VENDOR-THEMEUM",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Kirki Customizer Framework is developed and maintained by Themeum."
    },
    {
      "id": "REL-AUTO-CVE-2026-8206-PROD-WP-KIRKI",
      "source": "CVE-2026-8206",
      "target": "PROD-WP-KIRKI",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Kirki Customizer Framework documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-82078-PROD-PAPERCUT",
      "source": "CVE-2026-82078",
      "target": "PROD-PAPERCUT",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in PaperCut MF/NG documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-82078-T1059",
      "source": "CVE-2026-82078",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-82329-PROD-ARTIFACTORY",
      "source": "CVE-2026-82329",
      "target": "PROD-ARTIFACTORY",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in JFrog Artifactory documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-APACHE-BUILDSTREAM-VENDOR-APACHE",
      "source": "PROD-APACHE-BUILDSTREAM",
      "target": "VENDOR-APACHE",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Apache BuildStream is developed and maintained by Apache Software Foundation."
    },
    {
      "id": "REL-AUTO-CVE-2026-82331-PROD-APACHE-BUILDSTREAM",
      "source": "CVE-2026-82331",
      "target": "PROD-APACHE-BUILDSTREAM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Apache BuildStream documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-82331-AAP-007",
      "source": "CVE-2026-82331",
      "target": "AAP-007",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-82331 weaponizes the agentic attack pattern formalized under AAP-007."
    },
    {
      "id": "REL-AUTO-CVE-2026-82331-AAP-003",
      "source": "CVE-2026-82331",
      "target": "AAP-003",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-82331 weaponizes the agentic attack pattern formalized under AAP-003."
    },
    {
      "id": "REL-AUTO-CVE-2026-82474-PROD-SUDO",
      "source": "CVE-2026-82474",
      "target": "PROD-SUDO",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Sudo Privilege Manager documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-WP-RSS-VENDOR-REALLYSIMPLE",
      "source": "PROD-WP-RSS",
      "target": "VENDOR-REALLYSIMPLE",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Really Simple Security is developed and maintained by Really Simple Plugins."
    },
    {
      "id": "REL-AUTO-CVE-2026-8293-PROD-WP-RSS",
      "source": "CVE-2026-8293",
      "target": "PROD-WP-RSS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Really Simple Security documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-83020-PROD-OFFICE",
      "source": "CVE-2026-83020",
      "target": "PROD-OFFICE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Office & 365 Apps documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-83021-PROD-WEBLOGIC",
      "source": "CVE-2026-83021",
      "target": "PROD-WEBLOGIC",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Oracle WebLogic Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-83059-PROD-WINDOWS",
      "source": "CVE-2026-83059",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-83099-PROD-CPYTHON",
      "source": "CVE-2026-83099",
      "target": "PROD-CPYTHON",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in CPython Interpreter & Standard Library documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-IVANTI-SENTRY-VENDOR-IVANTI",
      "source": "PROD-IVANTI-SENTRY",
      "target": "VENDOR-IVANTI",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Ivanti Sentry is developed and maintained by Ivanti."
    },
    {
      "id": "REL-AUTO-CVE-2026-83527-PROD-IVANTI-SENTRY",
      "source": "CVE-2026-83527",
      "target": "PROD-IVANTI-SENTRY",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Ivanti Sentry documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-83527-T1059",
      "source": "CVE-2026-83527",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-PROD-SONICWALL-SMA-VENDOR-SONICWALL",
      "source": "PROD-SONICWALL-SMA",
      "target": "VENDOR-SONICWALL",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "SonicWall SMA1000 Gateway is developed and maintained by SonicWall."
    },
    {
      "id": "REL-AUTO-CVE-2026-83548-PROD-SONICWALL-SMA",
      "source": "CVE-2026-83548",
      "target": "PROD-SONICWALL-SMA",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in SonicWall SMA1000 Gateway documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-83549-PROD-SONICWALL-SMA",
      "source": "CVE-2026-83549",
      "target": "PROD-SONICWALL-SMA",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in SonicWall SMA1000 Gateway documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-TULEAP-VENDOR-ENALEAN",
      "source": "PROD-TULEAP",
      "target": "VENDOR-ENALEAN",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Tuleap Enterprise ALM is developed and maintained by Enalean / Dassault Systèmes."
