{
  "type": "bundle",
  "id": "bundle--8be0fa85-fd27-493a-a4f8-dde1c5dfc48a",
  "spec_version": "2.1",
  "objects": [
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "Hermes Codex Temporal Risk Intelligence",
      "description": "Autonomous Cyber Risk Intelligence & Temporal Threat Trajectory Engine.",
      "identity_class": "system",
      "sectors": [
        "technology",
        "cybersecurity"
      ],
      "contact_information": "https://hermes-codex.vercel.app"
    },
    {
      "type": "threat-actor",
      "spec_version": "2.1",
      "id": "threat-actor--0735d81e-7aea-4ae7-aeb5-5170b8bb3c14",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "Void Arachne",
      "description": "Threat actor Void Arachne monitored by Hermes Codex.",
      "threat_actor_types": [
        "cybercrime-syndicate",
        "ransomware-operator"
      ],
      "sophistication": "advanced"
    },
    {
      "type": "threat-actor",
      "spec_version": "2.1",
      "id": "threat-actor--a52e3172-7207-4383-aa7b-2b17a4d81de5",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "Akira Ransomware Syndicate",
      "description": "Threat actor Akira Ransomware Syndicate monitored by Hermes Codex.",
      "threat_actor_types": [
        "cybercrime-syndicate",
        "ransomware-operator"
      ],
      "sophistication": "advanced"
    },
    {
      "type": "threat-actor",
      "spec_version": "2.1",
      "id": "threat-actor--64bc0671-3421-4f5c-a133-2337f036e99e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "FIN7",
      "description": "Threat actor FIN7 monitored by Hermes Codex.",
      "threat_actor_types": [
        "cybercrime-syndicate",
        "ransomware-operator"
      ],
      "sophistication": "advanced"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--4944e7db-5acd-4563-ab0c-1f343db7e8b3",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "AAP-001: Direct System Prompt Override",
      "description": "Adversary technique or agentic attack pattern AAP-001: Direct System Prompt Override.",
      "external_references": []
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--38abbfb6-2f9c-4890-aa64-a0363710a6c4",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "AAP-002: Indirect Context Injection",
      "description": "Adversary technique or agentic attack pattern AAP-002: Indirect Context Injection.",
      "external_references": []
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--6cdfab74-1358-48e3-ab2b-4b5ba7a83b5a",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "AAP-003: Tool Parameter Tampering & Built-in Bypass",
      "description": "Adversary technique or agentic attack pattern AAP-003: Tool Parameter Tampering & Built-in Bypass.",
      "external_references": []
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--5e89795f-ce4c-401a-a79b-c277e480c825",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "AAP-004: Semantic Tool Poisoning",
      "description": "Adversary technique or agentic attack pattern AAP-004: Semantic Tool Poisoning.",
      "external_references": []
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--27ca782d-3e4f-49a1-a49c-d7e389612bab",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "AAP-005: Memory & Vector DB Knowledge Corruption",
      "description": "Adversary technique or agentic attack pattern AAP-005: Memory & Vector DB Knowledge Corruption.",
      "external_references": []
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--5e943b66-06a2-4ef3-a0c7-7565fecf6008",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "AAP-006: Inter-Agent Semantic Message Spoofing",
      "description": "Adversary technique or agentic attack pattern AAP-006: Inter-Agent Semantic Message Spoofing.",
      "external_references": []
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--6616b465-098e-4088-a13b-882430fa99a1",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "AAP-007: Autonomous Cascading RCE",
      "description": "Adversary technique or agentic attack pattern AAP-007: Autonomous Cascading RCE.",
      "external_references": []
    },
    {
      "type": "campaign",
      "spec_version": "2.1",
      "id": "campaign--5d6f120c-396d-434f-ab5d-9b3ba4d4c9bf",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "Operation MCP Harvester 2026",
      "description": "Malicious campaign Operation MCP Harvester 2026."
    },
    {
      "type": "campaign",
      "spec_version": "2.1",
      "id": "campaign--1a00eefb-941c-42a1-acde-282fc0614b25",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "Operation MikroTrick 2026",
      "description": "Malicious campaign Operation MikroTrick 2026."
    },
    {
      "type": "campaign",
      "spec_version": "2.1",
      "id": "campaign--0093007f-46d9-4597-a078-ec8730fde3aa",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "Agents Gone Wild: AI-Orchestrated Global Campaign Against PaperCut NG/MF",
      "description": "Malicious campaign Agents Gone Wild: AI-Orchestrated Global Campaign Against PaperCut NG/MF."
    },
    {
      "type": "malware",
      "spec_version": "2.1",
      "id": "malware--5435f428-5561-469a-ad64-adcc90b94a1a",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "LiteLLM Streamable MCP Token Forger",
      "description": "Artifact LiteLLM Streamable MCP Token Forger (exploit)."
    },
    {
      "type": "malware",
      "spec_version": "2.1",
      "id": "malware--1d1d9bf6-efb2-489a-a6bf-e118888ffae2",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "Cursor Shell Builtin Auto-Run PoC",
      "description": "Artifact Cursor Shell Builtin Auto-Run PoC (exploit)."
    },
    {
      "type": "malware",
      "spec_version": "2.1",
      "id": "malware--a5a67799-b785-4354-a650-3ead0d40b4b7",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "ShadowAgent Stealer",
      "description": "Artifact ShadowAgent Stealer (malware)."
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "T1059: Command and Scripting Interpreter",
      "description": "Adversary technique or agentic attack pattern T1059: Command and Scripting Interpreter.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1059",
          "url": "https://attack.mitre.org/techniques/T1059/"
        }
      ]
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--50ef62e1-8260-48ce-a4d6-ce361f2a267e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "T1566: Phishing / Untrusted Content Ingestion",
      "description": "Adversary technique or agentic attack pattern T1566: Phishing / Untrusted Content Ingestion.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1566",
          "url": "https://attack.mitre.org/techniques/T1566/"
        }
      ]
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--ae03499f-1cb4-40c4-a7eb-f30e7cda44b9",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "T1552: Unsecured Credentials",
      "description": "Adversary technique or agentic attack pattern T1552: Unsecured Credentials.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1552",
          "url": "https://attack.mitre.org/techniques/T1552/"
        }
      ]
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--a0e23acd-1abd-4ec0-a833-56bdbfe9870e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "T1574: Hijack Execution Flow",
      "description": "Adversary technique or agentic attack pattern T1574: Hijack Execution Flow.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1574",
          "url": "https://attack.mitre.org/techniques/T1574/"
        }
      ]
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--48d1a0e9-dece-482f-a791-7a328348203c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "AML.T0051: LLM Prompt Injection",
      "description": "Adversary technique or agentic attack pattern AML.T0051: LLM Prompt Injection.",
      "external_references": []
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--95949054-3566-474e-a94b-7c454b128901",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "AML.T0053: LLM Plugin and Tool Compromise",
      "description": "Adversary technique or agentic attack pattern AML.T0053: LLM Plugin and Tool Compromise.",
      "external_references": []
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--463b9dcd-5c6d-4c1c-a741-1dca8964c55f",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "AML.T0043: Adversarial Data Poisoning",
      "description": "Adversary technique or agentic attack pattern AML.T0043: Adversarial Data Poisoning.",
      "external_references": []
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--b3542d9b-5d24-41c6-a756-db6c9cd25f41",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "AML.T0054: LLM Jailbreak",
      "description": "Adversary technique or agentic attack pattern AML.T0054: LLM Jailbreak.",
      "external_references": []
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--f46b6461-ba19-43dc-ab89-6fba60261cb3",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-59822",
      "description": "CVE-2026-59822: LiteLLM MCP Streamable HTTP Auth Bypass",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-59822",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59822"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-59822",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-59822/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--786100ba-9782-44a9-a7b5-5bf32df97b8c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-41264",
      "description": "CVE-2026-41264: LangChain / LangGraph Agent Loop RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-41264",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41264"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-41264",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-41264/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--5672d9fa-d29b-4722-a93a-c6cb5a6dbb45",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-22708",
      "description": "CVE-2026-22708: Cursor IDE Terminal Allowlist Bypass via Shell Built-ins",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-22708",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22708"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-22708",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-22708/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--1980c9c2-5db0-417e-a06c-8d688a0f41cf",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-46580",
      "description": "CVE-2026-46580: Eclipse Theia Prompt Template Injection & RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-46580",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46580"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-46580",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-46580/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--06a219eb-062d-4535-a8f4-cf9d542d548d",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-40087",
      "description": "CVE-2026-40087: LangChain Incomplete f-string Validation & Attribute Exposure",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-40087",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40087"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-40087",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-40087/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--444ed63a-0091-4e7c-a279-9ce08cc0c979",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-32711",
      "description": "CVE-2025-32711: Microsoft 365 Copilot EchoLeak Zero-Click IPI",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-32711",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32711"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-32711",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-32711/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--14fa3f8e-6392-49ed-a45a-820196030101",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-53773",
      "description": "CVE-2025-53773: GitHub Copilot RCE via Settings Hijacking",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-53773",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-53773"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-53773",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-53773/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--63ae33e6-2c76-4510-a412-0e1c57c53aaa",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-27966",
      "description": "CVE-2026-27966: Langflow CSV Agent Hardcoded Dangerous Code Execution RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-27966",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27966"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-27966",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-27966/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--ee340eae-e3fc-4276-a245-71a23fcaacea",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-33873",
      "description": "CVE-2026-33873: Langflow Agentic Assistant Dynamic Execution Sink RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-33873",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33873"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-33873",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-33873/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--ec8e48c0-df98-4212-a152-4116a335c51d",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-52573",
      "description": "CVE-2025-52573: iOS Simulator MCP Server ui_tap Command Injection",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-52573",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-52573"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-52573",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-52573/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--64b3574d-08fb-4c31-aafa-d2ef3eace3c6",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-66389",
      "description": "CVE-2025-66389: GitHub Copilot Workspace Traversal & File-Handler Exfiltration",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-66389",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-66389"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-66389",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-66389/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--b2fac28c-3fe6-4be1-a32a-194547bef238",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-24307",
      "description": "CVE-2026-24307: Microsoft 365 Copilot Input Type Confusion & Information Disclosure",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-24307",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24307"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-24307",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-24307/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--a2309998-5b8b-4e6a-a945-6c44d2dd8f4a",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-59417",
      "description": "CVE-2025-59417: Lobe Chat lobeArtifact SVG dangerouslySetInnerHTML XSS to RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-59417",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-59417"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-59417",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-59417/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--b80c47c1-e447-48ff-ab81-76bd4db3ecad",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-49150",
      "description": "CVE-2025-49150: Cursor AI Editor Automatic JSON Schema Download Data Exfiltration",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-49150",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49150"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-49150",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-49150/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--d4311a47-ee4b-4fa3-a0f7-6e85a3552d20",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2024-5184",
      "description": "CVE-2024-5184: EmailGPT Direct Prompt Injection & Email Data Exfiltration",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2024-5184",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5184"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2024-5184",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2024-5184/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--e110b0a3-9fe4-42f5-ae45-1c07ca5caaa8",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-21669",
      "description": "CVE-2026-21669: Veeam Backup Catalog Service Pre-Auth Binary Deserialization RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-21669",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21669"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-21669",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-21669/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--c2a8bbc6-deaa-4593-aa19-a02f87c6111b",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-21670",
      "description": "CVE-2026-21670: Veeam Backup Service WCF Impersonation Privilege Escalation",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-21670",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21670"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-21670",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-21670/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--d887e0bb-d898-44e9-a3ed-1b181edf4ca3",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-21671",
      "description": "CVE-2026-21671: Veeam Enterprise Manager Path Traversal Arbitrary File Read",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-21671",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21671"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-21671",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-21671/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--0cbe22fa-e2ff-4a3a-aee0-c7de97453d45",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-21672",
      "description": "CVE-2026-21672: Veeam Agent Configuration Service SSRF & Cloud Metadata Theft",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-21672",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21672"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-21672",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-21672/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--24ca34cb-548c-4805-a4e5-eaa48a65fb76",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-21708",
      "description": "CVE-2026-21708: Veeam Backup & Replication PostgreSQL SQL Injection to RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-21708",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21708"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-21708",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-21708/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--76ab907c-04b3-47d3-a586-825b6cd04051",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-19490",
      "description": "CVE-2026-19490: Citrix NetScaler ADC & Gateway Authentication Bypass",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-19490",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19490"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-19490",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-19490/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--3c7d9686-e035-4211-a7cd-e02c9e850929",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-25249",
      "description": "CVE-2025-25249: Fortinet FortiOS cw_acd CAPWAP Heap Buffer Overflow RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-25249",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25249"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-25249",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-25249/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--cc336701-7a79-4e90-aacd-952a61fd26d7",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-87491",
      "description": "CVE-2026-87491: Google Chromium V8 Out-of-Bounds Write Zero-Day to Sandbox RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-87491",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87491"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-87491",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-87491/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--e5b2fd2d-cbc8-4107-a8bb-2b40aa395b02",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-86060",
      "description": "CVE-2026-86060: MikroTik RouterOS SSH Argument Delimiter Privilege Escalation",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-86060",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86060"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-86060",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-86060/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--e14612e4-c6f7-4852-a8de-c974536287b0",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-67277",
      "description": "CVE-2026-67277: MikroTik RouterOS Bandwidth-Test Auth Bypass & Kernel Memory Leak / DoS",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-67277",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67277"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-67277",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-67277/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--965759d8-0a0d-457e-ad2a-d5de8b830167",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-85102",
      "description": "CVE-2026-85102: Check Point VPN Certificate Trust Validation Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-85102",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85102"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-85102",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-85102/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--c76a2f88-7178-4993-aa4b-ee57573a8b74",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-85103",
      "description": "CVE-2026-85103: Check Point VPN Certificate ASN.1 Decoding Heap Buffer Overflow RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-85103",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85103"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-85103",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-85103/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--cbff4325-5967-440c-aae9-ac3105e7f52c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-81578",
      "description": "CVE-2026-81578: PaperCut NG/MF Web Management Authentication Bypass",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-81578",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81578"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-81578",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-81578/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--492c931c-2590-49ff-a000-81ba89e15999",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-82078",
      "description": "CVE-2026-82078: PaperCut NG/MF Database Dynamic Class Loading RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-82078",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82078"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-82078",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-82078/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--20f8a4a1-856b-4d45-ae2a-b6994800fcf8",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2021-42278",
      "description": "CVE-2021-42278: Active Directory sAMAccountName Spoofing (noPac)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2021-42278",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-42278"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2021-42278",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2021-42278/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--e8fe39c4-989b-44df-af6c-a295d635e1aa",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2021-42287",
      "description": "CVE-2021-42287: Kerberos KDC PAC Validation Impersonation (noPac)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2021-42287",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-42287"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2021-42287",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2021-42287/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--146bbdcf-27a4-4483-a59f-cd75d03f6df4",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2023-27532",
      "description": "CVE-2023-27532: Veeam Backup Service API Credential Disclosure",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2023-27532",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27532"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2023-27532",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2023-27532/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": null
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--5ff46a7e-4d46-44d0-a84e-8aa0ec817a07",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2009-0238",
      "description": "CVE-2009-0238: Microsoft Excel Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2009-0238",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2009-0238"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2009-0238",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2009-0238/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--b21b9de3-971a-43e5-ae13-2023adb3c080",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2012-1854",
      "description": "CVE-2012-1854: Microsoft VBA Insecure Library Loading",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2012-1854",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2012-1854"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2012-1854",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2012-1854/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--e8b8e29b-a8f7-4582-a9ba-796b3645cd01",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2020-2021",
      "description": "CVE-2020-2021: Palo Alto Networks PAN-OS SAML Authentication Bypass",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2020-2021",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-2021"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2020-2021",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2020-2021/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--5c3e1d5c-02e1-4936-abdf-43d2968e6d00",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2020-3452",
      "description": "CVE-2020-3452: Cisco ASA and FTD Web Services Read-Only Path Traversal",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2020-3452",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-3452"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2020-3452",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2020-3452/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--8b954c52-00bd-4708-a98d-e216b96d2ceb",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2020-9715",
      "description": "CVE-2020-9715: Adobe Acrobat and Reader Use-After-Free",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2020-9715",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-9715"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2020-9715",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2020-9715/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--d85adc37-7c71-48d3-a85e-e9760df3f95e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2022-29230",
      "description": "CVE-2022-29230: XSS in Shopify Hydrogen",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2022-29230",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-29230"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2022-29230",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2022-29230/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--9851e890-7e2d-420d-abb0-c1a8f49dbdb9",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2022-42475",
      "description": "CVE-2022-42475: Fortinet FortiOS SSL-VPN Pre-Auth Heap Buffer Overflow",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2022-42475",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42475"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2022-42475",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2022-42475/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--0ec54cee-0752-4577-a8a2-3bf97ad4720c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2023-20198",
      "description": "CVE-2023-20198: Cisco IOS XE Software Web UI Privilege Escalation Zero-Day",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2023-20198",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20198"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2023-20198",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2023-20198/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--6b6345c9-1e3b-47b4-a0b6-69dd8ed43752",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2023-21529",
      "description": "CVE-2023-21529: Microsoft Exchange Server RCE via Untrusted Deserialization",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2023-21529",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-21529"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2023-21529",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2023-21529/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--5d432dec-805a-4afb-aec6-5f4e24f788a8",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2023-27997",
      "description": "CVE-2023-27997: Fortinet FortiOS SSL-VPN Heap Buffer Overflow RCE (Volt Typhoon)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2023-27997",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27997"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2023-27997",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2023-27997/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--1887badd-5969-42ed-a5e1-cb224220bcb6",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2023-36424",
      "description": "CVE-2023-36424: VMware vCenter Server Authentication Bypass",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2023-36424",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36424"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2023-36424",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2023-36424/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--fee505b0-208f-49a1-abf7-8349aa6fc18a",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2024-0012",
      "description": "CVE-2024-0012: Palo Alto Networks PAN-OS Management Web Interface Authentication Bypass",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2024-0012",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0012"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2024-0012",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2024-0012/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--d98a4aef-f54b-4b80-a248-8d501c114a51",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2024-20353",
      "description": "CVE-2024-20353: Cisco ASA and FTD Web Server Denial of Service & Memory Corruption (ArcaneDoor)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2024-20353",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20353"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2024-20353",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2024-20353/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--348ca650-1731-46c8-a6f6-4796975baae1",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2024-20359",
      "description": "CVE-2024-20359: Cisco ASA and FTD Persistent Local Code Execution (Line Runner / ArcaneDoor)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2024-20359",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20359"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2024-20359",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2024-20359/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--eb7b9e5e-322e-4796-a193-74513fa8b768",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2024-21762",
      "description": "CVE-2024-21762: Fortinet FortiOS SSL-VPN Out-of-Bounds Write Remote Code Execution Zero-Day",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2024-21762",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21762"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2024-21762",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2024-21762/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--3a1733bd-10cc-4cc3-a326-6f906e300805",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2024-3400",
      "description": "CVE-2024-3400: Palo Alto Networks PAN-OS GlobalProtect Command Injection Zero-Day",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2024-3400",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3400"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2024-3400",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2024-3400/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--bab47d14-3b7f-487e-a14c-6f3b8cc1020e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2024-47575",
      "description": "CVE-2024-47575: Fortinet FortiManager fgfmd Authentication Bypass & Remote Code Execution (FortiJump)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2024-47575",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47575"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2024-47575",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2024-47575/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--252015bd-6b07-4f3c-add3-1225e8f30df2",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2024-57728",
