{
  "type": "bundle",
  "id": "bundle--e11db70a-5e18-44ac-aa44-669b93a67ef8",
  "spec_version": "2.1",
  "objects": [
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "Hermes Codex Temporal Risk Intelligence",
      "description": "Autonomous Cyber Risk Intelligence & Temporal Threat Trajectory Engine.",
      "identity_class": "system",
      "sectors": [
        "technology",
        "cybersecurity"
      ],
      "contact_information": "https://hermes-codex.vercel.app"
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--5c3e1d5c-02e1-4936-abdf-43d2968e6d00",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2020-3452",
      "description": "CVE-2020-3452: Cisco ASA and FTD Web Services Read-Only Path Traversal",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2020-3452",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-3452"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2020-3452",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2020-3452/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--348ca650-1731-46c8-a6f6-4796975baae1",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2024-20359",
      "description": "CVE-2024-20359: Cisco ASA and FTD Persistent Local Code Execution (Line Runner / ArcaneDoor)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2024-20359",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20359"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2024-20359",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2024-20359/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--8018a302-e6f4-4965-adec-be0e5184c2d0",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-0282",
      "description": "CVE-2025-0282: Pre-Authentication Root RCE via Stack Buffer Overflow in Ivanti Connect Secure (ICS / IPS / ZTA)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-0282",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0282"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-0282",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-0282/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--38885850-1f67-4e96-af9a-e1385567712d",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-20188",
      "description": "CVE-2025-20188: Arbitrary File Upload and Root RCE in Cisco IOS XE WLC via Hard-Coded JWT",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-20188",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20188"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-20188",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-20188/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--decb767e-7288-4c43-a526-adf7d6e339b1",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-20281",
      "description": "CVE-2025-20281: Unauthenticated Root RCE in Cisco Identity Services Engine (ISE) API",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-20281",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20281"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-20281",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-20281/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--4b1b7578-644c-4cee-a209-befc0c385a80",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-20393",
      "description": "CVE-2025-20393: Unauthenticated Root RCE in Cisco Secure Email Gateway (Spam Quarantine)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-20393",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20393"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-20393",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-20393/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--27efb9d5-3d19-460c-a533-b2335851977e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-22457",
      "description": "CVE-2025-22457: Subsequent Pre-Auth Root RCE via Stack Buffer Overflow in Ivanti Connect Secure (ICS / IPS / ZTA)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-22457",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22457"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-22457",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-22457/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--d369c1e4-722e-489e-acce-65afc804d323",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-24472",
      "description": "CVE-2025-24472: Super-Admin Authentication Bypass in Fortinet FortiOS & FortiProxy (CSF Proxy)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-24472",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24472"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-24472",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-24472/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--5c65350f-e2bd-4175-aaa7-94da05bd5958",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-24813",
      "description": "CVE-2025-24813: RCE via Partial PUT Requests and Session Deserialization in Apache Tomcat",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-24813",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24813"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-24813",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-24813/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--c5bb16ce-9ebd-4dac-a43a-15215088ad9e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-25257",
      "description": "CVE-2025-25257: Unauthenticated SQL Injection in Fortinet FortiWeb Management Interface",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-25257",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25257"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-25257",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-25257/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--25db4afa-1f31-4cdf-a288-1cce7424b838",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-26319",
      "description": "CVE-2025-26319: Flowise Arbitrary File Upload and Directory Traversal Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-26319",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26319"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-26319",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-26319/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--2d772e96-d3ee-4b7e-ad39-aefee3a980da",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-29927",
      "description": "CVE-2025-29927: Middleware Authorization Bypass via x-middleware-subrequest Header in Next.js",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-29927",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29927"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-29927",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-29927/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--08af832f-4a18-4580-ae36-ea471a96329b",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-32433",
      "description": "CVE-2025-32433: Pre-Authentication Command Execution in Erlang/OTP SSH Server",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-32433",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32433"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-32433",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-32433/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--3070e534-621f-44b3-a2ff-fcd376eb64c5",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-3248",
      "description": "CVE-2025-3248: Langflow Unauthenticated Code Validation Python exec() Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-3248",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3248"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-3248",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-3248/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--983013aa-b175-44aa-ad88-3e21fa3f6dda",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-39682",
      "description": "CVE-2025-39682: Linux Kernel kTLS Receive Path Zero-Length Record Use-After-Free Privilege Escalation",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-39682",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39682"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-39682",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-39682/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--69554729-a5eb-4e2c-a997-5ac234199a85",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-42944",