    },
    {
      "id": "REL-AUTO-CVE-2026-84285-PROD-TULEAP",
      "source": "CVE-2026-84285",
      "target": "PROD-TULEAP",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Tuleap Enterprise ALM documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-84285-T1059",
      "source": "CVE-2026-84285",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-8452-PROD-NETSCALER",
      "source": "CVE-2026-8452",
      "target": "PROD-NETSCALER",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Citrix NetScaler ADC documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-AGENTIMUS-VENDOR-AGENTIMUS",
      "source": "PROD-AGENTIMUS",
      "target": "VENDOR-AGENTIMUS",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Agentimus AI SEO & MCP Plugin is developed and maintained by Agentimus."
    },
    {
      "id": "REL-AUTO-CVE-2026-84779-PROD-AGENTIMUS",
      "source": "CVE-2026-84779",
      "target": "PROD-AGENTIMUS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Agentimus AI SEO & MCP Plugin documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-SCREENCONNECT-VENDOR-CONNECTWISE",
      "source": "PROD-SCREENCONNECT",
      "target": "VENDOR-CONNECTWISE",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "ConnectWise ScreenConnect is developed and maintained by ConnectWise."
    },
    {
      "id": "REL-AUTO-CVE-2026-84869-PROD-SCREENCONNECT",
      "source": "CVE-2026-84869",
      "target": "PROD-SCREENCONNECT",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in ConnectWise ScreenConnect documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-84869-T1059",
      "source": "CVE-2026-84869",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-84939-PROD-GITLAB",
      "source": "CVE-2026-84939",
      "target": "PROD-GITLAB",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in GitLab Community & Enterprise Edition documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-84939-T1059",
      "source": "CVE-2026-84939",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-PROD-CHROMIUM-VENDOR-GOOGLE",
      "source": "PROD-CHROMIUM",
      "target": "VENDOR-GOOGLE",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Google Chromium / V8 Engine is developed and maintained by Google LLC."
    },
    {
      "id": "REL-AUTO-CVE-2026-85046-PROD-CHROMIUM",
      "source": "CVE-2026-85046",
      "target": "PROD-CHROMIUM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Google Chromium / V8 Engine documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-CHECKPOINT-MGMT-VENDOR-CHECKPOINT",
      "source": "PROD-CHECKPOINT-MGMT",
      "target": "VENDOR-CHECKPOINT",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Check Point Security Management is developed and maintained by Check Point Software."
    },
    {
      "id": "REL-AUTO-CVE-2026-85102-PROD-CHECKPOINT-MGMT",
      "source": "CVE-2026-85102",
      "target": "PROD-CHECKPOINT-MGMT",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Check Point Security Management documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-85103-PROD-CHECKPOINT-MGMT",
      "source": "CVE-2026-85103",
      "target": "PROD-CHECKPOINT-MGMT",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Check Point Security Management documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-N8N-VENDOR-N8N",
      "source": "PROD-N8N",
      "target": "VENDOR-N8N",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "n8n Workflow Automation is developed and maintained by n8n GmbH."
    },
    {
      "id": "REL-AUTO-CVE-2026-85165-PROD-N8N",
      "source": "CVE-2026-85165",
      "target": "PROD-N8N",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in n8n Workflow Automation documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-85166-PROD-N8N",
      "source": "CVE-2026-85166",
      "target": "PROD-N8N",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in n8n Workflow Automation documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-85168-PROD-N8N",
      "source": "CVE-2026-85168",
      "target": "PROD-N8N",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in n8n Workflow Automation documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-85654-PROD-AWS-MCP-SERVER",
      "source": "CVE-2026-85654",
      "target": "PROD-AWS-MCP-SERVER",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in AWS MCP Server Suite documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-85706-PROD-GITLAB",
      "source": "CVE-2026-85706",
      "target": "PROD-GITLAB",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in GitLab Community & Enterprise Edition documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-85706-T1552",
      "source": "CVE-2026-85706",
      "target": "T1552",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552."
    },
    {
      "id": "REL-AUTO-CVE-2026-85706-T1059",
      "source": "CVE-2026-85706",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-85788-PROD-MYSQL",
      "source": "CVE-2026-85788",
      "target": "PROD-MYSQL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Oracle MySQL Server & Database Engine documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-85880-PROD-WINDOWS",
      "source": "CVE-2026-85880",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-86060-PROD-WINDOWS",
      "source": "CVE-2026-86060",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-N-CENTRAL-VENDOR-N-ABLE",
      "source": "PROD-N-CENTRAL",
      "target": "VENDOR-N-ABLE",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "N-able N-central RMM is developed and maintained by N-able."