      "description": "CVE-2024-57728 : SimpleHelp Arbitrary File Upload",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2024-57728",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57728"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2024-57728",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2024-57728/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--8018a302-e6f4-4965-adec-be0e5184c2d0",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-0282",
      "description": "CVE-2025-0282: Pre-Authentication Root RCE via Stack Buffer Overflow in Ivanti Connect Secure (ICS / IPS / ZTA)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-0282",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0282"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-0282",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-0282/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--38885850-1f67-4e96-af9a-e1385567712d",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-20188",
      "description": "CVE-2025-20188: Arbitrary File Upload and Root RCE in Cisco IOS XE WLC via Hard-Coded JWT",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-20188",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20188"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-20188",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-20188/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--decb767e-7288-4c43-a526-adf7d6e339b1",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-20281",
      "description": "CVE-2025-20281: Unauthenticated Root RCE in Cisco Identity Services Engine (ISE) API",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-20281",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20281"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-20281",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-20281/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--e95438fd-30ec-492a-a41a-de5e47190d03",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-20352",
      "description": "CVE-2025-20352: SNMP Stack Buffer Overflow in Cisco IOS and IOS XE (DoS & RCE)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-20352",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20352"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-20352",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-20352/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--4b1b7578-644c-4cee-a209-befc0c385a80",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-20393",
      "description": "CVE-2025-20393: Unauthenticated Root RCE in Cisco Secure Email Gateway (Spam Quarantine)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-20393",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20393"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-20393",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-20393/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--fd2c0bf2-ad5b-44e5-ab09-d8398300fef1",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-21333",
      "description": "CVE-2025-21333: Windows Kernel Privilege Escalation via Hyper-V VSP (Heap Overflow)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-21333",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21333"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-21333",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-21333/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--27efb9d5-3d19-460c-a533-b2335851977e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-22457",
      "description": "CVE-2025-22457: Subsequent Pre-Auth Root RCE via Stack Buffer Overflow in Ivanti Connect Secure (ICS / IPS / ZTA)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-22457",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22457"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-22457",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-22457/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--12cbbb2d-4e8d-4826-a265-5f541351fd6d",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-23304",
      "description": "CVE-2025-23304: NVIDIA NeMo Framework RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-23304",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23304"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-23304",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-23304/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--4e520af6-03e9-4789-ac76-c4cd8dbd96a0",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-24054",
      "description": "CVE-2025-24054: NTLM Hash Disclosure and Coerced Authentication in Windows (.library-ms)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-24054",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24054"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-24054",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-24054/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 6.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--d369c1e4-722e-489e-acce-65afc804d323",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-24472",
      "description": "CVE-2025-24472: Super-Admin Authentication Bypass in Fortinet FortiOS & FortiProxy (CSF Proxy)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-24472",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24472"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-24472",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-24472/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--5c65350f-e2bd-4175-aaa7-94da05bd5958",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-24813",
      "description": "CVE-2025-24813: RCE via Partial PUT Requests and Session Deserialization in Apache Tomcat",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-24813",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24813"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-24813",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-24813/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--c5bb16ce-9ebd-4dac-a43a-15215088ad9e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-25257",
      "description": "CVE-2025-25257: Unauthenticated SQL Injection in Fortinet FortiWeb Management Interface",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-25257",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25257"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-25257",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-25257/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--25db4afa-1f31-4cdf-a288-1cce7424b838",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-26319",
      "description": "CVE-2025-26319: Flowise Arbitrary File Upload and Directory Traversal Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-26319",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26319"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-26319",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-26319/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--80614a3b-f58d-47e5-aa26-d52135911eea",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-29635",
      "description": "CVE-2025-29635: Command injection vulnerability in D-Link DIR-823X router firmware",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-29635",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29635"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-29635",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-29635/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--2737339b-7153-4c79-aa39-d125a8822127",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-29824",
      "description": "CVE-2025-29824: SYSTEM Privilege Escalation in Windows CLFS Driver (Use-After-Free)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-29824",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29824"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-29824",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-29824/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--2d772e96-d3ee-4b7e-ad39-aefee3a980da",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-29927",
      "description": "CVE-2025-29927: Middleware Authorization Bypass via x-middleware-subrequest Header in Next.js",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-29927",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29927"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-29927",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-29927/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--ad4dfe94-23f9-4555-aef3-f621eb6992e8",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-30733",
      "description": "CVE-2025-30733: Pre-Authentication Memory Leak in Oracle Database Server (RDBMS Listener)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-30733",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30733"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-30733",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-30733/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 6.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--08af832f-4a18-4580-ae36-ea471a96329b",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-32433",
      "description": "CVE-2025-32433: Pre-Authentication Command Execution in Erlang/OTP SSH Server",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-32433",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32433"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-32433",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-32433/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--3070e534-621f-44b3-a2ff-fcd376eb64c5",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-3248",
      "description": "CVE-2025-3248: Langflow Unauthenticated Code Validation Python exec() Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-3248",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3248"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-3248",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-3248/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--834d7294-16c0-4c51-afa2-2c5ba90999ff",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-32724",
      "description": "CVE-2025-32724: Remote Denial of Service and System Crash in Windows LSASS via RPC",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-32724",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32724"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-32724",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-32724/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--983013aa-b175-44aa-ad88-3e21fa3f6dda",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-39682",
      "description": "CVE-2025-39682: Linux Kernel kTLS Receive Path Zero-Length Record Use-After-Free Privilege Escalation",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-39682",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39682"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-39682",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-39682/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--9382cdca-ca33-4c00-a4bd-d51ab5cb3719",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-39964",
      "description": "CVE-2025-39964: Linux Kernel Crypto AF_ALG Concurrent Write Race Condition",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-39964",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39964"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-39964",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-39964/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--69554729-a5eb-4e2c-a997-5ac234199a85",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-42944",
      "description": "CVE-2025-42944: Unauthenticated Java Deserialization RCE in SAP NetWeaver AS Java (RMI-P4)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-42944",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-42944"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-42944",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-42944/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--88657c14-b7b9-44ef-ad92-762d7b7c0d89",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-47277",
      "description": "CVE-2025-47277: vLLM Distributed KV-Cache PyNcclPipe Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-47277",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47277"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-47277",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-47277/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--55320dae-25ab-43da-ac83-3353b2c0c1c1",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-49113",
      "description": "CVE-2025-49113: Authenticated RCE via PHP Deserialization in Roundcube Webmail (upload.php)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-49113",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49113"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-49113",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-49113/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--48343358-7151-4044-abe6-d3f9db13aee9",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-49704",
      "description": "CVE-2025-49704: Remote Code Injection in Microsoft SharePoint Server",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-49704",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49704"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-49704",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-49704/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--04fa85fe-1d1e-4b48-ac38-350a89a2704a",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-50105",
      "description": "CVE-2025-50105: Privilege Escalation and Workflow Tampering in Oracle E-Business Suite (Universal Work Queue)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-50105",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-50105"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-50105",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-50105/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--5bd4ee66-5624-4a00-a8ee-39d3d00a70ac",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-5277",
      "description": "CVE-2025-5277: Command Injection in AWS MCP Server via Prompt-Coerced Tool Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-5277",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5277"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-5277",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-5277/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--211924de-36e0-425a-af68-6f3b7e6c770c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-52970",
      "description": "CVE-2025-52970: Access Control Bypass and Privilege Escalation in Fortinet FortiWeb",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-52970",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-52970"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-52970",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-52970/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--46875624-eb09-49f0-aa7b-62f322008a32",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-53770",
      "description": "CVE-2025-53770: Insecure Deserialization RCE in Microsoft SharePoint Server (ToolShell)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-53770",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-53770"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-53770",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-53770/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--9faf840b-51bf-4c09-a537-a41273c6c0e8",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-53844",
      "description": "CVE-2025-53844: FortiOS Out-of-Bounds Write via Compromised Fabric Devices",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-53844",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-53844"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-53844",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-53844/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--432daf2d-2c0a-4b58-aece-a8c5d6809967",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-54794",
      "description": "CVE-2025-54794: Claude Code Working Directory Sandbox Escape via Path Prefix Matching",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-54794",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-54794"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-54794",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-54794/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--b5aa53ee-d5bc-4808-a25e-abfb1b0faca2",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-54795",
      "description": "CVE-2025-54795: Claude Code Echo Command Injection and Approval Prompt Bypass via Untrusted Context",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-54795",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-54795"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-54795",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-54795/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--0e0a7e09-aec9-4348-a55f-5e55c843e35d",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-55125",
      "description": "CVE-2025-55125: Root Command Injection via Backup Configuration in Veeam Backup & Replication",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-55125",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-55125"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-55125",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-55125/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--09cfd756-732a-426d-ac11-8d9ddb3e9e05",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-55182",
      "description": "CVE-2025-55182:",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-55182",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-55182"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-55182",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-55182/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--d51d6b2d-6180-454c-a84d-44b49446a5c0",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-5777",
      "description": "CVE-2025-5777: OOB Memory Disclosure and MFA Session Hijacking in Citrix NetScaler ADC & Gateway (CitrixBleed 2)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-5777",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5777"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-5777",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-5777/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--dcb73638-0aa3-4f57-ae31-eddc24a09ca5",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-58434",
      "description": "CVE-2025-58434: FlowiseAI Unauthenticated Full Account Takeover",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-58434",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58434"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-58434",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-58434/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--edf5354a-2f7b-44b5-a215-62e18a9848da",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-59468",
      "description": "CVE-2025-59468: PostgreSQL Remote Code Execution via Malicious Password Parameter in Veeam Backup & Replication",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-59468",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-59468"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-59468",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-59468/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--596e9246-f252-4d01-afda-e2aca7f7bee1",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-59469",
      "description": "CVE-2025-59469: Arbitrary File Write as Root by Operators in Veeam Backup & Replication",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-59469",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-59469"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-59469",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-59469/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--b8ac5dbe-6dd2-4ebe-a355-c919d9faf309",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-59470",
      "description": "CVE-2025-59470: PostgreSQL Remote Code Execution via Operator Role in Veeam Backup & Replication",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-59470",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-59470"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-59470",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-59470/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--5a0ba985-2417-407e-a740-407c19bd8469",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-59528",
      "description": "CVE-2025-59528: Flowise CustomMCP Node JavaScript Function Constructor Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-59528",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-59528"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-59528",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-59528/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--6b59d7e9-48f1-4960-aa69-7a3bdd77ee0b",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-60710",
      "description": "CVE-2025-60710 - Elevation of Privilege in Host Process for Windows Tasks",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-60710",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-60710"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-60710",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-60710/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--3be7517c-87f4-4854-ab6c-b59e6375be74",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-61882",
      "description": "CVE-2025-61882: Zero-Day RCE in Oracle E-Business Suite (BI Publisher / Concurrent Processing)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-61882",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61882"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-61882",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-61882/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--cf75891c-5d01-4b0d-a6dd-4588e8d92fb3",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-64504",
      "description": "CVE-2025-64504: Langfuse Cross-Organization Member Enumeration",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-64504",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-64504"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-64504",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-64504/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--69ded9ff-ce2d-4c5a-a01b-32f2058c570a",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-8088",
      "description": "CVE-2025-8088: WinRAR Path Traversal Vulnerability",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-8088",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-8088"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-8088",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-8088/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--5b5bf598-f1e7-429f-adfc-adb9d346d4f6",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-0257",
      "description": "CVE-2026-0257: Critical Authentication Bypass in Palo Alto Networks GlobalProtect Portal",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-0257",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0257"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-0257",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-0257/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--44b6cfb1-604e-4443-a372-93df0a88bdbe",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-0300",
      "description": "CVE-2026-0300: Unauthenticated Stack Buffer Overflow to Root RCE in Palo Alto Networks PAN-OS User-ID Captive Portal",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-0300",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0300"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-0300",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-0300/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--93eac75f-5098-4c20-ae71-1bb4227827ea",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-0770",
      "description": "CVE-2026-0770: Unauthenticated Remote Code Execution in Langflow via Code Validation Sandbox Escape",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-0770",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0770"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-0770",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-0770/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--69a0d9c1-4c5c-41a4-a7f1-70da7a573d3c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-0915",
      "description": "CVE-2026-0915: glibc getnetbyaddr Stack Memory Leak to DNS Resolver",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-0915",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0915"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-0915",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-0915/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 6.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--714eec4e-1c8b-4a54-abe4-e222de49a6a5",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-11393",
      "description": "CVE-2026-11393: AWS Bedrock AgentCore Multi-Agent Collaboration Poisoning via Triple-Quote Injection RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-11393",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11393"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-11393",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-11393/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--b053aee0-2f52-4ba1-a898-ae34edc9c29a",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-11940",
      "description": "CVE-2026-11940: CPython tarfile Extraction Filter Directory Traversal Bypass",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-11940",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11940"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-11940",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-11940/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--2007d67c-d5b6-47d0-a8f1-b80c75992a2e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-11945",
      "description": "CVE-2026-11945: PostgreSQL Anonymizer Rules Import Function SQL Injection",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-11945",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11945"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-11945",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-11945/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 6.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--a44e7971-9624-4e94-aeaf-2fbfab725876",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-11972",
      "description": "CVE-2026-11972: CPython tarfile Streaming Mode EOF Denial of Service",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-11972",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11972"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-11972",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-11972/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--77af9155-6d00-45fe-a9c9-1d7983bd3ff7",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-12045",
      "description": "CVE-2026-12045: pgAdmin 4 AI Assistant Read-Only Transaction Bypass to RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-12045",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12045"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-12045",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-12045/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--593664ea-f8a0-425a-aba9-9d6c9f4baa98",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-12289",
      "description": "CVE-2026-12289: Mozilla Firefox WebRender Graphics Privilege Escalation",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-12289",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12289"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-12289",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-12289/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--2003bbf0-a55c-45e5-a9b7-e3b35e6dde5a",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-12293",
      "description": "CVE-2026-12293: Mozilla Firefox WebGPU Use-After-Free Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-12293",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12293"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-12293",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-12293/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--3ad93f41-bd11-42f5-aca4-3e5f7129972f",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-12304",
      "description": "CVE-2026-12304: Mozilla Firefox Cross-Origin Cookie Leakage & SOP Bypass",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-12304",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12304"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-12304",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-12304/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 6.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--49d20b6d-eceb-4890-a36e-475509b1a82f",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-12645",
      "description": "CVE-2026-12645: Authenticated Remote Code Execution in Ivanti Neurons for ITSM via Missing Authorization in Workflow Handlers",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-12645",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12645"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-12645",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-12645/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--462c7ec3-a095-49e6-a672-8782bb6cb1c0",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-12646",
      "description": "CVE-2026-12646: Authenticated Remote Code Execution in Ivanti Neurons for ITSM via Missing Authorization in Business Logic Actions",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-12646",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12646"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-12646",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-12646/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--1499f0ac-4dad-4a58-a848-859142e54440",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-12647",
      "description": "CVE-2026-12647: Authenticated Remote Code Execution in Ivanti Neurons for ITSM via Missing Authorization in Automation Engine",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-12647",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12647"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-12647",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-12647/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--89197ee9-974d-4422-a92a-b54754c33346",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-12648",
      "description": "CVE-2026-12648: Authenticated Remote Code Execution in Ivanti Neurons for ITSM via Deserialization of Untrusted Data",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-12648",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12648"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-12648",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-12648/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--c05ef79f-5dda-43bc-a61c-dc2fb2f76d22",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-12650",
      "description": "CVE-2026-12650: Authenticated Remote Code Execution with Scope Elevation in Ivanti Neurons for ITSM via Insecure Deserialization",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-12650",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12650"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-12650",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-12650/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--4f3dcf7c-4821-49cd-abcc-37abbe5ed5e9",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-12651",
      "description": "CVE-2026-12651: Authenticated Remote Code Execution in Ivanti Neurons for ITSM via Data Deserialization",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-12651",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12651"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-12651",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-12651/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--b3adae59-53a1-4e5b-a012-dc137b20f3dc",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-12744",
      "description": "CVE-2026-12744: Unauthenticated Remote Code Execution in Ivanti Neurons for ITSM via Insecure .NET Object Deserialization",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-12744",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12744"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-12744",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-12744/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--4ed32fcd-2756-4c0e-acd9-f676104241d7",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-12745",
      "description": "CVE-2026-12745: Secondary Unauthenticated Remote Code Execution in Ivanti Neurons for ITSM via Deserialization Flaw",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-12745",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12745"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-12745",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-12745/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--a60a8cee-149d-4bf8-a002-12f07d9599c0",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-1340",