      "description": "CVE-2025-42944: Unauthenticated Java Deserialization RCE in SAP NetWeaver AS Java (RMI-P4)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-42944",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-42944"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-42944",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-42944/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--88657c14-b7b9-44ef-ad92-762d7b7c0d89",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-47277",
      "description": "CVE-2025-47277: vLLM Distributed KV-Cache PyNcclPipe Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-47277",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47277"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-47277",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-47277/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--55320dae-25ab-43da-ac83-3353b2c0c1c1",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-49113",
      "description": "CVE-2025-49113: Authenticated RCE via PHP Deserialization in Roundcube Webmail (upload.php)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-49113",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49113"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-49113",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-49113/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--48343358-7151-4044-abe6-d3f9db13aee9",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-49704",
      "description": "CVE-2025-49704: Remote Code Injection in Microsoft SharePoint Server",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-49704",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49704"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-49704",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-49704/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--5bd4ee66-5624-4a00-a8ee-39d3d00a70ac",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-5277",
      "description": "CVE-2025-5277: Command Injection in AWS MCP Server via Prompt-Coerced Tool Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-5277",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5277"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-5277",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-5277/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--46875624-eb09-49f0-aa7b-62f322008a32",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-53770",
      "description": "CVE-2025-53770: Insecure Deserialization RCE in Microsoft SharePoint Server (ToolShell)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-53770",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-53770"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-53770",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-53770/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--432daf2d-2c0a-4b58-aece-a8c5d6809967",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-54794",
      "description": "CVE-2025-54794: Claude Code Working Directory Sandbox Escape via Path Prefix Matching",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-54794",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-54794"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-54794",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-54794/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--b5aa53ee-d5bc-4808-a25e-abfb1b0faca2",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-54795",
      "description": "CVE-2025-54795: Claude Code Echo Command Injection and Approval Prompt Bypass via Untrusted Context",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-54795",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-54795"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-54795",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-54795/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--09cfd756-732a-426d-ac11-8d9ddb3e9e05",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-55182",
      "description": "CVE-2025-55182:",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-55182",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-55182"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-55182",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-55182/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--d51d6b2d-6180-454c-a84d-44b49446a5c0",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-5777",
      "description": "CVE-2025-5777: OOB Memory Disclosure and MFA Session Hijacking in Citrix NetScaler ADC & Gateway (CitrixBleed 2)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-5777",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5777"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-5777",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-5777/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--edf5354a-2f7b-44b5-a215-62e18a9848da",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-59468",
      "description": "CVE-2025-59468: PostgreSQL Remote Code Execution via Malicious Password Parameter in Veeam Backup & Replication",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-59468",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-59468"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-59468",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-59468/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--b8ac5dbe-6dd2-4ebe-a355-c919d9faf309",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-59470",
      "description": "CVE-2025-59470: PostgreSQL Remote Code Execution via Operator Role in Veeam Backup & Replication",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-59470",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-59470"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-59470",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-59470/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--5a0ba985-2417-407e-a740-407c19bd8469",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-59528",
      "description": "CVE-2025-59528: Flowise CustomMCP Node JavaScript Function Constructor Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-59528",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-59528"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-59528",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-59528/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--3be7517c-87f4-4854-ab6c-b59e6375be74",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2025-61882",
      "description": "CVE-2025-61882: Zero-Day RCE in Oracle E-Business Suite (BI Publisher / Concurrent Processing)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2025-61882",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61882"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2025-61882",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2025-61882/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--5b5bf598-f1e7-429f-adfc-adb9d346d4f6",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-0257",
      "description": "CVE-2026-0257: Critical Authentication Bypass in Palo Alto Networks GlobalProtect Portal",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-0257",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0257"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-0257",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-0257/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--44b6cfb1-604e-4443-a372-93df0a88bdbe",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-0300",
      "description": "CVE-2026-0300: Unauthenticated Stack Buffer Overflow to Root RCE in Palo Alto Networks PAN-OS User-ID Captive Portal",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-0300",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0300"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-0300",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-0300/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--93eac75f-5098-4c20-ae71-1bb4227827ea",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-0770",