    },
    {
      "id": "REL-AUTO-CVE-2026-86218-PROD-N-CENTRAL",
      "source": "CVE-2026-86218",
      "target": "PROD-N-CENTRAL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in N-able N-central RMM documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-86296-PROD-LINUX-KERNEL",
      "source": "CVE-2026-86296",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-86297-PROD-LINUX-KERNEL",
      "source": "CVE-2026-86297",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-PIP-VENDOR-PYPA",
      "source": "PROD-PIP",
      "target": "VENDOR-PYPA",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "pip Python Package Installer is developed and maintained by Python Packaging Authority."
    },
    {
      "id": "REL-AUTO-CVE-2026-8643-PROD-PIP",
      "source": "CVE-2026-8643",
      "target": "PROD-PIP",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in pip Python Package Installer documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-86510-PROD-LINUX-KERNEL",
      "source": "CVE-2026-86510",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-86711-PROD-CHROMIUM",
      "source": "CVE-2026-86711",
      "target": "PROD-CHROMIUM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Google Chromium / V8 Engine documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-8719-PROD-OFFICE",
      "source": "CVE-2026-8719",
      "target": "PROD-OFFICE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Office & 365 Apps documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-87230-PROD-WINDOWS",
      "source": "CVE-2026-87230",
      "target": "PROD-WINDOWS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-87491-PROD-CHROMIUM",
      "source": "CVE-2026-87491",
      "target": "PROD-CHROMIUM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Google Chromium / V8 Engine documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-87491-AAP-007",
      "source": "CVE-2026-87491",
      "target": "AAP-007",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-87491 weaponizes the agentic attack pattern formalized under AAP-007."
    },
    {
      "id": "REL-AUTO-CVE-2026-87491-AAP-002",
      "source": "CVE-2026-87491",
      "target": "AAP-002",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-87491 weaponizes the agentic attack pattern formalized under AAP-002."
    },
    {
      "id": "REL-AUTO-CVE-2026-87886-PROD-VEEAM-VBR",
      "source": "CVE-2026-87886",
      "target": "PROD-VEEAM-VBR",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Veeam Backup & Replication documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-87911-PROD-AWS-MCP-SERVER",
      "source": "CVE-2026-87911",
      "target": "PROD-AWS-MCP-SERVER",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in AWS MCP Server Suite documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-MISTRAL-VIBE-VENDOR-MISTRAL",
      "source": "PROD-MISTRAL-VIBE",
      "target": "VENDOR-MISTRAL",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Mistral Vibe Coding Agent is developed and maintained by Mistral AI."
    },
    {
      "id": "REL-AUTO-CVE-2026-87983-PROD-MISTRAL-VIBE",
      "source": "CVE-2026-87983",
      "target": "PROD-MISTRAL-VIBE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Mistral Vibe Coding Agent documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-87983-AAP-002",
      "source": "CVE-2026-87983",
      "target": "AAP-002",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-87983 weaponizes the agentic attack pattern formalized under AAP-002."
    },
    {
      "id": "REL-AUTO-CVE-2026-87983-AAP-003",
      "source": "CVE-2026-87983",
      "target": "AAP-003",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-87983 weaponizes the agentic attack pattern formalized under AAP-003."
    },
    {
      "id": "REL-AUTO-CVE-2026-87983-AAP-001",
      "source": "CVE-2026-87983",
      "target": "AAP-001",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-87983 weaponizes the agentic attack pattern formalized under AAP-001."
    },
    {
      "id": "REL-AUTO-CVE-2026-87984-PROD-MISTRAL-VIBE",
      "source": "CVE-2026-87984",
      "target": "PROD-MISTRAL-VIBE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Mistral Vibe Coding Agent documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-87984-AAP-002",
      "source": "CVE-2026-87984",
      "target": "AAP-002",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-87984 weaponizes the agentic attack pattern formalized under AAP-002."
    },
    {
      "id": "REL-AUTO-CVE-2026-87984-AAP-003",
      "source": "CVE-2026-87984",
      "target": "AAP-003",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-87984 weaponizes the agentic attack pattern formalized under AAP-003."