      "description": "CVE-2026-1340: Unauthenticated Remote Code Execution in Ivanti EPMM",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-1340",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1340"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-1340",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-1340/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--0ed620ce-4921-4658-ab35-589dabcbcd72",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-14894",
      "description": "CVE-2026-14894: Super Forms WordPress Plugin Unauthenticated Arbitrary File Upload to Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-14894",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14894"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-14894",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-14894/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--4c4f9b40-2748-4d3b-abbb-99d8b9c7f891",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-15308",
      "description": "CVE-2026-15308: CPython HTMLParser.feed() Unterminated Markup CPU Exhaustion DoS",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-15308",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15308"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-15308",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-15308/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--926587d2-b796-404b-a8a3-7f3c59c916e5",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-15718",
      "description": "CVE-2026-15718: Mozilla Firefox WebAssembly Invalid Pointer Dereference",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-15718",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15718"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-15718",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-15718/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--9c6d6a58-f5c0-4791-a50b-4e4a97da5617",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-15719",
      "description": "CVE-2026-15719: Mozilla Firefox Site Isolation Bypass via DOM Navigation",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-15719",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15719"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-15719",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-15719/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--243aeca4-4da3-4cc1-a24e-07fcfffea620",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-16356",
      "description": "CVE-2026-16356: Mozilla Firefox Use-After-Free in Accessibility APIs",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-16356",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16356"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-16356",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-16356/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--7616114c-89d0-444c-a849-a68e6fea372a",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-18486",
      "description": "CVE-2026-18486: IBM ContextForge MCP Gateway jq Filter Credential Theft",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-18486",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18486"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-18486",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-18486/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--7df4f675-811b-46dc-a5e5-8bb2ef4fbfa2",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-18503",
      "description": "CVE-2026-18503: CPython csv.Sniffer Super-Linear ReDoS CPU Consumption",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-18503",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18503"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-18503",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-18503/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 6.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--661252a5-0b90-4034-ace8-d016c3b036cb",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-18851",
      "description": "CVE-2026-18851: Authenticated Privilege Escalation to Administrator in Ivanti Endpoint Manager Mobile via Missing Authorization",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-18851",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18851"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-18851",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-18851/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--3ab0d680-9e44-484f-affb-24cab09f43b6",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-2006",
      "description": "CVE-2026-2006: PostgreSQL Multibyte Character Length Validation Buffer Overrun RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-2006",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2006"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-2006",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-2006/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--6d451def-81c3-427b-a9de-fcd4ce3962af",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-2007",
      "description": "CVE-2026-2007: PostgreSQL pg_trgm Heap Buffer Overflow Pattern Corruption",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-2007",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2007"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-2007",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-2007/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--eaf5a0ac-5b03-498c-a4f9-2b328f7c4877",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-20079",
      "description": "CVE-2026-20079: Cisco Secure FMC Authentication Bypass to Root RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-20079",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20079"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-20079",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-20079/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--565f4f04-4569-43c3-a5bd-a5a9fe368038",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-20122",
      "description": "CVE-2026-20122: Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-20122",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20122"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-20122",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-20122/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--1c9b2d4b-d43a-4612-aa79-37ddd0c483df",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-20127",
      "description": "CVE-2026-20127: Cisco Catalyst SD-WAN Authentication Bypass",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-20127",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20127"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-20127",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-20127/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--a0b93c2e-b588-40de-ac5e-e0d6328ad395",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-20128",
      "description": "CVE-2026-20128: Cisco Catalyst SD-WAN Manager DCA Credential Disclosure and Privilege Escalation Vulnerability",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-20128",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20128"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-20128",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-20128/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--f39e2454-1a46-4a3d-aabc-352e67087601",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-20133",
      "description": "CVE-2026-20133: Cisco Catalyst SD-WAN Manager Sensitive Information Disclosure Vulnerability",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-20133",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20133"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-20133",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-20133/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--be729b94-6922-4379-a745-aec202bce3a1",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-20147",
      "description": "CVE-2026-20147: Cisco ISE Remote Code Execution Vulnerability",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-20147",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20147"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-20147",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-20147/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--a5683129-dfbe-447c-a8a9-b380ede05102",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-20180",
      "description": "CVE-2026-20180: Cisco ISE Multiple Remote Code Execution Vulnerability",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-20180",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20180"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-20180",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-20180/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--f4876288-4771-4955-a0d2-7691019ae8f8",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-20184",
      "description": "CVE-2026-20184: Cisco Webex SSO Impersonation Vulnerability",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-20184",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20184"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-20184",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-20184/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--d4ed644e-d6a3-4187-a208-bf42334c66c2",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-20186",
      "description": "CVE-2026-20186 - Cisco ISE Command Injection",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-20186",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20186"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-20186",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-20186/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--d56341b4-f957-49b1-a572-2afe06d9b48c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-20192",
      "description": "CVE-2026-20192: Cisco Identity Services Engine Unauthenticated Authorization Bypass",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-20192",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20192"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-20192",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-20192/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--744f1d5e-8dcf-4120-a17c-6c606a828bbf",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-20205",
      "description": "CVE-2026-20205: Sensitive Information Disclosure in Splunk MCP Server",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-20205",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20205"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-20205",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-20205/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--f5775dff-b1f0-42a6-a0a5-dfa959ee7a91",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-20307",
      "description": "CVE-2026-20307: Cisco Identity Services Engine Insecure Java Deserialization RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-20307",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20307"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-20307",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-20307/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--34323f17-efe8-4e69-a754-cb5f025fd76d",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-20324",
      "description": "CVE-2026-20324: Cisco Secure Firewall Management Center sftunnel OS Command Injection RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-20324",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20324"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-20324",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-20324/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--74da476a-d248-4f5f-a2f4-2083cb199262",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-21510",
      "description": "CVE-2026-21510: Windows Shell Security Feature Bypass",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-21510",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21510"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-21510",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-21510/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--c3fa5fdd-63a2-4dea-ab60-5ce30b4ec295",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-21643",
      "description": "CVE-2026-21643: Fortinet FortiClient EMS SQL Injection",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-21643",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21643"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-21643",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-21643/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--890041e0-fa18-4629-a712-5503d8e851ff",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-21962",
      "description": "CVE-2026-21962: Critical Authentication & Access Control Bypass in Oracle WebLogic Server Proxy Plug-in",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-21962",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21962"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-21962",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-21962/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--f5555eb2-685c-4210-a33f-92d097fc0688",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-22153",
      "description": "CVE-2026-22153: FortiOS LDAP Authentication Bypass in Agentless VPN & FSSO",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-22153",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22153"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-22153",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-22153/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--91648d1b-0df3-4a7f-a8ad-62d9425963be",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-22778",
      "description": "CVE-2026-22778: vLLM Multimodal Video URL Heap Overflow and ASLR Bypass RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-22778",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22778"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-22778",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-22778/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--13316664-fcf3-4878-a74e-48680bade83e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-22807",
      "description": "CVE-2026-22807: vLLM Dynamic Module Auto-Map Pre-Auth Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-22807",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22807"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-22807",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-22807/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--2b3b979c-377f-442b-a751-50fe871546b7",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-23246",
      "description": "CVE-2026-23246: Linux Kernel mac80211 Wi-Fi 7 MLO Reconfiguration link_id Array Index Overflow",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-23246",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23246"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-23246",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-23246/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--ecc286d9-5858-4e64-a3df-bc3029367625",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-23269",
      "description": "CVE-2026-23269: Linux Kernel AppArmor DFA Policy Unpack Out-of-Bounds State Validation",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-23269",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23269"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-23269",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-23269/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--bfb16a3b-e319-4ea4-a3a2-304b7901947b",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-23288",
      "description": "CVE-2026-23288: Linux Kernel AMD XDNA NPU Command Ring Out-of-Bounds Write",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-23288",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23288"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-23288",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-23288/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--0c1a021e-b834-4af7-a9eb-01b271db0b10",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-23432",
      "description": "CVE-2026-23432: Linux Kernel Hyper-V mshv Guest Memory Mapping Use-After-Free",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-23432",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23432"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-23432",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-23432/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--bbef5b33-7e10-4b3b-ab75-9821bad62b18",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-2360",
      "description": "CVE-2026-2360: PostgreSQL Anonymizer Operator search_path Superuser Privilege Escalation",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-2360",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2360"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-2360",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-2360/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--2023a845-c8ec-49fb-aef8-ac54dcf31d58",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-23772",
      "description": "CVE-2026-23772: Privilege Escalation in Dell Storage Manager",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-23772",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23772"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-23772",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-23772/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--ad2e13ca-2786-45e3-ae77-272f0cf341f8",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-24858",
      "description": "CVE-2026-24858: Critical FortiCloud SSO Authentication Bypass (Active In-The-Wild Exploitation)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-24858",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24858"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-24858",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-24858/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--0e599c3b-6883-48f0-a99b-c2550b87fc49",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-25089",
      "description": "CVE-2026-25089: Unauthenticated Remote OS Command Injection in Fortinet FortiSandbox Web Interface",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-25089",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25089"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-25089",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-25089/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--157a78ab-0e23-4052-a660-c30bdd56e458",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-25724",
      "description": "CVE-2026-25724: Anthropic Claude Code Agentic Permission Bypass via Symlink Traversal",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-25724",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25724"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-25724",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-25724/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--f6e2cc46-25ef-4de7-a510-7a2bf360fa43",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-25750",
      "description": "CVE-2026-25750: URL Parameter Injection Vulnerability in LangSmith Studio",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-25750",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25750"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-25750",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-25750/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--06fc6765-514b-46e6-a886-2c53044b771a",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-27825",
      "description": "CVE-2026-27825: mcp-atlassian Confluence Download Attachment Arbitrary File Write RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-27825",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27825"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-27825",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-27825/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--3ab43550-d079-48f8-a432-dc25d8d26ee6",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-27826",
      "description": "CVE-2026-27826: mcp-atlassian Unvalidated Header SSRF to Cloud Instance Metadata",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-27826",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27826"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-27826",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-27826/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--6b1058f2-5081-499e-afa1-8639b1039c0a",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-28326",
      "description": "CVE-2026-28326: SolarWinds Access Rights Manager Hard-coded Key Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-28326",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28326"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-28326",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-28326/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--e0289472-0d2f-4b42-a7e6-a40b9d935e59",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-3055",
      "description": "CVE-2026-3055: NetScaler Memory Overread (SAML IdP)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-3055",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3055"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-3055",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-3055/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--584bc6a5-73f1-49bf-aaba-4cbeaa4f3877",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-30615",
      "description": "CVE-2026-30615: Windsurf MCP Prompt Injection RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-30615",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-30615"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-30615",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-30615/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--1c325b2f-6791-4eba-a114-2e696374db85",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-30617",
      "description": "CVE-2026-30617: Remote Code Execution in LangChain-ChatChat",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-30617",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-30617"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-30617",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-30617/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--e8467fb7-2b70-40d5-a362-2f8242652fcb",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-30623",
      "description": "CVE-2026-30623: LiteLLM Authenticated MCP RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-30623",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-30623"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-30623",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-30623/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--5e77b297-4c86-40bf-a4c7-700b0e0cd473",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-30624",
      "description": "CVE-2026-30624: Agent Zero External MCP Servers Command Injection",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-30624",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-30624"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-30624",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-30624/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--1dafbb92-a318-45ab-a509-c42e0d2812e6",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-31223",
      "description": "CVE-2026-31223: Snorkel AI BaseLabeler pickle.load Insecure Deserialization RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-31223",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31223"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-31223",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-31223/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--1844348e-0669-4c4e-aa73-29d3378c25e0",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-31368",
      "description": "CVE-2026-31368: Database Initialization Failure",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-31368",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31368"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-31368",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-31368/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--ba475934-9fe3-4f6a-a39e-1b225a29110b",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-31377",
      "description": "CVE-2026-31377: Apache Doris Frontend Meta Service Unauthenticated Access and Metadata Exfiltration",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-31377",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31377"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-31377",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-31377/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--bba87b4f-d5be-4963-afe5-f5c0a159a18a",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-31430",
      "description": "CVE-2026-31430: Linux Kernel X.509 Certificate Parser Empty Extension Out-of-Bounds Read",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-31430",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31430"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-31430",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-31430/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 6.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--c40fdbce-958f-4e64-aab1-21854ee00947",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-31431",
      "description": "CVE-2026-31431: Linux Kernel",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-31431",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31431"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-31431",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-31431/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--141d9a07-97d6-409b-aa49-fb0977b70222",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-31633",
      "description": "CVE-2026-31633: Linux Kernel AF_RXRPC rxgk Token Handling Integer Overflow",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-31633",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31633"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-31633",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-31633/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--8c43bfde-128b-4477-aadc-16d89f095ef9",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-31718",
      "description": "CVE-2026-31718: Linux Kernel ksmbd Durable File Handle Scavenger Use-After-Free",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-31718",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31718"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-31718",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-31718/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--f79bd330-e08f-478e-ac80-2e9009bded0e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-31845",
      "description": "CVE-2026-31845: Reflected XSS in Rukovoditel CRM",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-31845",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31845"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-31845",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-31845/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--b1d69f6d-c9e7-4655-a2db-2b696148a4c7",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-3195",
      "description": "CVE-2026-3195: QEMU virtio-snd PCM Input Buffer Heap Overflow (Incomplete CVE-2024-7730 Fix)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-3195",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3195"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-3195",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-3195/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--2cde2475-de62-461e-a706-79db68dd3cd0",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-32201",
      "description": "CVE-2026-32201: Microsoft SharePoint Server Spoofing Vulnerability",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-32201",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32201"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-32201",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-32201/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--bc33313b-413d-40fa-aeb1-92cfd7d51d0d",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-32626",
      "description": "CVE-2026-32626: AnythingLLM Desktop Streaming Phase XSS to Electron Host RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-32626",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32626"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-32626",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-32626/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--d867d9c8-f751-46c3-a6cb-aba48bc92299",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-32997",
      "description": "CVE-2026-32997: Arbitrary File Write in Linux-based Veeam Backup & Replication",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-32997",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32997"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-32997",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-32997/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--77ba4f02-f411-4386-ad1a-dead09b610ed",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-33017",
      "description": "CVE-2026-33017: Unauthenticated RCE in Langflow via build_public_tmp Endpoint",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-33017",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33017"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-33017",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-33017/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--96f88aed-8039-464c-a448-3dad9237bc98",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-33626",
      "description": "CVE-2026-33626: LMDeploy Vision-Language SSRF & Cloud Metadata Exfiltration",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-33626",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33626"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-33626",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-33626/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--4779335f-2a6d-472f-aff2-3136c9348669",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-33634",
      "description": "CVE-2026-33634: Supply Chain Compromise in Aqua Security Trivy GitHub Actions Workflow",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-33634",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33634"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-33634",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-33634/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--1dcee843-b821-429b-a1ea-1065d7c7d274",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-33825",
      "description": "CVE-2026-33825: Microsoft Defender",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-33825",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33825"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-33825",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-33825/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--f731b3c3-3017-45e9-a343-9e35de51a461",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-34183",
      "description": "CVE-2026-34183: OpenSSL QUIC PATH_CHALLENGE Unbounded Memory Growth DoS",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-34183",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34183"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-34183",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-34183/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--70e282b3-d304-4b82-ad87-b1f04d93fc75",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-34197",
      "description": "CVE-2026-34197: Apache ActiveMQ Classic Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-34197",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34197"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-34197",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-34197/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--03922cd1-2b74-44e7-a654-db74aabe7fae",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-34621",
      "description": "CVE-2026-34621: Acrobat Reader Prototype Pollution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-34621",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34621"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-34621",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-34621/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--11a4f9b6-377b-4e86-a830-3d1fea30804e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-35188",
      "description": "CVE-2026-35188: OpenSSL Double-Free in TLS OCSP Stapling Verification",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-35188",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35188"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-35188",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-35188/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--7b86b6e9-b8b0-4403-abb6-b3bf6203dbf7",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-35385",