      "description": "CVE-2026-0770: Unauthenticated Remote Code Execution in Langflow via Code Validation Sandbox Escape",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-0770",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0770"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-0770",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-0770/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--714eec4e-1c8b-4a54-abe4-e222de49a6a5",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-11393",
      "description": "CVE-2026-11393: AWS Bedrock AgentCore Multi-Agent Collaboration Poisoning via Triple-Quote Injection RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-11393",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11393"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-11393",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-11393/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--77af9155-6d00-45fe-a9c9-1d7983bd3ff7",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-12045",
      "description": "CVE-2026-12045: pgAdmin 4 AI Assistant Read-Only Transaction Bypass to RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-12045",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12045"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-12045",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-12045/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--2003bbf0-a55c-45e5-a9b7-e3b35e6dde5a",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-12293",
      "description": "CVE-2026-12293: Mozilla Firefox WebGPU Use-After-Free Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-12293",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12293"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-12293",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-12293/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--49d20b6d-eceb-4890-a36e-475509b1a82f",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-12645",
      "description": "CVE-2026-12645: Authenticated Remote Code Execution in Ivanti Neurons for ITSM via Missing Authorization in Workflow Handlers",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-12645",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12645"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-12645",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-12645/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--462c7ec3-a095-49e6-a672-8782bb6cb1c0",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-12646",
      "description": "CVE-2026-12646: Authenticated Remote Code Execution in Ivanti Neurons for ITSM via Missing Authorization in Business Logic Actions",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-12646",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12646"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-12646",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-12646/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--1499f0ac-4dad-4a58-a848-859142e54440",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-12647",
      "description": "CVE-2026-12647: Authenticated Remote Code Execution in Ivanti Neurons for ITSM via Missing Authorization in Automation Engine",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-12647",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12647"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-12647",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-12647/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--c05ef79f-5dda-43bc-a61c-dc2fb2f76d22",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-12650",
      "description": "CVE-2026-12650: Authenticated Remote Code Execution with Scope Elevation in Ivanti Neurons for ITSM via Insecure Deserialization",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-12650",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12650"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-12650",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-12650/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--b3adae59-53a1-4e5b-a012-dc137b20f3dc",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-12744",
      "description": "CVE-2026-12744: Unauthenticated Remote Code Execution in Ivanti Neurons for ITSM via Insecure .NET Object Deserialization",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-12744",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12744"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-12744",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-12744/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--4ed32fcd-2756-4c0e-acd9-f676104241d7",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-12745",
      "description": "CVE-2026-12745: Secondary Unauthenticated Remote Code Execution in Ivanti Neurons for ITSM via Deserialization Flaw",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-12745",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12745"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-12745",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-12745/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--0ed620ce-4921-4658-ab35-589dabcbcd72",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-14894",
      "description": "CVE-2026-14894: Super Forms WordPress Plugin Unauthenticated Arbitrary File Upload to Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-14894",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14894"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-14894",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-14894/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--926587d2-b796-404b-a8a3-7f3c59c916e5",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-15718",
      "description": "CVE-2026-15718: Mozilla Firefox WebAssembly Invalid Pointer Dereference",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-15718",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15718"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-15718",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-15718/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--243aeca4-4da3-4cc1-a24e-07fcfffea620",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-16356",
      "description": "CVE-2026-16356: Mozilla Firefox Use-After-Free in Accessibility APIs",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-16356",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16356"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-16356",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-16356/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--eaf5a0ac-5b03-498c-a4f9-2b328f7c4877",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-20079",
      "description": "CVE-2026-20079: Cisco Secure FMC Authentication Bypass to Root RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-20079",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20079"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-20079",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-20079/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--f4876288-4771-4955-a0d2-7691019ae8f8",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-20184",
      "description": "CVE-2026-20184: Cisco Webex SSO Impersonation Vulnerability",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-20184",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20184"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-20184",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-20184/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--d56341b4-f957-49b1-a572-2afe06d9b48c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-20192",
      "description": "CVE-2026-20192: Cisco Identity Services Engine Unauthenticated Authorization Bypass",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-20192",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20192"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-20192",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-20192/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--f5775dff-b1f0-42a6-a0a5-dfa959ee7a91",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-20307",