    },
    {
      "id": "REL-AUTO-CVE-2026-87985-PROD-MISTRAL-VIBE",
      "source": "CVE-2026-87985",
      "target": "PROD-MISTRAL-VIBE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Mistral Vibe Coding Agent documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-87985-AAP-002",
      "source": "CVE-2026-87985",
      "target": "AAP-002",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-87985 weaponizes the agentic attack pattern formalized under AAP-002."
    },
    {
      "id": "REL-AUTO-CVE-2026-87985-AAP-003",
      "source": "CVE-2026-87985",
      "target": "AAP-003",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-87985 weaponizes the agentic attack pattern formalized under AAP-003."
    },
    {
      "id": "REL-AUTO-CVE-2026-87985-AAP-001",
      "source": "CVE-2026-87985",
      "target": "AAP-001",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-87985 weaponizes the agentic attack pattern formalized under AAP-001."
    },
    {
      "id": "REL-AUTO-CVE-2026-87986-PROD-MISTRAL-VIBE",
      "source": "CVE-2026-87986",
      "target": "PROD-MISTRAL-VIBE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Mistral Vibe Coding Agent documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-87986-AAP-002",
      "source": "CVE-2026-87986",
      "target": "AAP-002",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-87986 weaponizes the agentic attack pattern formalized under AAP-002."
    },
    {
      "id": "REL-AUTO-CVE-2026-87986-AAP-003",
      "source": "CVE-2026-87986",
      "target": "AAP-003",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-87986 weaponizes the agentic attack pattern formalized under AAP-003."
    },
    {
      "id": "REL-AUTO-CVE-2026-87986-AAP-001",
      "source": "CVE-2026-87986",
      "target": "AAP-001",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-87986 weaponizes the agentic attack pattern formalized under AAP-001."
    },
    {
      "id": "REL-AUTO-CVE-2026-87987-PROD-MISTRAL-VIBE",
      "source": "CVE-2026-87987",
      "target": "PROD-MISTRAL-VIBE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Mistral Vibe Coding Agent documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-87987-AAP-002",
      "source": "CVE-2026-87987",
      "target": "AAP-002",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-87987 weaponizes the agentic attack pattern formalized under AAP-002."
    },
    {
      "id": "REL-AUTO-CVE-2026-87987-AAP-003",
      "source": "CVE-2026-87987",
      "target": "AAP-003",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-87987 weaponizes the agentic attack pattern formalized under AAP-003."
    },
    {
      "id": "REL-AUTO-CVE-2026-87987-AAP-001",
      "source": "CVE-2026-87987",
      "target": "AAP-001",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-87987 weaponizes the agentic attack pattern formalized under AAP-001."
    },
    {
      "id": "REL-AUTO-CVE-2026-87988-PROD-MISTRAL-VIBE",
      "source": "CVE-2026-87988",
      "target": "PROD-MISTRAL-VIBE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Mistral Vibe Coding Agent documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-87988-AAP-002",
      "source": "CVE-2026-87988",
      "target": "AAP-002",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-87988 weaponizes the agentic attack pattern formalized under AAP-002."
    },
    {
      "id": "REL-AUTO-CVE-2026-87988-AAP-003",
      "source": "CVE-2026-87988",
      "target": "AAP-003",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-87988 weaponizes the agentic attack pattern formalized under AAP-003."
    },
    {
      "id": "REL-AUTO-CVE-2026-87988-AAP-001",
      "source": "CVE-2026-87988",
      "target": "AAP-001",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-87988 weaponizes the agentic attack pattern formalized under AAP-001."
    },
    {
      "id": "REL-AUTO-PROD-OPENWEBUI-VENDOR-OPENWEBUI",
      "source": "PROD-OPENWEBUI",
      "target": "VENDOR-OPENWEBUI",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Open WebUI Platform is developed and maintained by Open WebUI Community."
    },
    {
      "id": "REL-AUTO-CVE-2026-87999-PROD-OPENWEBUI",
      "source": "CVE-2026-87999",
      "target": "PROD-OPENWEBUI",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Open WebUI Platform documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-8932-PROD-SUDO",
      "source": "CVE-2026-8932",
      "target": "PROD-SUDO",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Sudo Privilege Manager documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-WP-SLIDERREV-VENDOR-THEMEPUNCH",
      "source": "PROD-WP-SLIDERREV",
      "target": "VENDOR-THEMEPUNCH",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Slider Revolution is developed and maintained by ThemePunch."