      "description": "CVE-2026-35385: OpenSSH scp Legacy Protocol Setuid File Installation",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-35385",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35385"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-35385",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-35385/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--70bf4b03-bbbc-4a7d-a412-d8496abef2e4",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-37008",
      "description": "CVE-2026-37008: CrewAI CodeInterpreterTool Python Sandbox Escape & Host Takeover",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-37008",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-37008"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-37008",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-37008/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--43be2fb8-b44b-4d94-a36f-156a20efa37b",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-37338",
      "description": "CVE-2026-37338: SQL Injection in SourceCodester Simple Music Cloud Community System",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-37338",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-37338"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-37338",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-37338/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--bf73d132-dd83-4d6c-a6fb-1e5f892f4ba8",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-39808",
      "description": "CVE-2026-39808: Root OS Command Injection in Fortinet FortiSandbox Administrative API",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-39808",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39808"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-39808",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-39808/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--76007fc5-8be6-4cb6-a047-d6dd6d2570f6",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-39842",
      "description": "CVE-2026-39842: Expression Injection in OpenRemote IoT Platform",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-39842",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39842"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-39842",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-39842/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--8115d3f1-3c87-48d5-a536-0ce711d23b01",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-39884",
      "description": "CVE-2026-39884: Argument Injection in mcp-server-kubernetes",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-39884",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39884"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-39884",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-39884/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--7aca89fb-264a-4ac4-ac72-3f9839af4108",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-40170",
      "description": "CVE-2026-40170: ngtcp2 stack buffer overflow",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-40170",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40170"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-40170",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-40170/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--ea933224-8df6-4f85-a90c-718c16c33afa",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-40192",
      "description": "CVE-2026-40192: Pillow FITS Image GZIP Decompression Bomb Denial of Service",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-40192",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40192"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-40192",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-40192/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--5ddda504-626e-408a-a45c-1f62307e68ce",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-40227",
      "description": "CVE-2026-40227: systemd IPC API Array Null Element Assertion Crash",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-40227",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40227"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-40227",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-40227/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 6.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--f70db426-1dad-4097-a25e-edb745ce0e72",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-40933",
      "description": "CVE-2026-40933: Flowise MCP Adapter Stdio Command Injection RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-40933",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40933"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-40933",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-40933/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--6eb740bc-ecc7-4cd8-ac00-30d6371cc00c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-41035",
      "description": "CVE-2026-41035: rsync receiver use-after-free",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-41035",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41035"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-41035",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-41035/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--12798e23-9997-4599-a749-464d3edcc141",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-41254",
      "description": "CVE-2026-41254: Integer Overflow in Little CMS (lcms2) Affecting Java 2D Color Management",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-41254",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41254"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-41254",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-41254/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--a620dca0-5751-4a1b-a333-532a34e24f70",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-41703",
      "description": "CVE-2026-41703: VMware ESXi Out-of-Bounds Read in VM Lifecycle Handling",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-41703",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41703"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-41703",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-41703/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--716ceee3-8619-43ed-a85d-9887f08606e3",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-41709",
      "description": "CVE-2026-41709: VMware ESXi Insufficient Logging & Forensic Evasion",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-41709",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41709"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-41709",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-41709/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 6.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--6ebdd1cd-4048-46e4-a48b-459c18690551",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-41843",
      "description": "CVE-2026-41843: Path Traversal in Spring Framework Versioned Static Resource Resolution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-41843",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41843"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-41843",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-41843/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 6.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--85165bc7-5a16-48da-a626-286031aa41fe",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-41849",
      "description": "CVE-2026-41849: Integer Overflow Denial of Service via SpEL String Multiplication in Spring Framework",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-41849",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41849"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-41849",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-41849/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--21851623-f919-4521-ac55-04c93aef0050",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-42016",
      "description": "CVE-2026-42016: Privilege Escalation in JFrog Artifactory via Token Scope Authorization Validation Bypass",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-42016",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42016"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-42016",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-42016/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--bd5a25ee-8eed-4f82-a8a6-536b94a85258",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-42018",
      "description": "CVE-2026-42018: Anonymous User Token Generation Exposure in JFrog Artifactory",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-42018",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42018"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-42018",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-42018/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--dfae2f54-142c-4bfa-a534-6af4b4164ad1",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-42208",
      "description": "CVE-2026-42208: LiteLLM Proxy API Key SQL Injection",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-42208",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42208"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-42208",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-42208/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--08c936ed-b339-4685-a130-cb3419429bff",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-42249",
      "description": "CVE-2026-42249: Ollama Windows Auto-Updater HTTP Header Path Traversal RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-42249",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42249"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-42249",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-42249/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--eef88695-df93-45ac-abd6-259eba86a8d8",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-42271",
      "description": "CVE-2026-42271: Unauthenticated Remote OS Command Injection in LiteLLM Proxy Test Endpoints",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-42271",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42271"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-42271",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-42271/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--12272806-29d8-40b3-a4f4-59e7d890ce21",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-43114",
      "description": "CVE-2026-43114: Linux Kernel Netfilter nft_set_pipapo AVX2 Lookup Expiry Bypass",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-43114",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43114"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-43114",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-43114/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--64a5fa13-2d4e-4048-a0f0-02e6cae568d5",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-43133",
      "description": "CVE-2026-43133: Linux Kernel KVM nSVM VMLOAD/VMSAVE Emulation Hypervisor Escape",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-43133",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43133"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-43133",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-43133/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--aa5ce39d-0e73-46ba-a245-9d0e41cca702",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-43386",
      "description": "CVE-2026-43386: Linux Kernel Realtek rtl8723bs Wi-Fi WMM IE Parsing Out-of-Bounds Read",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-43386",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43386"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-43386",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-43386/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 6.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--57df4398-58cf-45a5-aa52-015d7b5ce702",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-4372",
      "description": "CVE-2026-4372: Hugging Face Transformers Configuration Injection RCE via Attention Implementation",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-4372",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4372"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-4372",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-4372/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--cc07133b-c2a3-4225-ac8e-af5909986e1a",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-44963",
      "description": "CVE-2026-44963: Remote Code Execution in Veeam Backup & Replication via .NET Remoting ObjRef Deserialization",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-44963",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44963"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-44963",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-44963/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--5ca174fa-e997-4669-a4ee-b502bce1ce11",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-4519",
      "description": "CVE-2026-4519: CPython webbrowser.open() Leading Dash Argument Injection",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-4519",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4519"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-4519",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-4519/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--20bd1572-f7c9-4415-abb8-f68f7c699353",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-45321",
      "description": "CVE-2026-45321: Large-Scale Supply Chain Compromise Across 42 Packages in the TanStack NPM Ecosystem",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-45321",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45321"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-45321",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-45321/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--131b209c-4345-4faf-a1fe-470af0f10a73",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-46850",
      "description": "CVE-2026-46850: Remote Code Execution via Code Injection in MySQL Shell for VS Code",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-46850",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46850"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-46850",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-46850/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--7fed5c15-bb7c-4a72-a497-a56cf94ec5e6",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-46860",
      "description": "CVE-2026-46860: Unauthenticated Remote Administrative Takeover in MySQL Router",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-46860",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46860"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-46860",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-46860/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--51bf065d-1c06-474b-a883-c13f452884eb",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-46861",
      "description": "CVE-2026-46861: Privilege Escalation and Cluster Takeover in MySQL NDB Operator",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-46861",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46861"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-46861",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-46861/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--c083b9d7-b83b-44b4-afff-462df1160516",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-46862",
      "description": "CVE-2026-46862: Unauthenticated Remote Denial of Service via TLS in MySQL Router",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-46862",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46862"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-46862",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-46862/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--fbc7c9ee-1012-4579-a598-c67184f5914c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-46870",
      "description": "CVE-2026-46870: Access Control Bypass and Workstation Compromise in MySQL Shell for VS Code",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-46870",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46870"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-46870",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-46870/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--5a33e200-4fde-4c22-a87a-594ef4bf03a2",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-47057",
      "description": "CVE-2026-47057: Remote Denial of Service in Oracle Java SE Scripting Engine",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-47057",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47057"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-47057",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-47057/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--1ca3348f-af09-479b-ae00-af64508cf498",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-47058",
      "description": "CVE-2026-47058: Out-of-Bounds Memory Corruption in Java Scripting DataView Implementation",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-47058",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47058"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-47058",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-47058/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--d0bef6fe-de1d-45d0-a029-04e020ee0639",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-47063",
      "description": "CVE-2026-47063: Existential Forgery and JAR Verification Bypass in Oracle Java SE Libraries",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-47063",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47063"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-47063",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-47063/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--767c22f6-f602-4801-a82d-d54136fa83ce",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-47876",
      "description": "CVE-2026-47876: VMware ESXi VMXNET3 Out-of-Bounds Write Virtual Machine Escape",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-47876",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47876"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-47876",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-47876/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--ee5b4582-1324-454b-a3a7-dcfb6213aa70",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-48710",
      "description": "CVE-2026-48710: Starlette & FastAPI BadHost Path Smuggling & Auth Bypass",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-48710",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48710"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-48710",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-48710/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--35d3df09-7ad6-4fea-a666-86169f08d4af",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-48746",
      "description": "CVE-2026-48746: vLLM OpenAI API Authentication Middleware Bypass via ASGI Request Handling Inconsistency",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-48746",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48746"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-48746",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-48746/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--a016a031-9a95-4c4c-a062-524930df739c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-49179",
      "description": "CVE-2026-49179: Windows Active Directory Domain Services Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-49179",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49179"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-49179",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-49179/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--c7660163-8a91-4fda-ac8d-0e0842e7d441",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-49869",
      "description": "CVE-2026-49869: Authentication Bypass to Remote Code Execution in Kestra OSS via Path Suffix Whitelisting",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-49869",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49869"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-49869",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-49869/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--f02eb1ab-cc18-47d9-ae31-22b58ec45306",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-5002",
      "description": "CVE-2026-5002: Critical Prompt Injection in localGPT",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-5002",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5002"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-5002",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-5002/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--9093bbdb-fb7f-4b66-ae33-36be448c47c6",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-5027",
      "description": "CVE-2026-5027: Langflow Multipart Form Files Path Traversal and Arbitrary File Overwrite RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-5027",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5027"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-5027",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-5027/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--aa71a936-4b82-4d67-a1c4-d38f77180f45",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-50346",
      "description": "CVE-2026-50346: Windows Netlogon RPC Runtime Elevation of Privilege",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-50346",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50346"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-50346",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-50346/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--9560d618-e897-40fa-a26d-dc6e6feece03",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-50391",
      "description": "CVE-2026-50391: Windows Group Policy Client Elevation of Privilege",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-50391",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50391"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-50391",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-50391/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--3ea63f47-8590-47ac-a0d4-9b34d4477523",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-50481",
      "description": "CVE-2026-50481: Azure Active Directory Immutable Data Manipulation Privilege Escalation",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-50481",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50481"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-50481",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-50481/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--4de04d86-7bb3-476f-a9d7-54b7b414affe",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-50500",
      "description": "CVE-2026-50500: Windows Netlogon Secure Channel Use-After-Free Elevation of Privilege",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-50500",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50500"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-50500",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-50500/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--65a85d89-3082-4aea-ae26-d296cb9215a3",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-50522",
      "description": "CVE-2026-50522: Remote Code Execution in Microsoft SharePoint Server via .NET Deserialization",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-50522",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50522"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-50522",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-50522/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--ab611b8a-635e-4e72-a8fc-d9a368d90a54",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-5059",
      "description": "CVE-2026-5059: aws-mcp-server RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-5059",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5059"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-5059",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-5059/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--fa8c7f36-aa12-4898-a32c-4dc8cbf0b590",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-52924",
      "description": "CVE-2026-52924: Linux Kernel SCTP Stale COOKIE-ECHO Outqueue Purge Use-After-Free",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-52924",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52924"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-52924",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-52924/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--4741e2e2-907b-4c47-a7f5-e7498fe64b3a",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-52933",
      "description": "CVE-2026-52933: Linux Kernel io_uring/poll Signed Comparison Ownership Privilege Escalation",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-52933",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52933"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-52933",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-52933/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--757b178d-24ee-4575-a3fc-0dc4cde1f854",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-53266",
      "description": "CVE-2026-53266: Linux Kernel Netfilter ebtables SNAT ARP Out-of-Bounds Write & Privilege Escalation",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-53266",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53266"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-53266",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-53266/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--648d356a-3cd9-4989-a775-e33c227a14b6",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-5364",
      "description": "CVE-2026-5364: Arbitrary File Upload in Drag and Drop File Upload for Contact Form 7",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-5364",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5364"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-5364",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-5364/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--e82f4ba9-8313-4aca-a2d0-0272590dc0ee",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-54236",
      "description": "CVE-2026-54236: vLLM Multimodal Image Processing Unhandled Exception Memory Pointer Disclosure",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-54236",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54236"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-54236",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-54236/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--dc710d83-3dc4-4cff-ab4e-5fd8d7ff9934",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-54291",
      "description": "CVE-2026-54291: pgjdbc Silent SCRAM Channel-Binding Authentication Downgrade",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-54291",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54291"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-54291",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-54291/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--c0939d73-b1b6-4cff-ad65-7f162ed7eb2c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-55040",
      "description": "CVE-2026-55040: Authentication Bypass and Privilege Escalation in Microsoft SharePoint Server via JWT Signature Spoofing",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-55040",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55040"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-55040",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-55040/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--a205acb0-ccee-43ba-a6cc-93ec974ccb0e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-55653",
      "description": "CVE-2026-55653: OpenSSH DH-GEX Client Path Double-Free in FIPS Known-Group Validation",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-55653",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55653"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-55653",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-55653/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 6.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--f9329919-ec83-4be3-a69f-2eddef2e30e2",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-57967",
      "description": "CVE-2026-57967: Unauthenticated Remote Session Hijacking via CORE Protocol Reattachment in Apache ActiveMQ Artemis",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-57967",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-57967"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-57967",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-57967/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--e31c8603-5a2a-405c-a17e-67eaf67b0bfa",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-58070",
      "description": "CVE-2026-58070: Cleartext Guest OS Credentials Disclosure in Veeam Backup Support Logs",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-58070",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58070"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-58070",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-58070/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--8101e174-c9df-487b-ac25-422ea82c4269",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-5809",
      "description": "CVE-2026-5809: Arbitrary File Deletion in wpForo Forum",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-5809",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5809"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-5809",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-5809/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--5d5fc89c-3438-4fe3-af2b-75abb1733ff4",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-58480",
      "description": "CVE-2026-58480: Blocksy Companion Pro Unauthenticated Arbitrary File Upload Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-58480",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58480"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-58480",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-58480/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--3a61a300-0942-45cc-a9c8-8924f3eadbed",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-58599",
      "description": "CVE-2026-58599: Microsoft HEVC Video Extensions Heap Buffer Overflow Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-58599",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58599"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-58599",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-58599/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--faa251a5-582b-41fd-af10-e5c7dc619a39",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-58644",
      "description": "CVE-2026-58644: Remote Code Execution in Microsoft SharePoint Server via Workflow Event Receiver Deserialization",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-58644",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58644"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-58644",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-58644/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--4719f120-8a07-4027-a687-d2390de0587a",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-58704",
      "description": "CVE-2026-58704: Zero-Click Adjacent Privilege Escalation in Google Pixel Cellular Modem",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-58704",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58704"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-58704",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-58704/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--e049f41d-bc19-4e13-a0cb-a1171d2e4c23",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-59310",
      "description": "CVE-2026-59310: Remote Code Execution in VMware vCenter Server via Syslog Service Directory Traversal",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-59310",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59310"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-59310",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-59310/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--aecce1dc-8e5d-476d-ad76-b36648b48b95",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-5966",
      "description": "CVE-2026-5966: Arbitrary File Deletion in ThreatSonar Anti-Ransomware",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-5966",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5966"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-5966",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-5966/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--19f7c552-5baf-4100-a100-f0c43d431e30",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-59837",
      "description": "CVE-2026-59837: Stack-Based Buffer Overflow in FortiOS Log Report Generation",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-59837",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59837"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-59837",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-59837/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--0d337ed4-6aec-490e-a0b2-9f922be03de1",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-59839",