      "description": "CVE-2026-20307: Cisco Identity Services Engine Insecure Java Deserialization RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-20307",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20307"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-20307",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-20307/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--34323f17-efe8-4e69-a754-cb5f025fd76d",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-20324",
      "description": "CVE-2026-20324: Cisco Secure Firewall Management Center sftunnel OS Command Injection RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-20324",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20324"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-20324",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-20324/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--890041e0-fa18-4629-a712-5503d8e851ff",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-21962",
      "description": "CVE-2026-21962: Critical Authentication & Access Control Bypass in Oracle WebLogic Server Proxy Plug-in",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-21962",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21962"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-21962",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-21962/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--91648d1b-0df3-4a7f-a8ad-62d9425963be",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-22778",
      "description": "CVE-2026-22778: vLLM Multimodal Video URL Heap Overflow and ASLR Bypass RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-22778",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22778"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-22778",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-22778/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--13316664-fcf3-4878-a74e-48680bade83e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-22807",
      "description": "CVE-2026-22807: vLLM Dynamic Module Auto-Map Pre-Auth Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-22807",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22807"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-22807",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-22807/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--ad2e13ca-2786-45e3-ae77-272f0cf341f8",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-24858",
      "description": "CVE-2026-24858: Critical FortiCloud SSO Authentication Bypass (Active In-The-Wild Exploitation)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-24858",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24858"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-24858",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-24858/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--0e599c3b-6883-48f0-a99b-c2550b87fc49",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-25089",
      "description": "CVE-2026-25089: Unauthenticated Remote OS Command Injection in Fortinet FortiSandbox Web Interface",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-25089",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25089"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-25089",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-25089/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--06fc6765-514b-46e6-a886-2c53044b771a",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-27825",
      "description": "CVE-2026-27825: mcp-atlassian Confluence Download Attachment Arbitrary File Write RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-27825",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27825"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-27825",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-27825/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--6b1058f2-5081-499e-afa1-8639b1039c0a",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-28326",
      "description": "CVE-2026-28326: SolarWinds Access Rights Manager Hard-coded Key Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-28326",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28326"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-28326",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-28326/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--e0289472-0d2f-4b42-a7e6-a40b9d935e59",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-3055",
      "description": "CVE-2026-3055: NetScaler Memory Overread (SAML IdP)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-3055",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3055"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-3055",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-3055/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--1dafbb92-a318-45ab-a509-c42e0d2812e6",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-31223",
      "description": "CVE-2026-31223: Snorkel AI BaseLabeler pickle.load Insecure Deserialization RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-31223",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31223"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-31223",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-31223/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--bc33313b-413d-40fa-aeb1-92cfd7d51d0d",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-32626",
      "description": "CVE-2026-32626: AnythingLLM Desktop Streaming Phase XSS to Electron Host RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-32626",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32626"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-32626",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-32626/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--96f88aed-8039-464c-a448-3dad9237bc98",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-33626",
      "description": "CVE-2026-33626: LMDeploy Vision-Language SSRF & Cloud Metadata Exfiltration",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-33626",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33626"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-33626",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-33626/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--4779335f-2a6d-472f-aff2-3136c9348669",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-33634",
      "description": "CVE-2026-33634: Supply Chain Compromise in Aqua Security Trivy GitHub Actions Workflow",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-33634",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33634"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-33634",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-33634/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--70bf4b03-bbbc-4a7d-a412-d8496abef2e4",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-37008",
      "description": "CVE-2026-37008: CrewAI CodeInterpreterTool Python Sandbox Escape & Host Takeover",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-37008",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-37008"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-37008",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-37008/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--bf73d132-dd83-4d6c-a6fb-1e5f892f4ba8",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-39808",
      "description": "CVE-2026-39808: Root OS Command Injection in Fortinet FortiSandbox Administrative API",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-39808",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39808"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-39808",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-39808/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--f70db426-1dad-4097-a25e-edb745ce0e72",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-40933",
      "description": "CVE-2026-40933: Flowise MCP Adapter Stdio Command Injection RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-40933",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40933"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-40933",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-40933/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--21851623-f919-4521-ac55-04c93aef0050",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-42016",