    },
    {
      "id": "REL-AUTO-CVE-2026-9048-PROD-WP-SLIDERREV",
      "source": "CVE-2026-9048",
      "target": "PROD-WP-SLIDERREV",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Slider Revolution documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-9050-PROD-WP-SLIDERREV",
      "source": "CVE-2026-9050",
      "target": "PROD-WP-SLIDERREV",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Slider Revolution documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-90562-PROD-OFFICE",
      "source": "CVE-2026-90562",
      "target": "PROD-OFFICE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Office & 365 Apps documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-90562-AAP-003",
      "source": "CVE-2026-90562",
      "target": "AAP-003",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-90562 weaponizes the agentic attack pattern formalized under AAP-003."
    },
    {
      "id": "REL-AUTO-CVE-2026-90562-AAP-007",
      "source": "CVE-2026-90562",
      "target": "AAP-007",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-90562 weaponizes the agentic attack pattern formalized under AAP-007."
    },
    {
      "id": "REL-AUTO-CVE-2026-90680-PROD-LINUX-KERNEL",
      "source": "CVE-2026-90680",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-90692-PROD-LINUX-KERNEL",
      "source": "CVE-2026-90692",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-90693-PROD-LINUX-KERNEL",
      "source": "CVE-2026-90693",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-90699-PROD-LINUX-KERNEL",
      "source": "CVE-2026-90699",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-90702-PROD-LINUX-KERNEL",
      "source": "CVE-2026-90702",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-90711-AAP-002",
      "source": "CVE-2026-90711",
      "target": "AAP-002",
      "relation": "exploits",
      "confidence": 0.92,
      "confidence_level": "VERY_HIGH",
      "rationale": "CVE-2026-90711 weaponizes the agentic attack pattern formalized under AAP-002."
    },
    {
      "id": "REL-AUTO-CVE-2026-90770-PROD-MYSQL",
      "source": "CVE-2026-90770",
      "target": "PROD-MYSQL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Oracle MySQL Server & Database Engine documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-CHECKPOINT-VENDOR-CHECKPOINT",
      "source": "PROD-CHECKPOINT",
      "target": "VENDOR-CHECKPOINT",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Check Point Security Management Server & Gaia OS is developed and maintained by Check Point Software Technologies."
    },
    {
      "id": "REL-AUTO-CVE-2026-90777-PROD-CHECKPOINT",
      "source": "CVE-2026-90777",
      "target": "PROD-CHECKPOINT",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Check Point Security Management Server & Gaia OS documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-90777-T1059",
      "source": "CVE-2026-90777",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-CVE-2026-90777-T1552",
      "source": "CVE-2026-90777",
      "target": "T1552",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552."
    },
    {
      "id": "REL-AUTO-PROD-PARALLELS-VENDOR-PARALLELS",
      "source": "PROD-PARALLELS",
      "target": "VENDOR-PARALLELS",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Parallels Desktop for Mac is developed and maintained by Parallels International."
    },
    {
      "id": "REL-AUTO-CVE-2026-90894-PROD-PARALLELS",
      "source": "CVE-2026-90894",
      "target": "PROD-PARALLELS",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Parallels Desktop for Mac documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-91749-PROD-CHROMIUM",
      "source": "CVE-2026-91749",
      "target": "PROD-CHROMIUM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Google Chromium / V8 Engine documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-91843-PROD-CHECKPOINT-MGMT",
      "source": "CVE-2026-91843",
      "target": "PROD-CHECKPOINT-MGMT",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Check Point Security Management documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-9186-PROD-LANGFLOW",
      "source": "CVE-2026-9186",
      "target": "PROD-LANGFLOW",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Langflow Visual AI Builder documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-92574-PROD-CHECKPOINT",
      "source": "CVE-2026-92574",
      "target": "PROD-CHECKPOINT",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Check Point Security Management Server & Gaia OS documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-93372-PROD-CHROMIUM",
      "source": "CVE-2026-93372",
      "target": "PROD-CHROMIUM",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Google Chromium / V8 Engine documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-93616-PROD-CHECKPOINT-MGMT",
      "source": "CVE-2026-93616",
      "target": "PROD-CHECKPOINT-MGMT",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Check Point Security Management documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-VELOCLOUD-VENDOR-ARISTA",
      "source": "PROD-VELOCLOUD",
      "target": "VENDOR-ARISTA",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "Arista VeloCloud Orchestrator is developed and maintained by Arista Networks."