      "description": "CVE-2026-59839: FortiOS CLI Path Traversal Arbitrary File Deletion & Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-59839",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59839"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-59839",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-59839/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--b61fb241-822d-49b8-ac08-85b143f03f01",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-59840",
      "description": "CVE-2026-59840: Buffer Over-read in Fortinet FortiOS and FortiProxy",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-59840",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59840"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-59840",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-59840/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 6.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--9da2e108-3938-47ec-a2e4-21d649112535",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-60137",
      "description": "CVE-2026-60137: WordPress Core Facilitated SQL Injection via WP_Query author__not_in",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-60137",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-60137"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-60137",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-60137/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--ea1b028d-6d5b-4ccb-a8d0-28a0983b3f4d",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-60163",
      "description": "CVE-2026-60163: Local Privilege Escalation and Takeover in MySQL Group Replication",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-60163",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-60163"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-60163",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-60163/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--d84c22a0-e262-41fe-a392-c662d8171dad",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-60316",
      "description": "CVE-2026-60316: Server and Cluster Takeover via MySQL X Plugin Protocol",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-60316",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-60316"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-60316",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-60316/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--f694a37e-67b5-46a9-a17f-4f49ce83b5a1",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-60592",
      "description": "CVE-2026-60592: Unauthenticated Network Denial of Service and Data Tampering in NDB Operator",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-60592",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-60592"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-60592",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-60592/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--04674b2a-f91f-40cc-af19-965c3c52b88e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-60623",
      "description": "CVE-2026-60623: Data Tampering and Information Disclosure in MySQL Connector/J",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-60623",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-60623"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-60623",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-60623/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--908a39cf-dd66-4bd6-aa5b-898d3b72d057",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-6100",
      "description": "CVE-2026-6100: CPython Decompressor Use-After-Free under Memory Pressure",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-6100",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6100"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-6100",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-6100/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--4fb1d06e-c039-4616-a67b-5bf58f308af7",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-6105",
      "description": "CVE-2026-6105: Improper Authorization in perfree go-fastdfs-web",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-6105",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6105"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-6105",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-6105/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--305d6c2e-8836-4061-afa8-c8dddb58b760",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-61094",
      "description": "CVE-2026-61094: System Compromise via Binary Log Replication Subsystem in MySQL Server",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-61094",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61094"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-61094",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-61094/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--e5ee0e7d-b848-4ca2-aeea-f13e8e8f8f3d",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-61308",
      "description": "CVE-2026-61308: Information Disclosure Across Boundaries via HTTP Networking in Java SE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-61308",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61308"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-61308",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-61308/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--a2d83a25-beb6-452f-aacf-6d2d3d1bfc23",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-6138",
      "description": "CVE-2026-6138: Critical Remote OS Command Injection in Totolink A7100RU",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-6138",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6138"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-6138",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-6138/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--01399585-5d2b-467f-af5e-46806dbfa6bb",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-62574",
      "description": "CVE-2026-62574: Local Privilege Escalation via Install Component in Oracle Java SE and GraalVM",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-62574",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62574"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-62574",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-62574/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--d4b94806-7cbd-45cb-ad9e-1c44f4c84d6d",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-62752",
      "description": "CVE-2026-62752: Windows Kerberos Security Authority Elevation of Privilege",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-62752",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62752"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-62752",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-62752/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--40b1f984-1c87-410a-a4b9-6a77f5eb9687",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-6276",
      "description": "CVE-2026-6276: curl Stale Custom Host Header Cookie Leak",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-6276",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6276"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-6276",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-6276/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 6.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--42a16071-84ef-41a1-ac91-bb8a579f449f",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-62785",
      "description": "CVE-2026-62785: Windows LDAP Service Remote Code Execution on Domain Controllers",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-62785",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62785"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-62785",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-62785/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--90c422e5-b5c0-446a-af99-af9276d95f8d",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-62818",
      "description": "CVE-2026-62818: Windows Active Directory Certificate Services (AD CS) Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-62818",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62818"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-62818",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-62818/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--909dd50b-a935-4cbe-a3bb-a0598f67f415",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-63030",
      "description": "CVE-2026-63030: WordPress Core REST API Batch Route Confusion to Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-63030",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63030"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-63030",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-63030/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--5a837c68-e38f-49ec-a95a-9cb082e6b3be",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-63077",
      "description": "CVE-2026-63077: Authentication Bypass to Remote Code Execution in JetBrains TeamCity via Agent Polling Protocol",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-63077",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63077"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-63077",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-63077/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--68e80682-4e7e-4985-aa41-ae3a3b8cbaee",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-64268",
      "description": "CVE-2026-64268: Linux Kernel Soft-iWARP (siw) RDMA Read Response Out-of-Bounds Write",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-64268",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64268"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-64268",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-64268/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--34107deb-53f2-4000-a48b-0541c9dee3ea",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-6443",
      "description": "CVE-2026-6443: WordPress Essential Plugin Supply Chain Attack",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-6443",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6443"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-6443",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-6443/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--a678a62f-11d2-4cb1-ac30-929840b8ae45",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-6473",
      "description": "CVE-2026-6473: PostgreSQL Server Memory Allocation Integer Wraparound OOB Write",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-6473",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6473"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-6473",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-6473/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--b0e16d82-6849-445e-ae9e-435bce905139",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-6476",
      "description": "CVE-2026-6476: PostgreSQL pg_createsubscriber Subscription Name SQL Injection",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-6476",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6476"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-6476",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-6476/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--bfb22645-ae8e-451e-aba0-d1ebff3803ba",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-64849",
      "description": "CVE-2026-64849: Critical Server-Side Request Forgery (SSRF) in MLflow Webhook Notifications",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-64849",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64849"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-64849",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-64849/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--558712ed-8fdb-4b10-adfd-8d53fbb33d83",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-6490",
      "description": "CVE-2026-6490: QueryMine SMS SQL Injection",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-6490",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6490"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-6490",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-6490/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--aa5a1b03-a8f9-4f00-a13b-b7f6e51486ce",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-6507",
      "description": "CVE-2026-6507: dnsmasq Out-of-Bounds Write",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-6507",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6507"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-6507",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-6507/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--5380131e-d982-4941-ae0a-9afa0aab5e1e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-65182",
      "description": "CVE-2026-65182: Security Constraint Order Bypass and Authorization Failure in Apache Tomcat",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-65182",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65182"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-65182",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-65182/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--d6457c59-9ba6-4923-a61f-1a56be60d2f1",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-65381",
      "description": "CVE-2026-65381: Apple macOS Entitlement Verification Sandbox Escape & Local Privilege Escalation",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-65381",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65381"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-65381",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-65381/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--acc85d74-8ca1-49e8-ae50-c506f742578d",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-65400",
      "description": "CVE-2026-65400: Unauthenticated Remote Desktop Takeover in Apple macOS Screen Sharing",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-65400",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65400"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-65400",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-65400/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--a1b3346f-f704-4e22-a5ed-4409b2e337cb",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-6560",
      "description": "CVE-2026-6560: H3C Magic B0 Router Buffer Overflow",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-6560",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6560"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-6560",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-6560/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--92211493-7868-4e97-a007-985c35464871",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-65777",
      "description": "CVE-2026-65777: Active Directory Cross-Realm Security Feature Bypass",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-65777",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65777"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-65777",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-65777/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 6.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--10fcf82d-b32d-468e-aade-0e1cd5233eb2",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-65927",
      "description": "CVE-2026-65927: Access Control Bypass via RewriteValve Off-By-One Error in Apache Tomcat",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-65927",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65927"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-65927",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-65927/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--8898bd80-0b7b-4b65-ad3e-1ee02217c6c5",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-6595",
      "description": "CVE-2026-6595: SQL Injection in School Management System",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-6595",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6595"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-6595",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-6595/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--6852b6ba-a199-404f-ab9a-1e3178ad26a2",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-6596",
      "description": "CVE-2026-6596: Arbitrary File Upload in Langflow",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-6596",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6596"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-6596",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-6596/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--be772004-1915-42b8-ab0d-eef241a130aa",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-6602",
      "description": "CVE-2026-6602: Arbitrary File Upload in rickxy Hospital Management System",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-6602",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6602"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-6602",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-6602/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--2c30a17b-aa27-4ff3-aa5b-3bd8ad250724",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-6603",
      "description": "CVE-2026-6603: Remote Code Execution in AgentScope Framework",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-6603",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6603"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-6603",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-6603/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--084ea0bb-5616-40ca-a5d4-5fcd33c2b67c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-6604",
      "description": "CVE-2026-6604: AgentScope Blind SSRF via Prompt Injection",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-6604",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6604"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-6604",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-6604/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--68edd8b7-bc22-4c03-aebc-0d668bf24f6a",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-6605",
      "description": "CVE-2026-6605: AgentScope SSRF Vulnerability",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-6605",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6605"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-6605",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-6605/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--68bc5504-8e41-4665-a42c-fc885af55c45",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-6615",
      "description": "CVE-2026-6615: TransformerOptimus SuperAGI Path Traversal",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-6615",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6615"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-6615",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-6615/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--8cf5c995-6047-4078-ada6-fc726bf97dff",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-6638",
      "description": "CVE-2026-6638: PostgreSQL REFRESH PUBLICATION Table Name SQL Injection",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-6638",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6638"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-6638",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-6638/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--ec57e103-df0c-4eea-a982-23e99a03cdcc",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-67593",
      "description": "CVE-2026-67593: Apache ActiveMQ Artemis Pre-Authentication Queue Deletion via Openwire",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-67593",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67593"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-67593",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-67593/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--c4aa25b1-c63e-427e-af4b-20fca220c2a8",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-68200",
      "description": "CVE-2026-68200: Linux Kernel ALSA Timer User Trigger Concurrent ioctl Use-After-Free",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-68200",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68200"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-68200",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-68200/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--4e09bc4a-77f7-43a3-a3d2-abe0a812441c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-69518",
      "description": "CVE-2026-69518: Windows Remote Desktop Clipboard Virtual Channel Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-69518",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69518"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-69518",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-69518/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--b8417239-4a35-4307-a4c9-6283ef1f0b3e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-69579",
      "description": "CVE-2026-69579: Windows Message Queuing (MSMQ) Unauthenticated Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-69579",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69579"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-69579",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-69579/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--e0ad8abb-50c3-4336-acd0-cad5acf0c692",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-69595",
      "description": "CVE-2026-69595: Windows Services for NFS ONCRPC XDR Driver Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-69595",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69595"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-69595",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-69595/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--4e28a9d1-8c78-4a0e-ae5e-4e439d360313",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-69603",
      "description": "CVE-2026-69603: Windows Hyper-V Guest-to-Host Escape Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-69603",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69603"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-69603",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-69603/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--bfbbed26-ee26-4a28-ad92-a0ce077f5539",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-69649",
      "description": "CVE-2026-69649: Windows Raw Image Extension Thumbnail Preview Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-69649",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69649"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-69649",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-69649/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--6c582adc-9de0-44fe-ad32-0a891f4eaf03",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-69676",
      "description": "CVE-2026-69676: Windows Kerberos Authentication Bypass & Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-69676",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69676"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-69676",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-69676/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--bc3a7260-8b31-48ab-a391-576275462cd0",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-69730",
      "description": "CVE-2026-69730: Windows DNS Server Unauthenticated Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-69730",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69730"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-69730",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-69730/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--0e3646aa-3338-4533-a45e-b324f6a70038",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-69845",
      "description": "CVE-2026-69845: Windows DHCP Server Heap Buffer Overflow Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-69845",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69845"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-69845",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-69845/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--a196169b-8741-4236-aee5-139eb4b5a730",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-69851",
      "description": "CVE-2026-69851: Microsoft Entra ID Server-Side Request Forgery Privilege Escalation",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-69851",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69851"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-69851",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-69851/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--3b986d34-12c5-46c0-a39f-bf3edbe0abe4",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-70477",
      "description": "CVE-2026-70477: Flowise AI CSV Agent Prompt Injection to Unsandboxed Pyodide Host RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-70477",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70477"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-70477",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-70477/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--024f963d-b22b-437e-a9c5-7c017e26514c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-71133",
      "description": "CVE-2026-71133: Unauthenticated Identity Federation Compromise in Oracle Access Manager Authentication Engine",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-71133",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71133"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-71133",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-71133/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--3f314fa5-37f7-4b5c-a01e-a44c8ac07153",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-7141",
      "description": "CVE-2026-7141: vLLM KV Cache Handler RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-7141",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7141"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-7141",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-7141/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--a5ba3f4b-9078-4517-a77e-faacb70e70f2",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-7210",
      "description": "CVE-2026-7210: CPython Expat and ElementTree Insufficient Entropy Hash-Flooding DoS",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-7210",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7210"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-7210",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-7210/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 6.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--3d23a6cb-d162-44bc-a437-54296ec097e7",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-7273",
      "description": "CVE-2026-7273: Zyxel GS1900 Smart Switches CGI Stack Buffer Overflow RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-7273",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7273"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-7273",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-7273/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--0f08c194-311d-4768-a153-3c0733de1441",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-72961",
      "description": "CVE-2026-72961: Windows Hyper-V Guest-to-Host Elevation of Privilege",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-72961",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-72961"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-72961",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-72961/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--c26adea6-2a24-430f-ac24-3ebd98c66148",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-72979",
      "description": "CVE-2026-72979: Windows DHCP Server Use-After-Free Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-72979",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-72979"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-72979",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-72979/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--8616119d-115d-42ae-a540-f44bc4eeb0ee",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-72982",
      "description": "CVE-2026-72982: Windows Netlogon Unauthenticated Remote Code Execution (Domain Controller Takeover)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-72982",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-72982"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-72982",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-72982/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--4fec3217-1f21-441c-a35d-445ae19be5ba",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-73009",
      "description": "CVE-2026-73009: Windows Secure Socket Tunneling Protocol (SSTP) VPN Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-73009",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73009"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-73009",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-73009/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--0af0fbc2-cd69-42da-a73e-7b0104ab7a4b",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-73431",
      "description": "CVE-2026-73431: CIRCL Vulnerability-Lookup Stateless Token Replay Account Takeover",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-73431",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73431"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-73431",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-73431/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--077107bd-1dc1-4df5-aee2-34ad465dc53c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-73498",
      "description": "CVE-2026-73498: mcp-atlassian Confluence Upload Attachment Arbitrary File Exfiltration",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-73498",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73498"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-73498",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-73498/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--f653c2cc-6158-4d4f-a5fe-5e30062e4529",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-74512",
      "description": "CVE-2026-74512: Linux Kernel Audit Subsystem Rule Deletion Premature Free Use-After-Free",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-74512",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-74512"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-74512",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-74512/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--4d0e6282-96fd-401a-a75d-0a660d176e59",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-74521",
      "description": "CVE-2026-74521: Linux Kernel ksmbd Binary ClientGUID strncmp Comparison Flaw",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-74521",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-74521"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-74521",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-74521/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--7fe88ed6-99b2-4e67-adce-264c4301a8b0",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-74957",
      "description": "CVE-2026-74957: Mozilla Firefox Safe Browsing Mitigation Bypass",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-74957",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-74957"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-74957",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-74957/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 6.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--bf7a5863-6980-4fb1-a883-148ee8736d03",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-74963",
      "description": "CVE-2026-74963: Mozilla Firefox Same-Origin Policy Bypass in Cookie Engine",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-74963",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-74963"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-74963",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-74963/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 6.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--3b7cfd8f-3031-45d8-aff4-52036aaea6a4",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-74976",
      "description": "CVE-2026-74976: Mozilla Firefox SpiderMonkey JIT Miscompilation & Type Confusion",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-74976",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-74976"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-74976",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-74976/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--675ba791-877d-4b4e-a366-ca5f26c3a868",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-75650",