      "description": "CVE-2026-42016: Privilege Escalation in JFrog Artifactory via Token Scope Authorization Validation Bypass",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-42016",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42016"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-42016",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-42016/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--08c936ed-b339-4685-a130-cb3419429bff",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-42249",
      "description": "CVE-2026-42249: Ollama Windows Auto-Updater HTTP Header Path Traversal RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-42249",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42249"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-42249",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-42249/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--eef88695-df93-45ac-abd6-259eba86a8d8",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-42271",
      "description": "CVE-2026-42271: Unauthenticated Remote OS Command Injection in LiteLLM Proxy Test Endpoints",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-42271",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42271"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-42271",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-42271/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--57df4398-58cf-45a5-aa52-015d7b5ce702",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-4372",
      "description": "CVE-2026-4372: Hugging Face Transformers Configuration Injection RCE via Attention Implementation",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-4372",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4372"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-4372",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-4372/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--cc07133b-c2a3-4225-ac8e-af5909986e1a",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-44963",
      "description": "CVE-2026-44963: Remote Code Execution in Veeam Backup & Replication via .NET Remoting ObjRef Deserialization",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-44963",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44963"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-44963",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-44963/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--20bd1572-f7c9-4415-abb8-f68f7c699353",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-45321",
      "description": "CVE-2026-45321: Large-Scale Supply Chain Compromise Across 42 Packages in the TanStack NPM Ecosystem",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-45321",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45321"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-45321",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-45321/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--131b209c-4345-4faf-a1fe-470af0f10a73",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-46850",
      "description": "CVE-2026-46850: Remote Code Execution via Code Injection in MySQL Shell for VS Code",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-46850",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46850"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-46850",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-46850/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--7fed5c15-bb7c-4a72-a497-a56cf94ec5e6",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-46860",
      "description": "CVE-2026-46860: Unauthenticated Remote Administrative Takeover in MySQL Router",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-46860",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46860"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-46860",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-46860/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--51bf065d-1c06-474b-a883-c13f452884eb",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-46861",
      "description": "CVE-2026-46861: Privilege Escalation and Cluster Takeover in MySQL NDB Operator",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-46861",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46861"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-46861",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-46861/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--fbc7c9ee-1012-4579-a598-c67184f5914c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-46870",
      "description": "CVE-2026-46870: Access Control Bypass and Workstation Compromise in MySQL Shell for VS Code",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-46870",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46870"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-46870",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-46870/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--1ca3348f-af09-479b-ae00-af64508cf498",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-47058",
      "description": "CVE-2026-47058: Out-of-Bounds Memory Corruption in Java Scripting DataView Implementation",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-47058",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47058"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-47058",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-47058/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--d0bef6fe-de1d-45d0-a029-04e020ee0639",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-47063",
      "description": "CVE-2026-47063: Existential Forgery and JAR Verification Bypass in Oracle Java SE Libraries",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-47063",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47063"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-47063",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-47063/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--767c22f6-f602-4801-a82d-d54136fa83ce",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-47876",
      "description": "CVE-2026-47876: VMware ESXi VMXNET3 Out-of-Bounds Write Virtual Machine Escape",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-47876",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47876"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-47876",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-47876/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--35d3df09-7ad6-4fea-a666-86169f08d4af",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-48746",
      "description": "CVE-2026-48746: vLLM OpenAI API Authentication Middleware Bypass via ASGI Request Handling Inconsistency",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-48746",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48746"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-48746",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-48746/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--a016a031-9a95-4c4c-a062-524930df739c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-49179",
      "description": "CVE-2026-49179: Windows Active Directory Domain Services Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-49179",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49179"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-49179",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-49179/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--c7660163-8a91-4fda-ac8d-0e0842e7d441",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-49869",
      "description": "CVE-2026-49869: Authentication Bypass to Remote Code Execution in Kestra OSS via Path Suffix Whitelisting",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-49869",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49869"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-49869",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-49869/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--9093bbdb-fb7f-4b66-ae33-36be448c47c6",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-5027",