    },
    {
      "id": "REL-AUTO-CVE-2026-93952-PROD-VELOCLOUD",
      "source": "CVE-2026-93952",
      "target": "PROD-VELOCLOUD",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Arista VeloCloud Orchestrator documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-94089-PROD-LINUX-KERNEL",
      "source": "CVE-2026-94089",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-PROD-F5-BIGIP-VENDOR-F5",
      "source": "PROD-F5-BIGIP",
      "target": "VENDOR-F5",
      "relation": "manufactured_by",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "F5 BIG-IP Access Policy Manager is developed and maintained by F5 Networks."
    },
    {
      "id": "REL-AUTO-CVE-2026-94127-PROD-F5-BIGIP",
      "source": "CVE-2026-94127",
      "target": "PROD-F5-BIGIP",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in F5 BIG-IP Access Policy Manager documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-95675-PROD-LINUX-KERNEL",
      "source": "CVE-2026-95675",
      "target": "PROD-LINUX-KERNEL",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-9586-PROD-OFFICE",
      "source": "CVE-2026-9586",
      "target": "PROD-OFFICE",
      "relation": "affects",
      "confidence": 0.98,
      "confidence_level": "VERY_HIGH",
      "rationale": "Confirmed security vulnerability in Microsoft Office & 365 Apps documented in Hermes dossier."
    },
    {
      "id": "REL-AUTO-CVE-2026-9586-T1059",
      "source": "CVE-2026-9586",
      "target": "T1059",
      "relation": "uses",
      "confidence": 0.9,
      "confidence_level": "VERY_HIGH",
      "rationale": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059."
    },
    {
      "id": "REL-AUTO-STUDY-AGENTPOISON-RED-TEAMING-LLM-MEMO-AAP-005",
      "source": "STUDY-AGENTPOISON-RED-TEAMING-LLM-MEMO",
      "target": "AAP-005",
      "relation": "evaluates",
      "confidence": 0.95,
      "confidence_level": "VERY_HIGH",
      "rationale": "The empirical research study rigorously benchmarks and measures the attack mechanics of AAP-005."
    },
    {
      "id": "REL-AUTO-STUDY-AGENTPOISON-RED-TEAMING-LLM-MEMO-AAP-002",
      "source": "STUDY-AGENTPOISON-RED-TEAMING-LLM-MEMO",
      "target": "AAP-002",
      "relation": "evaluates",
      "confidence": 0.95,
      "confidence_level": "VERY_HIGH",
      "rationale": "The empirical research study rigorously benchmarks and measures the attack mechanics of AAP-002."
    },
    {
      "id": "REL-AUTO-STUDY-AGENTPOISON-RED-TEAMING-LLM-MEMO-AAP-003",
      "source": "STUDY-AGENTPOISON-RED-TEAMING-LLM-MEMO",
      "target": "AAP-003",
      "relation": "evaluates",
      "confidence": 0.95,
      "confidence_level": "VERY_HIGH",
      "rationale": "The empirical research study rigorously benchmarks and measures the attack mechanics of AAP-003."
    },
    {
      "id": "REL-AUTO-STUDY-AGENTPOISON-RED-TEAMING-LLM-MEMO-AAP-007",
      "source": "STUDY-AGENTPOISON-RED-TEAMING-LLM-MEMO",
      "target": "AAP-007",
      "relation": "evaluates",
      "confidence": 0.95,
      "confidence_level": "VERY_HIGH",
      "rationale": "The empirical research study rigorously benchmarks and measures the attack mechanics of AAP-007."
    },
    {
      "id": "REL-AUTO-STUDY-ARE-PROMPT-INJECTIONS-IMPOSSIBLE-AAP-001",
      "source": "STUDY-ARE-PROMPT-INJECTIONS-IMPOSSIBLE",
      "target": "AAP-001",
      "relation": "evaluates",
      "confidence": 0.95,
      "confidence_level": "VERY_HIGH",
      "rationale": "The empirical research study rigorously benchmarks and measures the attack mechanics of AAP-001."