      "description": "CVE-2026-75650: Unauthenticated Remote Code Execution via",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-75650",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75650"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-75650",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-75650/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--af9ef3b6-6706-45f6-a590-4e5fe39706cf",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-75874",
      "description": "CVE-2026-75874: Mozilla Firefox Critical Sandbox Escape via Remote Settings Client",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-75874",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75874"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-75874",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-75874/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--64a05178-94c0-48c7-a803-ceab4dace0e1",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-76460",
      "description": "CVE-2026-76460: Unauthenticated REST API Authentication Bypass in Cisco Identity Services Engine (ISE)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-76460",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76460"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-76460",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-76460/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--22c29d6e-5289-4be4-a958-5dd9f5ebbc62",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-76461",
      "description": "CVE-2026-76461: Zero-Click Remote Code Execution via AsyncOS Email Parsing SQL Injection in Cisco Secure Email Gateway",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-76461",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76461"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-76461",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-76461/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--0b136faa-93ac-4158-a9ce-61e375b388f6",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-76674",
      "description": "CVE-2026-76674: HPE Aruba EdgeConnect SD-WAN Buffer Overflow System Takeover",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-76674",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76674"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-76674",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-76674/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--e33df2b5-8ce3-4ae3-acb7-93bcea4902f4",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-77248",
      "description": "CVE-2026-77248: mcp-atlassian Unauthenticated Arbitrary File Read and Attachment Exfiltration",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-77248",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77248"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-77248",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-77248/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--6b294404-412c-4076-ae3c-1b60704b7815",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-77254",
      "description": "CVE-2026-77254: mcp-atlassian Missing Authentication on HTTP Transport Endpoint",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-77254",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77254"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-77254",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-77254/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--0e1fa683-b312-4117-a2b0-4a7dc57ee670",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-77257",
      "description": "CVE-2026-77257: mcp-atlassian Jira Upload Attachment Path Traversal",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-77257",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77257"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-77257",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-77257/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--ad7668da-02b7-42a4-a337-50bcf8b93dad",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-77258",
      "description": "CVE-2026-77258: mcp-atlassian Confluence Attachment Handler Missing Safe Path Validation",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-77258",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77258"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-77258",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-77258/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--b332daf5-9820-4b81-a252-87ab3d44b262",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-77266",
      "description": "CVE-2026-77266: mcp-atlassian Absolute Path Traversal Bypass in Attachment Operations",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-77266",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77266"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-77266",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-77266/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--90de18e8-8b17-4f54-a76f-392e242c4d86",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-77267",
      "description": "CVE-2026-77267: mcp-atlassian Header-Based SSRF in Fetcher Constructor",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-77267",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77267"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-77267",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-77267/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--4951aa2f-f265-4ede-a98a-54e9f8f46ecf",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-77268",
      "description": "CVE-2026-77268: mcp-atlassian World-Readable Permissions on OAuth Fallback Tokens",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-77268",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77268"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-77268",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-77268/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 6.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--24bba00c-b873-44d8-a215-cefbe30649f7",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-77269",
      "description": "CVE-2026-77269: mcp-atlassian Incomplete Fix for Path Traversal in Attachment Uploads",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-77269",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77269"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-77269",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-77269/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--abe462b2-82b0-46b8-aafb-0de4c35a9166",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-77270",
      "description": "CVE-2026-77270: mcp-atlassian Blind Path Trust in File Dispatcher",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-77270",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77270"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-77270",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-77270/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--eda6a8ee-6975-4504-a6bf-4c582833b994",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-77272",
      "description": "CVE-2026-77272: mcp-atlassian Reflected XSS in OAuth Callback Error Response",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-77272",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77272"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-77272",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-77272/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 6.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--6afc7ec7-2a44-418b-a1ce-ddd977f13c48",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-77493",
      "description": "CVE-2026-77493: Windows Graphics Component Preview Pane Zero-Click Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-77493",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77493"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-77493",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-77493/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--9867aa0c-598b-4790-aa69-c98811caf65f",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-77521",
      "description": "CVE-2026-77521: MaxKB Enterprise AI Platform SandboxShellBackend Command Injection and Container Breakout",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-77521",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77521"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-77521",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-77521/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--e99c45bd-49f6-41be-a991-6395d782a837",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-7814",
      "description": "CVE-2026-7814: pgAdmin 4 Stored XSS via Database Object Names in Browser Tree",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-7814",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7814"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-7814",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-7814/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 6.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--a9d250ad-f2a7-4c30-a23e-31a438f23786",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-78234",
      "description": "CVE-2026-78234: Hawtio Operator OpenShift Service CA Signing Key Theft and Cluster Takeover",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-78234",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78234"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-78234",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-78234/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--f0b17852-f482-484a-aab3-8848f3010482",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-78445",
      "description": "CVE-2026-78445: Windows Services for NFS Memory Corruption Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-78445",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78445"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-78445",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-78445/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--ecbdb46f-c41a-4dfc-a445-39dfbe74b604",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-78509",
      "description": "CVE-2026-78509: Windows Shell Preview Pane Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-78509",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78509"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-78509",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-78509/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--744c2f7d-d95c-4920-a7a8-0d7a97f4c6a2",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-78510",
      "description": "CVE-2026-78510: Microsoft Outlook Reading Pane Zero-Click Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-78510",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78510"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-78510",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-78510/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--5ca56e2c-28c4-4e1f-a77e-33619e8b2a35",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-80083",
      "description": "CVE-2026-80083: Windows Hyper-V Virtual Switch Guest-to-Host Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-80083",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80083"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-80083",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-80083/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--c6f178c7-5848-4b6f-a821-079084eb46da",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-80351",
      "description": "CVE-2026-80351: Remote Code Execution via Dynamic Maven Configuration Eval Injection in Apache Camel K",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-80351",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80351"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-80351",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-80351/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--02ce2fc5-8f09-410f-ae58-c3c2f2d66b6d",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-80352",
      "description": "CVE-2026-80352: Kubernetes Operator Privilege Escalation via Master Trait YAML Injection in Apache Camel K",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-80352",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80352"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-80352",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-80352/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--a7560f50-a945-42cc-a7c9-249d0be39c07",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-80354",
      "description": "CVE-2026-80354: Apache Camel K Operator Authorization Bypass via Maven Profiles ValueSources",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-80354",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80354"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-80354",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-80354/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--0f70717c-503f-4759-a3fd-7f561b352dcd",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-81963",
      "description": "CVE-2026-81963: Windows Update Stack Elevation of Privilege (Actively Exploited Zero-Day)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-81963",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81963"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-81963",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-81963/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--b4de5417-a59c-4e4a-a583-0c12149282a4",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-8206",
      "description": "CVE-2026-8206: Kirki Customizer Framework Unauthenticated Privilege Escalation to Account Takeover",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-8206",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8206"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-8206",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-8206/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--0260d055-d7c9-4f39-a47c-0466e5980aec",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-82329",
      "description": "CVE-2026-82329: JFrog Artifactory Phantom Join-Key Authentication Bypass",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-82329",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82329"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-82329",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-82329/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--2bf67a56-8683-4d11-a493-3ef43c0c51d5",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-82331",
      "description": "CVE-2026-82331: Apache BuildStream Tar Plugin Link Resolution and Host File Overwrite",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-82331",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82331"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-82331",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-82331/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--5fad1760-149a-4ff3-abb9-7530068b0873",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-82474",
      "description": "CVE-2026-82474: Sudo Intercept Policy Bypass via execveat",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-82474",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82474"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-82474",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-82474/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--e1dacf2d-bf4a-4ae4-a2d3-339aee9f0eaf",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-8293",
      "description": "CVE-2026-8293: Really Simple Security Authentication Bypass via 2FA Challenge Skip",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-8293",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8293"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-8293",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-8293/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--c36e6af1-2c49-4e23-a2d2-1246320d226c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-83020",
      "description": "CVE-2026-83020: Unauthenticated Remote Code Execution in Oracle Platform Security for Java (OPSS)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-83020",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83020"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-83020",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-83020/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--141467be-82e5-4564-a53c-405a8c6b4d09",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-83021",
      "description": "CVE-2026-83021: Unauthenticated Remote Code Execution in Oracle WebLogic Server Web Container",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-83021",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83021"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-83021",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-83021/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--35e74ba7-339f-4f03-ad3b-9b3898dbc7b7",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-83059",
      "description": "CVE-2026-83059: Unauthenticated Remote Compromise in Oracle Internet Directory (OID) LDAP Server",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-83059",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83059"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-83059",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-83059/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--7c02a693-9316-4438-a4a2-629a63b7c3ad",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-83099",
      "description": "CVE-2026-83099: Unauthenticated Remote Code Execution in Oracle Forms Services",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-83099",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83099"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-83099",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-83099/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--65563cd0-30f3-427a-a4bb-b5ecd7bb7bf2",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-83527",
      "description": "CVE-2026-83527: Unauthenticated Administrative Authentication Bypass in Ivanti Sentry via Alternate Routing Path",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-83527",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83527"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-83527",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-83527/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--90e67ebe-00fb-4e3a-adae-4c67bc025aba",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-83548",
      "description": "CVE-2026-83548: SonicWall SMA1000 Remote Unauthenticated SSRF & Edge Gateway Takeover",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-83548",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83548"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-83548",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-83548/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--1fdc198d-aeb8-40fe-a76a-0095c625f9c7",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-83549",
      "description": "CVE-2026-83549: SonicWall SMA 1000 Series AMC OS Command Injection & Chain Exploitation",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-83549",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83549"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-83549",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-83549/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--3ae51b53-3220-4330-ad40-7009b26c0a0a",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-84285",
      "description": "CVE-2026-84285: Tuleap Enterprise ALM Workspace Export OS Command Injection",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-84285",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84285"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-84285",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-84285/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--ee35cc2c-93c9-4c50-a198-d5aa7a5a95d3",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-8452",
      "description": "CVE-2026-8452: Unauthenticated Heap Buffer Overflow to Root RCE in NetScaler ADC & Gateway via SAML Canonicalization",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-8452",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8452"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-8452",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-8452/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--541b3992-acf1-46e0-a6aa-d75fcefbf31c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-84779",
      "description": "CVE-2026-84779: WordPress Agentimus MCP Endpoint Broken Access Control",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-84779",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84779"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-84779",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-84779/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--4fe6bbbf-a1ed-4444-a4aa-6ddc29b69b81",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-84869",
      "description": "CVE-2026-84869: Unrestricted File Transfer and Remote Execution in ConnectWise ScreenConnect Client via Active Session Authorization Bypass",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-84869",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84869"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-84869",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-84869/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--ecf701c2-b8ce-4610-a3a7-fd40f79df003",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-84939",
      "description": "CVE-2026-84939: Path Traversal to Remote Template Injection and Code Execution via Malformed Locale in Apache FreeMarker",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-84939",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84939"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-84939",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-84939/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--8e4a8d9a-110c-4df1-a709-3b6ef1fa4aa2",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-85046",
      "description": "CVE-2026-85046: Google Chromium V8 Maglev/TurboFan Type Confusion Zero-Day",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-85046",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85046"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-85046",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-85046/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--c090e06e-1f90-46c0-aac3-03747c6a82a9",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-85165",
      "description": "CVE-2026-85165: n8n Expression Sandbox Escape via Prototype Resolution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-85165",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85165"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-85165",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-85165/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--53756ccc-1cdd-44cb-a243-fd08b3588aa7",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-85166",
      "description": "CVE-2026-85166: n8n Workflow Tool Sub-Workflow Credential Authorization Bypass",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-85166",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85166"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-85166",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-85166/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--84dbf845-c1a4-41ad-a247-c2b1c09ac456",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-85168",
      "description": "CVE-2026-85168: Git Node Merge-Driver & Content-Filter Command Injection in n8n",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-85168",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85168"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-85168",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-85168/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--625b0634-42f6-4630-a7df-3892789e9b96",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-85654",
      "description": "CVE-2026-85654: awslabs dynamodb-mcp-server CDK Generator Template Injection RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-85654",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85654"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-85654",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-85654/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--9d1b6e59-6ebb-4eb1-a96b-64f3bf3bf1ba",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-85706",
      "description": "CVE-2026-85706: Unauthenticated Path Traversal to Arbitrary File Read in GitLab CE/EE Repository Commits API",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-85706",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85706"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-85706",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-85706/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--3d8bd56c-7a4b-419e-a412-4d52eff800f3",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-85788",
      "description": "CVE-2026-85788: awslabs mysql-mcp-server Comment-Bypass Mutation Vulnerability",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-85788",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85788"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-85788",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-85788/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--ff34a888-56fa-4819-a09f-95b9fc250ee4",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-85880",
      "description": "CVE-2026-85880: Windows ALPC Heap Buffer Overflow Privilege Escalation (Actively Exploited Zero-Day)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-85880",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85880"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-85880",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-85880/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--1a4e5289-9690-47a6-a4b3-97d363ef700b",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-86218",
      "description": "CVE-2026-86218: Pre-Authentication Remote Code Execution via Static Code Injection in N-able N-central",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-86218",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86218"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-86218",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-86218/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--bc5498f5-2afa-48ee-a50d-586202f4c0cd",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-86296",
      "description": "CVE-2026-86296: D-Link DIR-822A udhcpcd Stack-Based Buffer Overflow RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-86296",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86296"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-86296",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-86296/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--c1ce26e8-fd2a-4e99-abb1-56daf2ec3a99",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-86297",
      "description": "CVE-2026-86297: D-Link DIR-605 L2TP Parser Off-by-One Buffer Overflow",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-86297",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86297"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-86297",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-86297/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--49038786-7b79-4b48-a12a-5b3ea01fc01e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-8643",
      "description": "CVE-2026-8643: pip console_scripts Out-of-Directory Arbitrary File Overwrite",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-8643",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8643"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-8643",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-8643/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--5474f3b9-f9ab-4eef-ad45-196cc7f63193",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-86510",
      "description": "CVE-2026-86510: D-Link DIR-822A L2TP Parser Out-of-Bounds Write RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-86510",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86510"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-86510",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-86510/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--485b4830-864c-4aa0-af44-0282e8b78b83",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-86711",
      "description": "CVE-2026-86711: Electerm Desktop runGlobalAsync Electron IPC Handler Arbitrary Command Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-86711",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86711"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-86711",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-86711/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--106ce101-858d-4d64-adf4-6c7c7a1d83e0",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-8719",
      "description": "CVE-2026-8719: Privilege Escalation in AI Engine",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-8719",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8719"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-8719",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-8719/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--815c8bac-e5c4-42fc-a933-810e16a410d5",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-87230",
      "description": "CVE-2026-87230: Unauthenticated Remote Financial Ledger Compromise in Oracle Hyperion Financial Management",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-87230",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87230"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-87230",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-87230/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--3cf0b1ec-69af-4bd6-a147-2e49cfced067",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-87886",
      "description": "CVE-2026-87886: Local Privilege Escalation via Insecure Permissions in Acronis Backup Plugin for cPanel & Plesk",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-87886",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87886"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-87886",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-87886/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--7e310adc-d229-4811-a785-1c5ff4ba8914",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-87911",
      "description": "CVE-2026-87911: awslabs postgres-mcp-server SQL Parser Desync to Command Injection",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-87911",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87911"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-87911",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-87911/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--ad1265ce-e2c9-4f94-a140-36986451da7b",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-87983",
      "description": "CVE-2026-87983: Mistral Vibe Arbitrary File Read via Quoted Absolute Paths in Auto-Approved Commands",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-87983",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87983"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-87983",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-87983/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--841a893a-8b6a-4f70-a96c-39efdb5e436b",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-87984",
      "description": "CVE-2026-87984: Mistral Vibe Arbitrary File Write via Shell Redirection Target Omission",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-87984",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87984"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-87984",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-87984/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--11ff7c81-b174-4d39-a799-481cc2d3cbfd",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-87985",
      "description": "CVE-2026-87985: Mistral Vibe Arbitrary Remote Code Execution via ANSI-C Quoting in find -exec",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-87985",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87985"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-87985",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-87985/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--f1517580-f022-469c-a95e-ff50a0a1609c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-87986",
      "description": "CVE-2026-87986: Mistral Vibe Command Injection via Parser Syntax Error Node Bypass",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-87986",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87986"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-87986",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-87986/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--9642af3a-4e09-4747-a555-4149c626605f",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-87987",