      "description": "CVE-2026-5027: Langflow Multipart Form Files Path Traversal and Arbitrary File Overwrite RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-5027",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5027"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-5027",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-5027/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--aa71a936-4b82-4d67-a1c4-d38f77180f45",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-50346",
      "description": "CVE-2026-50346: Windows Netlogon RPC Runtime Elevation of Privilege",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-50346",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50346"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-50346",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-50346/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--3ea63f47-8590-47ac-a0d4-9b34d4477523",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-50481",
      "description": "CVE-2026-50481: Azure Active Directory Immutable Data Manipulation Privilege Escalation",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-50481",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50481"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-50481",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-50481/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--4de04d86-7bb3-476f-a9d7-54b7b414affe",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-50500",
      "description": "CVE-2026-50500: Windows Netlogon Secure Channel Use-After-Free Elevation of Privilege",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-50500",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50500"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-50500",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-50500/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--65a85d89-3082-4aea-ae26-d296cb9215a3",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-50522",
      "description": "CVE-2026-50522: Remote Code Execution in Microsoft SharePoint Server via .NET Deserialization",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-50522",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50522"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-50522",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-50522/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--fa8c7f36-aa12-4898-a32c-4dc8cbf0b590",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-52924",
      "description": "CVE-2026-52924: Linux Kernel SCTP Stale COOKIE-ECHO Outqueue Purge Use-After-Free",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-52924",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52924"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-52924",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-52924/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--757b178d-24ee-4575-a3fc-0dc4cde1f854",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-53266",
      "description": "CVE-2026-53266: Linux Kernel Netfilter ebtables SNAT ARP Out-of-Bounds Write & Privilege Escalation",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-53266",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53266"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-53266",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-53266/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--c0939d73-b1b6-4cff-ad65-7f162ed7eb2c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-55040",
      "description": "CVE-2026-55040: Authentication Bypass and Privilege Escalation in Microsoft SharePoint Server via JWT Signature Spoofing",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-55040",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55040"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-55040",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-55040/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--f9329919-ec83-4be3-a69f-2eddef2e30e2",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-57967",
      "description": "CVE-2026-57967: Unauthenticated Remote Session Hijacking via CORE Protocol Reattachment in Apache ActiveMQ Artemis",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-57967",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-57967"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-57967",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-57967/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--5d5fc89c-3438-4fe3-af2b-75abb1733ff4",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-58480",
      "description": "CVE-2026-58480: Blocksy Companion Pro Unauthenticated Arbitrary File Upload Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-58480",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58480"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-58480",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-58480/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--faa251a5-582b-41fd-af10-e5c7dc619a39",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-58644",
      "description": "CVE-2026-58644: Remote Code Execution in Microsoft SharePoint Server via Workflow Event Receiver Deserialization",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-58644",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58644"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-58644",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-58644/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--4719f120-8a07-4027-a687-d2390de0587a",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-58704",
      "description": "CVE-2026-58704: Zero-Click Adjacent Privilege Escalation in Google Pixel Cellular Modem",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-58704",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58704"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-58704",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-58704/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--e049f41d-bc19-4e13-a0cb-a1171d2e4c23",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-59310",
      "description": "CVE-2026-59310: Remote Code Execution in VMware vCenter Server via Syslog Service Directory Traversal",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-59310",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59310"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-59310",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-59310/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--e5ee0e7d-b848-4ca2-aeea-f13e8e8f8f3d",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-61308",
      "description": "CVE-2026-61308: Information Disclosure Across Boundaries via HTTP Networking in Java SE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-61308",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61308"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-61308",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-61308/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--01399585-5d2b-467f-af5e-46806dbfa6bb",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-62574",
      "description": "CVE-2026-62574: Local Privilege Escalation via Install Component in Oracle Java SE and GraalVM",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-62574",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62574"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-62574",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-62574/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--42a16071-84ef-41a1-ac91-bb8a579f449f",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-62785",
      "description": "CVE-2026-62785: Windows LDAP Service Remote Code Execution on Domain Controllers",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-62785",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62785"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-62785",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-62785/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--90c422e5-b5c0-446a-af99-af9276d95f8d",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-62818",