    },
    {
      "id": "REL-AUTO-STUDY-HOW-TO-ATTACK-AN-AI-AGENT-PILLAR-AAP-003",
      "source": "STUDY-HOW-TO-ATTACK-AN-AI-AGENT-PILLAR",
      "target": "AAP-003",
      "relation": "evaluates",
      "confidence": 0.95,
      "confidence_level": "VERY_HIGH",
      "rationale": "The empirical research study rigorously benchmarks and measures the attack mechanics of AAP-003."
    },
    {
      "id": "REL-AUTO-STUDY-LLM-MEDIATED-WEB-ATTACKS-ARXIV-2-AAP-003",
      "source": "STUDY-LLM-MEDIATED-WEB-ATTACKS-ARXIV-2",
      "target": "AAP-003",
      "relation": "evaluates",
      "confidence": 0.95,
      "confidence_level": "VERY_HIGH",
      "rationale": "The empirical research study rigorously benchmarks and measures the attack mechanics of AAP-003."
    },
    {
      "id": "REL-AUTO-STUDY-LLM-MEDIATED-WEB-ATTACKS-ARXIV-2-AAP-001",
      "source": "STUDY-LLM-MEDIATED-WEB-ATTACKS-ARXIV-2",
      "target": "AAP-001",
      "relation": "evaluates",
      "confidence": 0.95,
      "confidence_level": "VERY_HIGH",
      "rationale": "The empirical research study rigorously benchmarks and measures the attack mechanics of AAP-001."
    },
    {
      "id": "REL-AUTO-STUDY-LLM-MEDIATED-WEB-ATTACKS-ARXIV-2-AAP-007",
      "source": "STUDY-LLM-MEDIATED-WEB-ATTACKS-ARXIV-2",
      "target": "AAP-007",
      "relation": "evaluates",
      "confidence": 0.95,
      "confidence_level": "VERY_HIGH",
      "rationale": "The empirical research study rigorously benchmarks and measures the attack mechanics of AAP-007."
    },
    {
      "id": "REL-AUTO-STUDY-MCP-SECURITY-HYBRID-ANALYSIS-MTG-AAP-003",
      "source": "STUDY-MCP-SECURITY-HYBRID-ANALYSIS-MTG",
      "target": "AAP-003",
      "relation": "evaluates",
      "confidence": 0.95,
      "confidence_level": "VERY_HIGH",
      "rationale": "The empirical research study rigorously benchmarks and measures the attack mechanics of AAP-003."
    },
    {
      "id": "REL-AUTO-STUDY-PIMINER-AGENT-AGAINST-AGENT-RED--AAP-001",
      "source": "STUDY-PIMINER-AGENT-AGAINST-AGENT-RED-",
      "target": "AAP-001",
      "relation": "evaluates",
      "confidence": 0.95,
      "confidence_level": "VERY_HIGH",
      "rationale": "The empirical research study rigorously benchmarks and measures the attack mechanics of AAP-001."
    },
    {
      "id": "REL-AUTO-STUDY-SYSEVOLVE-AUTONOMOUS-CYBER-CO-EV-AAP-007",
      "source": "STUDY-SYSEVOLVE-AUTONOMOUS-CYBER-CO-EV",
      "target": "AAP-007",
      "relation": "evaluates",
      "confidence": 0.95,
      "confidence_level": "VERY_HIGH",
      "rationale": "The empirical research study rigorously benchmarks and measures the attack mechanics of AAP-007."
    },
    {
      "id": "REL-AUTO-STUDY-SYSEVOLVE-AUTONOMOUS-CYBER-CO-EV-AAP-003",
      "source": "STUDY-SYSEVOLVE-AUTONOMOUS-CYBER-CO-EV",
      "target": "AAP-003",
      "relation": "evaluates",
      "confidence": 0.95,
      "confidence_level": "VERY_HIGH",
      "rationale": "The empirical research study rigorously benchmarks and measures the attack mechanics of AAP-003."
    },
    {
      "id": "REL-AUTO-TOOL-AGENTTHREAT-STUDIO-AAP-001",
      "source": "TOOL-AGENTTHREAT-STUDIO",
      "target": "AAP-001",
      "relation": "evaluates",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "AgentThreat Studio dynamically audits and models compromise propagation for AAP-001."
    },
    {
      "id": "REL-AUTO-TOOL-AGENTTHREAT-STUDIO-AAP-002",
      "source": "TOOL-AGENTTHREAT-STUDIO",
      "target": "AAP-002",
      "relation": "evaluates",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "AgentThreat Studio dynamically audits and models compromise propagation for AAP-002."