      "description": "CVE-2026-87987: Mistral Vibe Remote Code Execution via Environment Variable Assignment Stripping",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-87987",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87987"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-87987",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-87987/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--39871ca1-d251-427a-a959-662f4ca6c4a8",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-87988",
      "description": "CVE-2026-87988: Mistral Vibe Arbitrary Read/Write via Discrepancy Between Auto-Approved Commands and Path Control List",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-87988",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87988"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-87988",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-87988/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--69942afa-f235-48b9-ab3f-9832c8b18f79",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-87999",
      "description": "CVE-2026-87999: Open WebUI Azure WireServer Metadata Filter Bypass SSRF",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-87999",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87999"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-87999",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-87999/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--675e570b-6bd3-417c-a16f-c1d2619b420e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-8932",
      "description": "CVE-2026-8932: curl Incomplete mTLS Configuration Matching in Connection Reuse",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-8932",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8932"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-8932",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-8932/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--fea319d9-44aa-4d8c-a75c-5e83396000c1",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-9048",
      "description": "CVE-2026-9048: Slider Revolution Sensitive Information Exposure via slider.get.full",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-9048",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9048"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-9048",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-9048/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 6.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--585bbe5c-db50-446b-af9c-8cd8c7af7426",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-9050",
      "description": "CVE-2026-9050: Slider Revolution Missing Authorization to Arbitrary Plugin Deactivation",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-9050",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9050"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-9050",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-9050/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 6.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--46533786-2a76-4a5a-ab7e-31d6c89da1d0",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-90562",
      "description": "CVE-2026-90562: Authentication Bypass and Administrative Takeover via Low Entropy Password Recovery in LangBot",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-90562",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90562"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-90562",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-90562/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--d9cca38a-b3d6-4142-a39a-85661489656e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-90680",
      "description": "CVE-2026-90680: D-Link DIR-823G HNAP1 SetStaticRouteSettings Buffer Overflow",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-90680",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90680"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-90680",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-90680/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--daa49e61-46e8-4409-a2fa-d6b692ec1d28",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-90692",
      "description": "CVE-2026-90692: D-Link DIR-878 SetDynamicDNSIPv6Settings Stack Overflow RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-90692",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90692"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-90692",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-90692/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--76501d71-d6f4-4fac-aa04-dd453fb24208",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-90693",
      "description": "CVE-2026-90693: D-Link DIR-878 SetWan3Settings Stack-Based Buffer Overflow RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-90693",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90693"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-90693",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-90693/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--15564a85-8f56-4d4e-ae1b-70baac459303",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-90699",
      "description": "CVE-2026-90699: D-Link DWR-M920 formPinManageSetup OS Command Injection",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-90699",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90699"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-90699",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-90699/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--2ec5e45a-e38e-475c-a8f5-74e05d86c217",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-90702",
      "description": "CVE-2026-90702: D-Link DWR-M921 formDiskFormat OS Command Injection",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-90702",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90702"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-90702",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-90702/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--39398cec-07b9-4d84-a7ca-8ef8d2857d26",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-90711",
      "description": "CVE-2026-90711: Client IP Address Spoofing and Trust Boundary Bypass via IPv4-Mapped IPv6 CIDR Parsing Flaw in proxy-addr",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-90711",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90711"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-90711",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-90711/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--79fe0cfe-86d6-4ba6-a06e-9e820d029b28",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-90770",
      "description": "CVE-2026-90770: Spug Deployment Platform ping_check OS Command Injection RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-90770",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90770"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-90770",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-90770/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--198187b4-ca29-4171-a843-047799cac47d",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-90777",
      "description": "CVE-2026-90777: Arbitrary Code Execution via Insecure torch.load Checkpoint Deserialization in ESPnet",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-90777",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90777"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-90777",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-90777/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--1780689e-2d87-4dc4-a994-053e89551205",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-90894",
      "description": "CVE-2026-90894: Parallels Desktop ParaShells Virtual Machine Host Escape & LPE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-90894",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90894"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-90894",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-90894/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--8f2296d7-ff6f-4ad6-a1d0-1c7ae3a4eace",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-91749",
      "description": "CVE-2026-91749: Google Chrome Web Workers Subsystem Use-After-Free Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-91749",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-91749"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-91749",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-91749/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--2744f301-6978-45d9-a2cc-35edd0ce6e01",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-91843",
      "description": "CVE-2026-91843: Check Point Security Management Server Stack Buffer Overflow RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-91843",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-91843"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-91843",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-91843/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--7450b3b7-bf58-4531-a18a-c5182f91a64f",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-9186",
      "description": "CVE-2026-9186: Langflow Localhost Restriction Bypass Arbitrary IDE mcp.json Overwrite",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-9186",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9186"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-9186",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-9186/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--e30973a3-dcae-43aa-a192-476d55f0dfd4",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-92574",
      "description": "CVE-2026-92574: CRI-O Container Checkpoint-Restore Destination Security Context Bypass",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-92574",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92574"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-92574",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-92574/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--c32a93f7-9d87-446c-a8cc-325cafc1b208",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-93372",
      "description": "CVE-2026-93372: Google Chrome Android WebGL Heap Buffer Overflow GPU Sandbox Escape",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-93372",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93372"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-93372",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-93372/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--54218b10-67dc-4bfa-aa61-9f5f8cee1b0d",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-93616",
      "description": "CVE-2026-93616: Check Point Multi-Domain Security Management Web Service Traversal and RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-93616",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93616"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-93616",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-93616/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--856b45ee-2589-457c-ab13-44e5a77fbb82",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-93952",
      "description": "CVE-2026-93952: Arista VeloCloud Orchestrator Authentication Bypass and Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-93952",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93952"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-93952",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-93952/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--eb686a2b-ecda-4c08-ae78-2ce884604511",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-94089",
      "description": "CVE-2026-94089: D-Link DIR-868L webfa_authentication.cgi Stack Buffer Overflow RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-94089",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94089"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-94089",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-94089/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--555ef47e-85de-4c29-acd0-998624a32001",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-94127",
      "description": "CVE-2026-94127: F5 BIG-IP APM TMM Heap-Based Buffer Overflow Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-94127",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94127"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-94127",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-94127/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--ce0d5f9e-7ed0-48af-ae69-b2cfee709935",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-95675",
      "description": "CVE-2026-95675: D-Link DAP-1360 Web Management OS Command Injection Root RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-95675",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-95675"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-95675",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-95675/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 82,
        "x_hermes_cvss": 8.5
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--cbaedc7d-7998-442a-a953-3592067cbf17",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-9586",
      "description": "CVE-2026-9586: Unauthenticated SQL Injection to Remote Code Execution in Sangoma Switchvox PBX",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-9586",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9586"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-9586",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-9586/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "tool",
      "spec_version": "2.1",
      "id": "tool--b531f159-4038-4822-abb5-5089f5985e3e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "AgentThreat Studio",
      "description": "Artifact AgentThreat Studio (tool)."
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--b615166c-21fe-427f-a55b-3b1d3599e0a3",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "malware--5435f428-5561-469a-ad64-adcc90b94a1a",
      "target_ref": "vulnerability--f46b6461-ba19-43dc-ab89-6fba60261cb3",
      "description": "Public PoC exploits the blank Bearer authentication validation flaw.",
      "confidence": 96
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--258abaad-2788-4235-af25-c5a68a260175",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "threat-actor--0735d81e-7aea-4ae7-aeb5-5170b8bb3c14",
      "target_ref": "malware--5435f428-5561-469a-ad64-adcc90b94a1a",
      "description": "Telemetry shows automated exploitation payloads identical to the public PoC origin.",
      "confidence": 88
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--e4d03c18-a9bd-48b8-a7e5-f85c70119cc8",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "threat-actor--0735d81e-7aea-4ae7-aeb5-5170b8bb3c14",
      "target_ref": "campaign--5d6f120c-396d-434f-ab5d-9b3ba4d4c9bf",
      "description": "Attributed scanning behavior aligns with Operation MCP Harvester reconnaissance activity.",
      "confidence": 85
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--ea0f8a1f-7626-48c8-a930-4a37056bf426",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--f46b6461-ba19-43dc-ab89-6fba60261cb3",
      "target_ref": "attack-pattern--6cdfab74-1358-48e3-ab2b-4b5ba7a83b5a",
      "description": "Hijacking MCP endpoints enables attackers to supply crafted tool execution parameters.",
      "confidence": 94
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--bb7d86a5-ba21-4e5c-ac90-17e2c7124ed5",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--786100ba-9782-44a9-a7b5-5bf32df97b8c",
      "target_ref": "attack-pattern--4944e7db-5acd-4563-ab0c-1f343db7e8b3",
      "description": "Deep research loop processes external web markdown that contains indirect injection instructions.",
      "confidence": 95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--56315274-ffc6-4bf6-ae46-8b43cf98fc72",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--5672d9fa-d29b-4722-a93a-c6cb5a6dbb45",
      "target_ref": "attack-pattern--38abbfb6-2f9c-4890-aa64-a0363710a6c4",
      "description": "Injecting export BASH_ENV into the shell environment establishes persistent execution across agent steps.",
      "confidence": 94
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--fd92277d-699b-42fd-a345-5ce2cbcd4a06",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--1980c9c2-5db0-417e-a06c-8d688a0f41cf",
      "target_ref": "attack-pattern--4944e7db-5acd-4563-ab0c-1f343db7e8b3",
      "description": "Workspace prompt templates override assistant system prompts via untrusted repository files.",
      "confidence": 96
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--0c63bef0-db0d-40e3-afc2-e8feeec40be6",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--5672d9fa-d29b-4722-a93a-c6cb5a6dbb45",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Abuses bash built-in commands (export, typeset) to manipulate shell startup scripts.",
      "confidence": 98
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--80f14c45-0f33-426b-a21c-3a7071233534",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--5672d9fa-d29b-4722-a93a-c6cb5a6dbb45",
      "target_ref": "attack-pattern--a0e23acd-1abd-4ec0-a833-56bdbfe9870e",
      "description": "BASH_ENV environment variable directly hijacks the execution flow of benign commands.",
      "confidence": 95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--2b3a2fd0-3e36-4d69-a11f-aed9e2a88004",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--1980c9c2-5db0-417e-a06c-8d688a0f41cf",
      "target_ref": "attack-pattern--50ef62e1-8260-48ce-a4d6-ce361f2a267e",
      "description": "Entices developers to clone and open untrusted repositories containing malicious prompt templates.",
      "confidence": 93
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--08ea3bba-8731-4a8c-adb6-1d13dc7edb65",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--f46b6461-ba19-43dc-ab89-6fba60261cb3",
      "target_ref": "attack-pattern--ae03499f-1cb4-40c4-a7eb-f30e7cda44b9",
      "description": "Unauthenticated MCP access allows scraping upstream model API keys and internal environment variables.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--a754afb0-53d0-4531-a039-7fbd52da1ca1",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "malware--a5a67799-b785-4354-a650-3ead0d40b4b7",
      "target_ref": "vulnerability--f46b6461-ba19-43dc-ab89-6fba60261cb3",
      "description": "ShadowAgent modular payload includes an automated LiteLLM MCP session hijacker.",
      "confidence": 87
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--0d8d38cc-82a4-4c6a-a8a6-2973f1f3a817",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "related-to",
      "source_ref": "vulnerability--f46b6461-ba19-43dc-ab89-6fba60261cb3",
      "target_ref": "attack-pattern--5e89795f-ce4c-401a-a79b-c277e480c825",
      "description": "Unauthenticated MCP access allows registering rogue tool definitions with weaponized descriptions.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--d1a3fca9-6f70-4043-aefb-3b066cbaefbf",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "related-to",
      "source_ref": "vulnerability--786100ba-9782-44a9-a7b5-5bf32df97b8c",
      "target_ref": "attack-pattern--27ca782d-3e4f-49a1-a49c-d7e389612bab",
      "description": "Autonomous web crawling ingests untrusted text chunks directly into the agent's RAG index.",
      "confidence": 91
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--c8f1b93a-8f14-4648-a3e7-3d03ee87b627",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "related-to",
      "source_ref": "vulnerability--f46b6461-ba19-43dc-ab89-6fba60261cb3",
      "target_ref": "attack-pattern--5e943b66-06a2-4ef3-a0c7-7565fecf6008",
      "description": "Compromising the MCP streaming proxy allows injecting spoofed responses into peer agent message flows.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--45b7d344-0c3e-477a-ab35-bad83c3de5ea",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "related-to",
      "source_ref": "vulnerability--5672d9fa-d29b-4722-a93a-c6cb5a6dbb45",
      "target_ref": "attack-pattern--6616b465-098e-4088-a13b-882430fa99a1",
      "description": "Auto-run shell command chaining results in autonomous cascading breakout from the IDE agent.",
      "confidence": 95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--f83b6518-98d2-4fc6-a2e1-cb4623833a65",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "related-to",
      "source_ref": "vulnerability--786100ba-9782-44a9-a7b5-5bf32df97b8c",
      "target_ref": "attack-pattern--6616b465-098e-4088-a13b-882430fa99a1",
      "description": "Chaining context ingestion with OS tool capabilities leads to full host execution takeover.",
      "confidence": 94
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--05bf4014-e586-4980-ad43-14ae3616dcf1",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--06a219eb-062d-4535-a8f4-cf9d542d548d",
      "target_ref": "attack-pattern--4944e7db-5acd-4563-ab0c-1f343db7e8b3",
      "description": "Untrusted prompt template strings allow injecting format specifiers that subvert system prompt boundaries and access internal object properties.",
      "confidence": 91
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--1c12770a-fe2a-48ea-a86a-d00328192fd9",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "related-to",
      "source_ref": "vulnerability--63ae33e6-2c76-4510-a412-0e1c57c53aaa",
      "target_ref": "attack-pattern--6616b465-098e-4088-a13b-882430fa99a1",
      "description": "Hardcoded allow_dangerous_code exposes Python REPL tool causing autonomous cascading command execution.",
      "confidence": 98
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--75d18612-93e5-4941-a380-68a3236ace7e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--ee340eae-e3fc-4276-a245-71a23fcaacea",
      "target_ref": "attack-pattern--6cdfab74-1358-48e3-ab2b-4b5ba7a83b5a",
      "description": "Abuses validation sink and dynamic class instantiation parameters to achieve server RCE.",
      "confidence": 94
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--216f79eb-488b-4fb9-a012-c5e0c6d1b05a",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--ec8e48c0-df98-4212-a152-4116a335c51d",
      "target_ref": "attack-pattern--6cdfab74-1358-48e3-ab2b-4b5ba7a83b5a",
      "description": "Exploits shell parameter concatenation in MCP tool arguments to trigger host OS commands.",
      "confidence": 97
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--d22698c4-0865-4e1c-a1d2-4ca298059c47",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--444ed63a-0091-4e7c-a279-9ce08cc0c979",
      "target_ref": "attack-pattern--38abbfb6-2f9c-4890-aa64-a0363710a6c4",
      "description": "Leverages zero-click indirect prompt injection during autonomous document ingestion.",
      "confidence": 98
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--3472162f-b4d5-415f-a9d3-b4ab489b4908",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "related-to",
      "source_ref": "vulnerability--14fa3f8e-6392-49ed-a45a-820196030101",
      "target_ref": "attack-pattern--6616b465-098e-4088-a13b-882430fa99a1",
      "description": "Modifying workspace auto-approve settings allows the agent to execute unconstrained host shell commands.",
      "confidence": 96
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--1765be11-2bf0-4333-aa58-546337fad1a8",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--64b3574d-08fb-4c31-aafa-d2ef3eace3c6",
      "target_ref": "attack-pattern--6cdfab74-1358-48e3-ab2b-4b5ba7a83b5a",
      "description": "Manipulates tool parameter URI scheme to traverse outside workspace boundaries.",
      "confidence": 96
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--7e54e8f9-b6e0-4e5b-a5d7-e14842711259",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--b2fac28c-3fe6-4be1-a32a-194547bef238",
      "target_ref": "attack-pattern--4944e7db-5acd-4563-ab0c-1f343db7e8b3",
      "description": "Type validation confusion enables bypassing prompt restrictions to read cross-tenant context.",
      "confidence": 94
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--3c6b21c1-a46a-4198-af22-49a2a13b8115",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "related-to",
      "source_ref": "vulnerability--a2309998-5b8b-4e6a-a945-6c44d2dd8f4a",
      "target_ref": "attack-pattern--6616b465-098e-4088-a13b-882430fa99a1",
      "description": "Client-side script execution in desktop/Electron context escalates to host command execution.",
      "confidence": 95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--00ffd62a-674f-4a18-a959-1abe8e823aed",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--b80c47c1-e447-48ff-ab81-76bd4db3ecad",
      "target_ref": "attack-pattern--38abbfb6-2f9c-4890-aa64-a0363710a6c4",
      "description": "Agent prompt injection causes JSON $schema injection leading to out-of-band HTTP exfiltration.",
      "confidence": 95
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--433d5256-6f3a-4fc4-a3e0-54627491b3e8",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--d4311a47-ee4b-4fa3-a0f7-6e85a3552d20",
      "target_ref": "attack-pattern--4944e7db-5acd-4563-ab0c-1f343db7e8b3",
      "description": "Direct conversational prompt injection overrides service guardrails to leak system prompt.",
      "confidence": 96
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--6e37703d-f3f1-41f1-af31-39a00e527c43",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--e5b2fd2d-cbc8-4107-a8bb-2b40aa395b02",
      "target_ref": "campaign--1a00eefb-941c-42a1-acde-282fc0614b25",
      "description": "Actively exploited in the wild as the second stage of the MikroTrick campaign.",
      "confidence": 98
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--47d0b92e-bd72-4afd-a68a-3949809351a4",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "campaign--0093007f-46d9-4597-a078-ec8730fde3aa",
      "target_ref": "vulnerability--cbff4325-5967-440c-aae9-ac3105e7f52c",
      "description": "GreyNoise telemetry confirmed automated AI agents exploited CVE-2026-81578 for initial access.",
      "confidence": 99
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--8b7740d2-3348-4eba-aba3-061f5aa61467",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "campaign--0093007f-46d9-4597-a078-ec8730fde3aa",
      "target_ref": "vulnerability--492c931c-2590-49ff-a000-81ba89e15999",
      "description": "GreyNoise telemetry confirmed automated AI agents chained CVE-2026-82078 to achieve RCE.",
      "confidence": 99
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--77251879-e28e-48f5-ab28-f4ed5ba4798d",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--146bbdcf-27a4-4483-a59f-cd75d03f6df4",
      "target_ref": "attack-pattern--ae03499f-1cb4-40c4-a7eb-f30e7cda44b9",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--433d5256-6f3a-4fc4-a3e0-54627491b3e8",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--d4311a47-ee4b-4fa3-a0f7-6e85a3552d20",
      "target_ref": "attack-pattern--4944e7db-5acd-4563-ab0c-1f343db7e8b3",
      "description": "CVE-2024-5184 weaponizes the agentic attack pattern formalized under AAP-001.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--36fbeca0-5525-448d-a7bc-294c7f6b641a",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--d4311a47-ee4b-4fa3-a0f7-6e85a3552d20",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--858c02e9-9422-4137-ab82-8381668eda05",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--8018a302-e6f4-4965-adec-be0e5184c2d0",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--0b677cee-ad03-4ccb-a5a3-dfd70ed51792",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--38885850-1f67-4e96-af9a-e1385567712d",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--e0c7def4-f9e2-480c-a494-d681ec74a99d",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--decb767e-7288-4c43-a526-adf7d6e339b1",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--59727c3f-78b0-4d10-a0bd-bd31583d78cc",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--4b1b7578-644c-4cee-a209-befc0c385a80",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--f6b30e7d-59f3-4c63-a5a0-6eceb585fdba",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--4b1b7578-644c-4cee-a209-befc0c385a80",
      "target_ref": "attack-pattern--50ef62e1-8260-48ce-a4d6-ce361f2a267e",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1566.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--d618caba-adf6-4afa-afdc-d48fbbb436cf",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--27efb9d5-3d19-460c-a533-b2335851977e",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--185c7dfb-2b71-496d-ace8-ac7db52d8d7f",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--5c65350f-e2bd-4175-aaa7-94da05bd5958",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--0fe716ca-3b4d-4168-a342-c46e8734500c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--c5bb16ce-9ebd-4dac-a43a-15215088ad9e",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--1d9c6b56-f8fd-41fe-a524-7fa9a2ec66b7",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--25db4afa-1f31-4cdf-a288-1cce7424b838",
      "target_ref": "attack-pattern--27ca782d-3e4f-49a1-a49c-d7e389612bab",
      "description": "CVE-2025-26319 weaponizes the agentic attack pattern formalized under AAP-005.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--bcc0f293-490e-45f2-a45e-6d4270208649",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--ad4dfe94-23f9-4555-aef3-f621eb6992e8",
      "target_ref": "attack-pattern--ae03499f-1cb4-40c4-a7eb-f30e7cda44b9",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--4704c59a-f6c3-4952-adba-a901e20caede",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--08af832f-4a18-4580-ae36-ea471a96329b",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--48afcb1f-b5b9-40a2-a4ca-de127c0746f6",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--3070e534-621f-44b3-a2ff-fcd376eb64c5",
      "target_ref": "attack-pattern--6616b465-098e-4088-a13b-882430fa99a1",
      "description": "CVE-2025-3248 weaponizes the agentic attack pattern formalized under AAP-007.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--6cd495b8-6c1b-4500-a5ee-6b2b8269be3e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--3070e534-621f-44b3-a2ff-fcd376eb64c5",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--1df5a81b-e392-4a75-a947-af9e0b5cd482",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--69554729-a5eb-4e2c-a997-5ac234199a85",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--c7d092aa-3132-4e83-aaec-229f8dfc4961",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--55320dae-25ab-43da-ac83-3353b2c0c1c1",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--7b6a80f4-89ff-4029-a03c-4ed38e2d762b",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--b80c47c1-e447-48ff-ab81-76bd4db3ecad",
      "target_ref": "attack-pattern--6cdfab74-1358-48e3-ab2b-4b5ba7a83b5a",
      "description": "CVE-2025-49150 weaponizes the agentic attack pattern formalized under AAP-003.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--c4ba7d78-7901-4639-acc7-153bd2131edc",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--48343358-7151-4044-abe6-d3f9db13aee9",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--216f79eb-488b-4fb9-a012-c5e0c6d1b05a",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--ec8e48c0-df98-4212-a152-4116a335c51d",
      "target_ref": "attack-pattern--6cdfab74-1358-48e3-ab2b-4b5ba7a83b5a",
      "description": "CVE-2025-52573 weaponizes the agentic attack pattern formalized under AAP-003.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--2efadcd3-5c64-4411-a378-e11e45ae6bdc",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--ec8e48c0-df98-4212-a152-4116a335c51d",
      "target_ref": "attack-pattern--5e89795f-ce4c-401a-a79b-c277e480c825",
      "description": "CVE-2025-52573 weaponizes the agentic attack pattern formalized under AAP-004.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--059d0a55-cf90-417b-a799-90f8ca7eeff3",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--5bd4ee66-5624-4a00-a8ee-39d3d00a70ac",
      "target_ref": "attack-pattern--6cdfab74-1358-48e3-ab2b-4b5ba7a83b5a",
      "description": "CVE-2025-5277 weaponizes the agentic attack pattern formalized under AAP-003.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--53879316-15a3-4f04-a2b3-57b21a72955f",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--5bd4ee66-5624-4a00-a8ee-39d3d00a70ac",
      "target_ref": "attack-pattern--4944e7db-5acd-4563-ab0c-1f343db7e8b3",
      "description": "CVE-2025-5277 weaponizes the agentic attack pattern formalized under AAP-001.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--fd5ba828-836b-4f83-a478-a184635e7144",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--5bd4ee66-5624-4a00-a8ee-39d3d00a70ac",
      "target_ref": "attack-pattern--6616b465-098e-4088-a13b-882430fa99a1",
      "description": "CVE-2025-5277 weaponizes the agentic attack pattern formalized under AAP-007.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--b8acb0ae-5765-4f48-afb1-0341da271e34",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--5bd4ee66-5624-4a00-a8ee-39d3d00a70ac",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--05770257-2324-4d42-a2c7-0dce0bdc498c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--5bd4ee66-5624-4a00-a8ee-39d3d00a70ac",