      "description": "CVE-2026-62818: Windows Active Directory Certificate Services (AD CS) Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-62818",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62818"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-62818",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-62818/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--909dd50b-a935-4cbe-a3bb-a0598f67f415",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-63030",
      "description": "CVE-2026-63030: WordPress Core REST API Batch Route Confusion to Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-63030",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63030"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-63030",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-63030/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--5a837c68-e38f-49ec-a95a-9cb082e6b3be",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-63077",
      "description": "CVE-2026-63077: Authentication Bypass to Remote Code Execution in JetBrains TeamCity via Agent Polling Protocol",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-63077",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63077"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-63077",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-63077/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--68e80682-4e7e-4985-aa41-ae3a3b8cbaee",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-64268",
      "description": "CVE-2026-64268: Linux Kernel Soft-iWARP (siw) RDMA Read Response Out-of-Bounds Write",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-64268",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64268"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-64268",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-64268/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--bfb22645-ae8e-451e-aba0-d1ebff3803ba",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-64849",
      "description": "CVE-2026-64849: Critical Server-Side Request Forgery (SSRF) in MLflow Webhook Notifications",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-64849",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64849"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-64849",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-64849/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--5380131e-d982-4941-ae0a-9afa0aab5e1e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-65182",
      "description": "CVE-2026-65182: Security Constraint Order Bypass and Authorization Failure in Apache Tomcat",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-65182",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65182"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-65182",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-65182/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--acc85d74-8ca1-49e8-ae50-c506f742578d",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-65400",
      "description": "CVE-2026-65400: Unauthenticated Remote Desktop Takeover in Apple macOS Screen Sharing",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-65400",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65400"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-65400",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-65400/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--2c30a17b-aa27-4ff3-aa5b-3bd8ad250724",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-6603",
      "description": "CVE-2026-6603: Remote Code Execution in AgentScope Framework",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-6603",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6603"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-6603",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-6603/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--ec57e103-df0c-4eea-a982-23e99a03cdcc",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-67593",
      "description": "CVE-2026-67593: Apache ActiveMQ Artemis Pre-Authentication Queue Deletion via Openwire",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-67593",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67593"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-67593",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-67593/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--4e09bc4a-77f7-43a3-a3d2-abe0a812441c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-69518",
      "description": "CVE-2026-69518: Windows Remote Desktop Clipboard Virtual Channel Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-69518",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69518"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-69518",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-69518/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--b8417239-4a35-4307-a4c9-6283ef1f0b3e",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-69579",
      "description": "CVE-2026-69579: Windows Message Queuing (MSMQ) Unauthenticated Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-69579",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69579"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-69579",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-69579/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--e0ad8abb-50c3-4336-acd0-cad5acf0c692",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-69595",
      "description": "CVE-2026-69595: Windows Services for NFS ONCRPC XDR Driver Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-69595",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69595"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-69595",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-69595/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--4e28a9d1-8c78-4a0e-ae5e-4e439d360313",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-69603",
      "description": "CVE-2026-69603: Windows Hyper-V Guest-to-Host Escape Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-69603",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69603"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-69603",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-69603/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--bfbbed26-ee26-4a28-ad92-a0ce077f5539",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-69649",
      "description": "CVE-2026-69649: Windows Raw Image Extension Thumbnail Preview Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-69649",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69649"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-69649",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-69649/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--6c582adc-9de0-44fe-ad32-0a891f4eaf03",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-69676",
      "description": "CVE-2026-69676: Windows Kerberos Authentication Bypass & Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-69676",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69676"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-69676",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-69676/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--bc3a7260-8b31-48ab-a391-576275462cd0",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-69730",
      "description": "CVE-2026-69730: Windows DNS Server Unauthenticated Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-69730",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69730"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-69730",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-69730/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--0e3646aa-3338-4533-a45e-b324f6a70038",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-69845",
      "description": "CVE-2026-69845: Windows DHCP Server Heap Buffer Overflow Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-69845",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69845"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-69845",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-69845/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--a196169b-8741-4236-aee5-139eb4b5a730",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-69851",