    },
    {
      "id": "REL-AUTO-TOOL-AGENTTHREAT-STUDIO-AAP-003",
      "source": "TOOL-AGENTTHREAT-STUDIO",
      "target": "AAP-003",
      "relation": "evaluates",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "AgentThreat Studio dynamically audits and models compromise propagation for AAP-003."
    },
    {
      "id": "REL-AUTO-TOOL-AGENTTHREAT-STUDIO-AAP-004",
      "source": "TOOL-AGENTTHREAT-STUDIO",
      "target": "AAP-004",
      "relation": "evaluates",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "AgentThreat Studio dynamically audits and models compromise propagation for AAP-004."
    },
    {
      "id": "REL-AUTO-TOOL-AGENTTHREAT-STUDIO-AAP-005",
      "source": "TOOL-AGENTTHREAT-STUDIO",
      "target": "AAP-005",
      "relation": "evaluates",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "AgentThreat Studio dynamically audits and models compromise propagation for AAP-005."
    },
    {
      "id": "REL-AUTO-TOOL-AGENTTHREAT-STUDIO-AAP-006",
      "source": "TOOL-AGENTTHREAT-STUDIO",
      "target": "AAP-006",
      "relation": "evaluates",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "AgentThreat Studio dynamically audits and models compromise propagation for AAP-006."
    },
    {
      "id": "REL-AUTO-TOOL-AGENTTHREAT-STUDIO-AAP-007",
      "source": "TOOL-AGENTTHREAT-STUDIO",
      "target": "AAP-007",
      "relation": "evaluates",
      "confidence": 0.99,
      "confidence_level": "VERY_HIGH",
      "rationale": "AgentThreat Studio dynamically audits and models compromise propagation for AAP-007."
    },
    {
      "id": "REL-AUTO-TOOL-AGENTTHREAT-STUDIO-PROD-LITELLM",
      "source": "TOOL-AGENTTHREAT-STUDIO",
      "target": "PROD-LITELLM",
      "relation": "references",
      "confidence": 0.95,
      "confidence_level": "VERY_HIGH",
      "rationale": "AgentThreat Studio includes defensive patches, proxies, and threat templates for PROD-LITELLM."
    },
    {
      "id": "REL-AUTO-TOOL-AGENTTHREAT-STUDIO-PROD-LANGGRAPH",
      "source": "TOOL-AGENTTHREAT-STUDIO",
      "target": "PROD-LANGGRAPH",
      "relation": "references",
      "confidence": 0.95,
      "confidence_level": "VERY_HIGH",
      "rationale": "AgentThreat Studio includes defensive patches, proxies, and threat templates for PROD-LANGGRAPH."
    },
    {
      "id": "REL-AUTO-TOOL-AGENTTHREAT-STUDIO-PROD-MISTRAL-VIBE",
      "source": "TOOL-AGENTTHREAT-STUDIO",
      "target": "PROD-MISTRAL-VIBE",
      "relation": "references",
      "confidence": 0.95,
      "confidence_level": "VERY_HIGH",
      "rationale": "AgentThreat Studio includes defensive patches, proxies, and threat templates for PROD-MISTRAL-VIBE."
    }
  ],
  "categories": [
    {
      "type": "vulnerability",
      "color": "#ef4444",
      "label": "Vulnerabilities"
    },
    {
      "type": "agentic_attack_pattern",
      "color": "#c084fc",
      "label": "Agentic Patterns"
    },
    {
      "type": "attack_technique",
      "color": "#fbbf24",
      "label": "MITRE Techniques"
    },
    {
      "type": "product",
      "color": "#60a5fa",
      "label": "Products"
    },
    {
      "type": "vendor",
      "color": "#38bdf8",
      "label": "Vendors"
    },
    {
      "type": "detection",
      "color": "#34d399",
      "label": "Detections"
    },
    {
      "type": "forensic_artifact",
      "color": "#f472b6",
      "label": "Forensic Artifacts"
    },
    {
      "type": "threat_actor",
      "color": "#f87171",
      "label": "Threat Actors"
    },
    {
      "type": "campaign",
      "color": "#f97316",
      "label": "Campaigns"
    },
    {
      "type": "malware",
      "color": "#ea580c",
      "label": "Malware"
    },
    {
      "type": "research_study",
      "color": "#a855f7",
      "label": "Research Studies"
    }
  ]
}