      "target_ref": "attack-pattern--ae03499f-1cb4-40c4-a7eb-f30e7cda44b9",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--e5fc0131-dfcd-4fae-a6a4-7cb38b665723",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--46875624-eb09-49f0-aa7b-62f322008a32",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--50ec9d5a-5108-4971-a9d3-7a6497161858",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--432daf2d-2c0a-4b58-aece-a8c5d6809967",
      "target_ref": "attack-pattern--5e943b66-06a2-4ef3-a0c7-7565fecf6008",
      "description": "CVE-2025-54794 weaponizes the agentic attack pattern formalized under AAP-006.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--677bbeed-b930-4196-a0ec-240990824293",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--b5aa53ee-d5bc-4808-a25e-abfb1b0faca2",
      "target_ref": "attack-pattern--38abbfb6-2f9c-4890-aa64-a0363710a6c4",
      "description": "CVE-2025-54795 weaponizes the agentic attack pattern formalized under AAP-002.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--01bce48e-2e3f-454b-af8c-895f1d347025",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--b5aa53ee-d5bc-4808-a25e-abfb1b0faca2",
      "target_ref": "attack-pattern--6616b465-098e-4088-a13b-882430fa99a1",
      "description": "CVE-2025-54795 weaponizes the agentic attack pattern formalized under AAP-007.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--ab911ed5-f204-4838-a836-b7ebb9481d42",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--b5aa53ee-d5bc-4808-a25e-abfb1b0faca2",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--dff39a12-8b57-4925-a4bd-06b02953e338",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--09cfd756-732a-426d-ac11-8d9ddb3e9e05",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--038a2ac9-c415-4ae0-afbb-26bc90709e0d",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--09cfd756-732a-426d-ac11-8d9ddb3e9e05",
      "target_ref": "attack-pattern--ae03499f-1cb4-40c4-a7eb-f30e7cda44b9",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--9d152454-29a8-4aa4-a9ab-7f1dfdf4c9cc",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--a2309998-5b8b-4e6a-a945-6c44d2dd8f4a",
      "target_ref": "attack-pattern--6cdfab74-1358-48e3-ab2b-4b5ba7a83b5a",
      "description": "CVE-2025-59417 weaponizes the agentic attack pattern formalized under AAP-003.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--23bda459-7e37-4e29-a214-50778c982928",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--5a0ba985-2417-407e-a740-407c19bd8469",
      "target_ref": "attack-pattern--6616b465-098e-4088-a13b-882430fa99a1",
      "description": "CVE-2025-59528 weaponizes the agentic attack pattern formalized under AAP-007.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--d074e924-06e4-48be-a1cb-1ec7b85e101a",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--5a0ba985-2417-407e-a740-407c19bd8469",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--d56bdfe4-d36b-4fc9-afc1-c72787710375",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--3be7517c-87f4-4854-ab6c-b59e6375be74",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--1765be11-2bf0-4333-aa58-546337fad1a8",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--64b3574d-08fb-4c31-aafa-d2ef3eace3c6",
      "target_ref": "attack-pattern--6cdfab74-1358-48e3-ab2b-4b5ba7a83b5a",
      "description": "CVE-2025-66389 weaponizes the agentic attack pattern formalized under AAP-003.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--a6ad24e2-93a6-4905-a337-ededace52493",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--64b3574d-08fb-4c31-aafa-d2ef3eace3c6",
      "target_ref": "attack-pattern--38abbfb6-2f9c-4890-aa64-a0363710a6c4",
      "description": "CVE-2025-66389 weaponizes the agentic attack pattern formalized under AAP-002.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--b5801499-e2e5-4599-a6ac-2a886702cd2b",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--44b6cfb1-604e-4443-a372-93df0a88bdbe",
      "target_ref": "attack-pattern--ae03499f-1cb4-40c4-a7eb-f30e7cda44b9",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--6cb273aa-a89f-4a1b-a67f-941f6899f759",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--93eac75f-5098-4c20-ae71-1bb4227827ea",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--2506e742-1d7c-41e4-a121-9a9a71944f59",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--93eac75f-5098-4c20-ae71-1bb4227827ea",
      "target_ref": "attack-pattern--ae03499f-1cb4-40c4-a7eb-f30e7cda44b9",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--22afd8d0-11f9-464a-a0fa-d88339a175c6",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--714eec4e-1c8b-4a54-abe4-e222de49a6a5",
      "target_ref": "attack-pattern--6cdfab74-1358-48e3-ab2b-4b5ba7a83b5a",
      "description": "CVE-2026-11393 weaponizes the agentic attack pattern formalized under AAP-003.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--6d6f4425-a934-41d6-a155-6a7d41f97cea",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--714eec4e-1c8b-4a54-abe4-e222de49a6a5",
      "target_ref": "attack-pattern--6616b465-098e-4088-a13b-882430fa99a1",
      "description": "CVE-2026-11393 weaponizes the agentic attack pattern formalized under AAP-007.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--ce5e975d-5a96-4a5b-a489-bdfb29413ae9",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--714eec4e-1c8b-4a54-abe4-e222de49a6a5",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--9a4c1ef0-622a-4390-acc9-2b3d6f831da3",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--714eec4e-1c8b-4a54-abe4-e222de49a6a5",
      "target_ref": "attack-pattern--ae03499f-1cb4-40c4-a7eb-f30e7cda44b9",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--24766e96-249f-4811-a947-74f635823cfd",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--a44e7971-9624-4e94-aeaf-2fbfab725876",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--4b98dd6b-dec4-49a7-ac35-e2f61f73d0f4",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--77af9155-6d00-45fe-a9c9-1d7983bd3ff7",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--d16e5cde-fa13-4703-aa48-5e02badd2bbb",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--49d20b6d-eceb-4890-a36e-475509b1a82f",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--11dd901d-df75-4ead-a9a2-37411837e004",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--462c7ec3-a095-49e6-a672-8782bb6cb1c0",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--3ebe3a85-df3b-4c5d-a5c7-ff63056a80f5",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--1499f0ac-4dad-4a58-a848-859142e54440",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--3f07aa1e-6bfe-4476-a4cc-a5801b4986ba",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--89197ee9-974d-4422-a92a-b54754c33346",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--ec5342a8-9352-45b6-a505-67d41ee4b9a1",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--c05ef79f-5dda-43bc-a61c-dc2fb2f76d22",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--511bd225-981d-4eb1-a349-12773188dad1",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--4f3dcf7c-4821-49cd-abcc-37abbe5ed5e9",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--927a16ca-1da7-4324-af2d-38134293584d",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--b3adae59-53a1-4e5b-a012-dc137b20f3dc",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--5866ffd8-d3cc-4563-a4b8-20b6d7f78cb3",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--4ed32fcd-2756-4c0e-acd9-f676104241d7",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--5b2866a6-4adf-4d20-ac89-25871d32bee5",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--4c4f9b40-2748-4d3b-abbb-99d8b9c7f891",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--94387dd4-a833-48b5-a8d7-ac32adbf9593",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--7df4f675-811b-46dc-a5e5-8bb2ef4fbfa2",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--7c5be026-0d0f-46fe-a54b-44a924214a7e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--661252a5-0b90-4034-ace8-d016c3b036cb",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--6329702b-c15b-48b8-a40a-1839d7aa4e52",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--890041e0-fa18-4629-a712-5503d8e851ff",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--05822801-7618-4743-a610-e1d1087ecfae",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--13316664-fcf3-4878-a74e-48680bade83e",
      "target_ref": "attack-pattern--6616b465-098e-4088-a13b-882430fa99a1",
      "description": "CVE-2026-22807 weaponizes the agentic attack pattern formalized under AAP-007.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--21005fdf-1107-4c13-ac57-f07afd51dd50",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--13316664-fcf3-4878-a74e-48680bade83e",
      "target_ref": "attack-pattern--5e89795f-ce4c-401a-a79b-c277e480c825",
      "description": "CVE-2026-22807 weaponizes the agentic attack pattern formalized under AAP-004.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--7e54e8f9-b6e0-4e5b-a5d7-e14842711259",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--b2fac28c-3fe6-4be1-a32a-194547bef238",
      "target_ref": "attack-pattern--4944e7db-5acd-4563-ab0c-1f343db7e8b3",
      "description": "CVE-2026-24307 weaponizes the agentic attack pattern formalized under AAP-001.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--28759bbe-8f48-486b-aad3-7c23e0f22458",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--0e599c3b-6883-48f0-a99b-c2550b87fc49",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--ecd3f531-b059-4d87-ac46-5f901b62c96e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--157a78ab-0e23-4052-a660-c30bdd56e458",
      "target_ref": "attack-pattern--38abbfb6-2f9c-4890-aa64-a0363710a6c4",
      "description": "CVE-2026-25724 weaponizes the agentic attack pattern formalized under AAP-002.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--17641923-038c-48c4-aa5b-b560d9e753e2",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--157a78ab-0e23-4052-a660-c30bdd56e458",
      "target_ref": "attack-pattern--6cdfab74-1358-48e3-ab2b-4b5ba7a83b5a",
      "description": "CVE-2026-25724 weaponizes the agentic attack pattern formalized under AAP-003.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--f3e70161-efb8-4bf2-a880-fd7c0a36a721",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--63ae33e6-2c76-4510-a412-0e1c57c53aaa",
      "target_ref": "attack-pattern--6616b465-098e-4088-a13b-882430fa99a1",
      "description": "CVE-2026-27966 weaponizes the agentic attack pattern formalized under AAP-007.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--13f9650f-af25-4fb4-a5b7-e1d680ed31df",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--63ae33e6-2c76-4510-a412-0e1c57c53aaa",
      "target_ref": "attack-pattern--6cdfab74-1358-48e3-ab2b-4b5ba7a83b5a",
      "description": "CVE-2026-27966 weaponizes the agentic attack pattern formalized under AAP-003.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--1b554ce6-55c9-4b48-acfd-7292e0def2b2",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--1dafbb92-a318-45ab-a509-c42e0d2812e6",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--17ed31f6-322e-4fd5-af8e-3bd0bf06d6a6",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--ba475934-9fe3-4f6a-a39e-1b225a29110b",
      "target_ref": "attack-pattern--6cdfab74-1358-48e3-ab2b-4b5ba7a83b5a",
      "description": "CVE-2026-31377 weaponizes the agentic attack pattern formalized under AAP-003.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--c771d391-83e3-4624-a8a2-b53803afcac0",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--ba475934-9fe3-4f6a-a39e-1b225a29110b",
      "target_ref": "attack-pattern--5e943b66-06a2-4ef3-a0c7-7565fecf6008",
      "description": "CVE-2026-31377 weaponizes the agentic attack pattern formalized under AAP-006.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--a4f825ee-d22f-4357-a0d0-3a3dce8f863f",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--96f88aed-8039-464c-a448-3dad9237bc98",
      "target_ref": "attack-pattern--6616b465-098e-4088-a13b-882430fa99a1",
      "description": "CVE-2026-33626 weaponizes the agentic attack pattern formalized under AAP-007.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--af5da715-99c8-4467-a8a3-da865bfa77ce",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--4779335f-2a6d-472f-aff2-3136c9348669",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--5fa7b85b-9076-44ae-a90e-0695c5759bf7",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--4779335f-2a6d-472f-aff2-3136c9348669",
      "target_ref": "attack-pattern--ae03499f-1cb4-40c4-a7eb-f30e7cda44b9",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--75d18612-93e5-4941-a380-68a3236ace7e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--ee340eae-e3fc-4276-a245-71a23fcaacea",
      "target_ref": "attack-pattern--6cdfab74-1358-48e3-ab2b-4b5ba7a83b5a",
      "description": "CVE-2026-33873 weaponizes the agentic attack pattern formalized under AAP-003.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--4452641c-9e9e-4378-afc8-a1c2dc1c3e39",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--ee340eae-e3fc-4276-a245-71a23fcaacea",
      "target_ref": "attack-pattern--6616b465-098e-4088-a13b-882430fa99a1",
      "description": "CVE-2026-33873 weaponizes the agentic attack pattern formalized under AAP-007.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--92025619-0d9a-4f71-a4af-09cfe0a905ae",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--bf73d132-dd83-4d6c-a6fb-1e5f892f4ba8",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--05bf4014-e586-4980-ad43-14ae3616dcf1",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--06a219eb-062d-4535-a8f4-cf9d542d548d",
      "target_ref": "attack-pattern--4944e7db-5acd-4563-ab0c-1f343db7e8b3",
      "description": "CVE-2026-40087 weaponizes the agentic attack pattern formalized under AAP-001.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--fe99afa7-be2b-416f-aec2-d27e66300f93",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--06a219eb-062d-4535-a8f4-cf9d542d548d",
      "target_ref": "attack-pattern--38abbfb6-2f9c-4890-aa64-a0363710a6c4",
      "description": "CVE-2026-40087 weaponizes the agentic attack pattern formalized under AAP-002.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--d9f19a28-3385-431b-acea-4f4e5c5a4bc2",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--eef88695-df93-45ac-abd6-259eba86a8d8",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--d0850391-6a52-46d3-a246-96338714b34e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--eef88695-df93-45ac-abd6-259eba86a8d8",
      "target_ref": "attack-pattern--ae03499f-1cb4-40c4-a7eb-f30e7cda44b9",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--9e74ef91-133e-453a-a52e-99d068baad92",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--57df4398-58cf-45a5-aa52-015d7b5ce702",
      "target_ref": "attack-pattern--27ca782d-3e4f-49a1-a49c-d7e389612bab",
      "description": "CVE-2026-4372 weaponizes the agentic attack pattern formalized under AAP-005.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--f7cd3dbd-7a31-4229-a587-33b8d06f5a55",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--5ca174fa-e997-4669-a4ee-b502bce1ce11",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--f4dd8ecf-1324-4b10-a6f4-0faf0c297bde",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--20bd1572-f7c9-4415-abb8-f68f7c699353",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--1646f178-9109-49ba-a929-dc78a2496c8e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--20bd1572-f7c9-4415-abb8-f68f7c699353",
      "target_ref": "attack-pattern--ae03499f-1cb4-40c4-a7eb-f30e7cda44b9",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--08e5b8f6-062e-4486-aee2-f75fc7cf4230",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--35d3df09-7ad6-4fea-a666-86169f08d4af",
      "target_ref": "attack-pattern--5e943b66-06a2-4ef3-a0c7-7565fecf6008",
      "description": "CVE-2026-48746 weaponizes the agentic attack pattern formalized under AAP-006.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--9a1f2189-76c6-4cd1-aa0a-8d0db41cd040",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--c7660163-8a91-4fda-ac8d-0e0842e7d441",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--56fbda7d-03b2-4d07-a05f-47df35cf8697",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--c7660163-8a91-4fda-ac8d-0e0842e7d441",
      "target_ref": "attack-pattern--ae03499f-1cb4-40c4-a7eb-f30e7cda44b9",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--a77a7677-bf54-48ca-a7a1-d294cc7ecc45",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--9093bbdb-fb7f-4b66-ae33-36be448c47c6",
      "target_ref": "attack-pattern--6616b465-098e-4088-a13b-882430fa99a1",
      "description": "CVE-2026-5027 weaponizes the agentic attack pattern formalized under AAP-007.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--a1740a85-588f-4802-a019-af841d922436",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--9093bbdb-fb7f-4b66-ae33-36be448c47c6",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--cc1af381-b96a-4a12-ad1f-f4825a892622",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--65a85d89-3082-4aea-ae26-d296cb9215a3",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--19a6de2b-5ca9-4618-ac72-633037dc0bdc",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--65a85d89-3082-4aea-ae26-d296cb9215a3",
      "target_ref": "attack-pattern--ae03499f-1cb4-40c4-a7eb-f30e7cda44b9",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--34821be2-de13-4259-a5d3-890e78e313f8",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--e82f4ba9-8313-4aca-a2d0-0272590dc0ee",
      "target_ref": "attack-pattern--5e943b66-06a2-4ef3-a0c7-7565fecf6008",
      "description": "CVE-2026-54236 weaponizes the agentic attack pattern formalized under AAP-006.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--b6a63575-6fbe-4991-a159-3b403bf379a9",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--faa251a5-582b-41fd-af10-e5c7dc619a39",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--eb56feb0-bd73-4231-a0c6-c0f646979274",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--5a837c68-e38f-49ec-a95a-9cb082e6b3be",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--6701c9ef-c827-4134-a672-2a373d200097",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--5a837c68-e38f-49ec-a95a-9cb082e6b3be",
      "target_ref": "attack-pattern--ae03499f-1cb4-40c4-a7eb-f30e7cda44b9",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--5d39bc86-6109-4dfe-aeed-38076b64c4a3",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--bfb22645-ae8e-451e-aba0-d1ebff3803ba",
      "target_ref": "attack-pattern--ae03499f-1cb4-40c4-a7eb-f30e7cda44b9",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--8be140ef-3443-41c3-a957-38735dce8430",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--acc85d74-8ca1-49e8-ae50-c506f742578d",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--4760af83-b74c-41be-a2b6-1c498211f82d",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--a5ba3f4b-9078-4517-a77e-faacb70e70f2",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--db5ca45e-fa77-4e18-a70f-112f7494d94c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--e99c45bd-49f6-41be-a991-6395d782a837",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--a52e4dad-eedf-4506-aa27-c4ae26a403b2",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--492c931c-2590-49ff-a000-81ba89e15999",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--d8db5a3a-e2f0-4851-ab14-417c66308076",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--2bf67a56-8683-4d11-a493-3ef43c0c51d5",
      "target_ref": "attack-pattern--6616b465-098e-4088-a13b-882430fa99a1",
      "description": "CVE-2026-82331 weaponizes the agentic attack pattern formalized under AAP-007.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--59835bff-3032-472a-ac82-283453f357be",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--2bf67a56-8683-4d11-a493-3ef43c0c51d5",
      "target_ref": "attack-pattern--6cdfab74-1358-48e3-ab2b-4b5ba7a83b5a",
      "description": "CVE-2026-82331 weaponizes the agentic attack pattern formalized under AAP-003.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--2a5add8e-46c1-482d-a342-fc30bd97fba1",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--65563cd0-30f3-427a-a4bb-b5ecd7bb7bf2",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--bd9e6999-7281-4ced-acfe-4fdb27cac6b8",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--3ae51b53-3220-4330-ad40-7009b26c0a0a",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--baf80918-2f14-4ae1-a82d-d909606d7ffd",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--4fe6bbbf-a1ed-4444-a4aa-6ddc29b69b81",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--5e64ff93-50fd-47b8-a123-bf7cea3484a2",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--ecf701c2-b8ce-4610-a3a7-fd40f79df003",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--e9bee69f-1f50-4e87-aaf4-844013e2b79c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--9d1b6e59-6ebb-4eb1-a96b-64f3bf3bf1ba",
      "target_ref": "attack-pattern--ae03499f-1cb4-40c4-a7eb-f30e7cda44b9",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--96836c96-4167-4fb0-aadb-e2d6130df608",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--9d1b6e59-6ebb-4eb1-a96b-64f3bf3bf1ba",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--1886a136-edb2-4648-acba-72800479d2c0",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--cc336701-7a79-4e90-aacd-952a61fd26d7",
      "target_ref": "attack-pattern--6616b465-098e-4088-a13b-882430fa99a1",
      "description": "CVE-2026-87491 weaponizes the agentic attack pattern formalized under AAP-007.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--dca12f10-e29c-467f-a2c8-bc9fa6588d30",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--cc336701-7a79-4e90-aacd-952a61fd26d7",
      "target_ref": "attack-pattern--38abbfb6-2f9c-4890-aa64-a0363710a6c4",
      "description": "CVE-2026-87491 weaponizes the agentic attack pattern formalized under AAP-002.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--8084f3ce-7ed5-45c7-a975-4a8b465253c1",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--ad1265ce-e2c9-4f94-a140-36986451da7b",
      "target_ref": "attack-pattern--38abbfb6-2f9c-4890-aa64-a0363710a6c4",
      "description": "CVE-2026-87983 weaponizes the agentic attack pattern formalized under AAP-002.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--f8d76035-ab79-446c-a737-a21fd738af28",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--ad1265ce-e2c9-4f94-a140-36986451da7b",
      "target_ref": "attack-pattern--6cdfab74-1358-48e3-ab2b-4b5ba7a83b5a",
      "description": "CVE-2026-87983 weaponizes the agentic attack pattern formalized under AAP-003.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--65c403f6-5e87-4462-a321-9d021a90b37e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--ad1265ce-e2c9-4f94-a140-36986451da7b",
      "target_ref": "attack-pattern--4944e7db-5acd-4563-ab0c-1f343db7e8b3",
      "description": "CVE-2026-87983 weaponizes the agentic attack pattern formalized under AAP-001.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--1f9e8493-ac27-4fc8-afbe-e3f2bf493276",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--841a893a-8b6a-4f70-a96c-39efdb5e436b",
      "target_ref": "attack-pattern--38abbfb6-2f9c-4890-aa64-a0363710a6c4",
      "description": "CVE-2026-87984 weaponizes the agentic attack pattern formalized under AAP-002.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--897f7720-11e7-4ec1-ae95-0c37ac97f5fd",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--841a893a-8b6a-4f70-a96c-39efdb5e436b",
      "target_ref": "attack-pattern--6cdfab74-1358-48e3-ab2b-4b5ba7a83b5a",
      "description": "CVE-2026-87984 weaponizes the agentic attack pattern formalized under AAP-003.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--4c2f3f33-ecbc-4e52-a074-07d4f8562179",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--11ff7c81-b174-4d39-a799-481cc2d3cbfd",
      "target_ref": "attack-pattern--38abbfb6-2f9c-4890-aa64-a0363710a6c4",
      "description": "CVE-2026-87985 weaponizes the agentic attack pattern formalized under AAP-002.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--2b705bca-818a-4898-af3d-9678a56b1dd5",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--11ff7c81-b174-4d39-a799-481cc2d3cbfd",
      "target_ref": "attack-pattern--6cdfab74-1358-48e3-ab2b-4b5ba7a83b5a",
      "description": "CVE-2026-87985 weaponizes the agentic attack pattern formalized under AAP-003.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--65a9859c-45bb-40e1-a1c9-ec4e1b8a82aa",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--11ff7c81-b174-4d39-a799-481cc2d3cbfd",
      "target_ref": "attack-pattern--4944e7db-5acd-4563-ab0c-1f343db7e8b3",
      "description": "CVE-2026-87985 weaponizes the agentic attack pattern formalized under AAP-001.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--3c93e9ff-2040-4342-aa23-5fe1a3b45f98",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--f1517580-f022-469c-a95e-ff50a0a1609c",
      "target_ref": "attack-pattern--38abbfb6-2f9c-4890-aa64-a0363710a6c4",
      "description": "CVE-2026-87986 weaponizes the agentic attack pattern formalized under AAP-002.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--d6cfb6e7-4d88-4842-a317-ca1adb97342a",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--f1517580-f022-469c-a95e-ff50a0a1609c",
      "target_ref": "attack-pattern--6cdfab74-1358-48e3-ab2b-4b5ba7a83b5a",
      "description": "CVE-2026-87986 weaponizes the agentic attack pattern formalized under AAP-003.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--0aa566af-87c3-4327-a349-1eb7a878e824",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--f1517580-f022-469c-a95e-ff50a0a1609c",
      "target_ref": "attack-pattern--4944e7db-5acd-4563-ab0c-1f343db7e8b3",
      "description": "CVE-2026-87986 weaponizes the agentic attack pattern formalized under AAP-001.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--de9c371e-7521-46d7-a966-0dbb2ba4a99c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--9642af3a-4e09-4747-a555-4149c626605f",
      "target_ref": "attack-pattern--38abbfb6-2f9c-4890-aa64-a0363710a6c4",
      "description": "CVE-2026-87987 weaponizes the agentic attack pattern formalized under AAP-002.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--74eba2a7-9cf4-4cb6-a132-74b590e342c3",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--9642af3a-4e09-4747-a555-4149c626605f",
      "target_ref": "attack-pattern--6cdfab74-1358-48e3-ab2b-4b5ba7a83b5a",
      "description": "CVE-2026-87987 weaponizes the agentic attack pattern formalized under AAP-003.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--91ccfc7a-2192-4708-af91-8bd66ae981aa",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--9642af3a-4e09-4747-a555-4149c626605f",
      "target_ref": "attack-pattern--4944e7db-5acd-4563-ab0c-1f343db7e8b3",
      "description": "CVE-2026-87987 weaponizes the agentic attack pattern formalized under AAP-001.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--bb1ec3b2-b6ff-415c-af58-6942be421a3c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--39871ca1-d251-427a-a959-662f4ca6c4a8",
      "target_ref": "attack-pattern--38abbfb6-2f9c-4890-aa64-a0363710a6c4",
      "description": "CVE-2026-87988 weaponizes the agentic attack pattern formalized under AAP-002.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--51c723dc-39f8-4b97-ab8f-2336ffb9dfe5",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--39871ca1-d251-427a-a959-662f4ca6c4a8",
      "target_ref": "attack-pattern--6cdfab74-1358-48e3-ab2b-4b5ba7a83b5a",
      "description": "CVE-2026-87988 weaponizes the agentic attack pattern formalized under AAP-003.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--681b6ad6-a434-4fad-a6f2-c6e27593225b",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--39871ca1-d251-427a-a959-662f4ca6c4a8",
      "target_ref": "attack-pattern--4944e7db-5acd-4563-ab0c-1f343db7e8b3",
      "description": "CVE-2026-87988 weaponizes the agentic attack pattern formalized under AAP-001.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--3be3807c-6054-4289-a7a6-d8c1bb9a54c0",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--46533786-2a76-4a5a-ab7e-31d6c89da1d0",
      "target_ref": "attack-pattern--6cdfab74-1358-48e3-ab2b-4b5ba7a83b5a",
      "description": "CVE-2026-90562 weaponizes the agentic attack pattern formalized under AAP-003.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--0e1d7935-da32-4c0a-ab76-584c226380ab",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--46533786-2a76-4a5a-ab7e-31d6c89da1d0",
      "target_ref": "attack-pattern--6616b465-098e-4088-a13b-882430fa99a1",
      "description": "CVE-2026-90562 weaponizes the agentic attack pattern formalized under AAP-007.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--ee96635a-9e7f-4c44-ac55-3c7df7d4a70e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "targets",
      "source_ref": "vulnerability--39398cec-07b9-4d84-a7ca-8ef8d2857d26",
      "target_ref": "attack-pattern--38abbfb6-2f9c-4890-aa64-a0363710a6c4",
      "description": "CVE-2026-90711 weaponizes the agentic attack pattern formalized under AAP-002.",
      "confidence": 92
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--881ae6a5-65ca-45c8-a69c-2e38477dec8a",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--198187b4-ca29-4171-a843-047799cac47d",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--a25a7445-adcd-42e6-ab9b-255b09eea77e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--198187b4-ca29-4171-a843-047799cac47d",
      "target_ref": "attack-pattern--ae03499f-1cb4-40c4-a7eb-f30e7cda44b9",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1552.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--e23f450a-d222-4e9b-aaae-4e20ac96a5ea",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "uses",
      "source_ref": "vulnerability--cbaedc7d-7998-442a-a953-3592067cbf17",
      "target_ref": "attack-pattern--d5f68c3e-3583-497a-afd3-6fe32b38bf5f",
      "description": "Attack execution telemetry aligns with MITRE ATT&CK technique T1059.",
      "confidence": 90
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--0ac0f1dd-a678-487f-ad6a-c982026c57f6",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "related-to",
      "source_ref": "tool--b531f159-4038-4822-abb5-5089f5985e3e",
      "target_ref": "attack-pattern--4944e7db-5acd-4563-ab0c-1f343db7e8b3",
      "description": "AgentThreat Studio dynamically audits and models compromise propagation for AAP-001.",
      "confidence": 99
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--a5a9107c-b345-4479-afc9-79bb4caa4f72",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "related-to",
      "source_ref": "tool--b531f159-4038-4822-abb5-5089f5985e3e",
      "target_ref": "attack-pattern--38abbfb6-2f9c-4890-aa64-a0363710a6c4",
      "description": "AgentThreat Studio dynamically audits and models compromise propagation for AAP-002.",
      "confidence": 99
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--cafdaeb8-abaa-488a-ae3e-854d94d72200",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "related-to",
      "source_ref": "tool--b531f159-4038-4822-abb5-5089f5985e3e",
      "target_ref": "attack-pattern--6cdfab74-1358-48e3-ab2b-4b5ba7a83b5a",
      "description": "AgentThreat Studio dynamically audits and models compromise propagation for AAP-003.",
      "confidence": 99
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--3832f4a0-2483-4738-a6ed-36f85af4be2c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "related-to",
      "source_ref": "tool--b531f159-4038-4822-abb5-5089f5985e3e",
      "target_ref": "attack-pattern--5e89795f-ce4c-401a-a79b-c277e480c825",
      "description": "AgentThreat Studio dynamically audits and models compromise propagation for AAP-004.",
      "confidence": 99
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--76ab39e7-8e68-4e48-a0f6-7ec72b879173",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "related-to",
      "source_ref": "tool--b531f159-4038-4822-abb5-5089f5985e3e",
      "target_ref": "attack-pattern--27ca782d-3e4f-49a1-a49c-d7e389612bab",
      "description": "AgentThreat Studio dynamically audits and models compromise propagation for AAP-005.",
      "confidence": 99
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--2a043106-b960-4309-aee5-84b5adbd9428",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "related-to",
      "source_ref": "tool--b531f159-4038-4822-abb5-5089f5985e3e",
      "target_ref": "attack-pattern--5e943b66-06a2-4ef3-a0c7-7565fecf6008",
      "description": "AgentThreat Studio dynamically audits and models compromise propagation for AAP-006.",
      "confidence": 99
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--7d425511-9d46-4972-a1c9-804e524f6f82",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "relationship_type": "related-to",
      "source_ref": "tool--b531f159-4038-4822-abb5-5089f5985e3e",
      "target_ref": "attack-pattern--6616b465-098e-4088-a13b-882430fa99a1",
      "description": "AgentThreat Studio dynamically audits and models compromise propagation for AAP-007.",
      "confidence": 99
    }
  ]
}