      "description": "CVE-2026-69851: Microsoft Entra ID Server-Side Request Forgery Privilege Escalation",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-69851",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69851"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-69851",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-69851/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--024f963d-b22b-437e-a9c5-7c017e26514c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-71133",
      "description": "CVE-2026-71133: Unauthenticated Identity Federation Compromise in Oracle Access Manager Authentication Engine",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-71133",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71133"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-71133",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-71133/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--c26adea6-2a24-430f-ac24-3ebd98c66148",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-72979",
      "description": "CVE-2026-72979: Windows DHCP Server Use-After-Free Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-72979",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-72979"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-72979",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-72979/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--8616119d-115d-42ae-a540-f44bc4eeb0ee",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-72982",
      "description": "CVE-2026-72982: Windows Netlogon Unauthenticated Remote Code Execution (Domain Controller Takeover)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-72982",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-72982"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-72982",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-72982/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--4fec3217-1f21-441c-a35d-445ae19be5ba",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-73009",
      "description": "CVE-2026-73009: Windows Secure Socket Tunneling Protocol (SSTP) VPN Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-73009",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73009"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-73009",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-73009/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--675ba791-877d-4b4e-a366-ca5f26c3a868",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-75650",
      "description": "CVE-2026-75650: Unauthenticated Remote Code Execution via",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-75650",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75650"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-75650",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-75650/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--af9ef3b6-6706-45f6-a590-4e5fe39706cf",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-75874",
      "description": "CVE-2026-75874: Mozilla Firefox Critical Sandbox Escape via Remote Settings Client",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-75874",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75874"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-75874",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-75874/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--64a05178-94c0-48c7-a803-ceab4dace0e1",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-76460",
      "description": "CVE-2026-76460: Unauthenticated REST API Authentication Bypass in Cisco Identity Services Engine (ISE)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-76460",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76460"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-76460",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-76460/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--22c29d6e-5289-4be4-a958-5dd9f5ebbc62",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-76461",
      "description": "CVE-2026-76461: Zero-Click Remote Code Execution via AsyncOS Email Parsing SQL Injection in Cisco Secure Email Gateway",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-76461",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76461"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-76461",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-76461/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--0b136faa-93ac-4158-a9ce-61e375b388f6",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-76674",
      "description": "CVE-2026-76674: HPE Aruba EdgeConnect SD-WAN Buffer Overflow System Takeover",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-76674",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76674"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-76674",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-76674/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--6b294404-412c-4076-ae3c-1b60704b7815",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-77254",
      "description": "CVE-2026-77254: mcp-atlassian Missing Authentication on HTTP Transport Endpoint",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-77254",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77254"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-77254",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-77254/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--6afc7ec7-2a44-418b-a1ce-ddd977f13c48",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-77493",
      "description": "CVE-2026-77493: Windows Graphics Component Preview Pane Zero-Click Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-77493",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77493"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-77493",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-77493/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--9867aa0c-598b-4790-aa69-c98811caf65f",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-77521",
      "description": "CVE-2026-77521: MaxKB Enterprise AI Platform SandboxShellBackend Command Injection and Container Breakout",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-77521",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77521"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-77521",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-77521/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--a9d250ad-f2a7-4c30-a23e-31a438f23786",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-78234",
      "description": "CVE-2026-78234: Hawtio Operator OpenShift Service CA Signing Key Theft and Cluster Takeover",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-78234",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78234"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-78234",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-78234/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--f0b17852-f482-484a-aab3-8848f3010482",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-78445",
      "description": "CVE-2026-78445: Windows Services for NFS Memory Corruption Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-78445",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78445"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-78445",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-78445/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--ecbdb46f-c41a-4dfc-a445-39dfbe74b604",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-78509",
      "description": "CVE-2026-78509: Windows Shell Preview Pane Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-78509",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78509"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-78509",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-78509/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--744c2f7d-d95c-4920-a7a8-0d7a97f4c6a2",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-78510",
      "description": "CVE-2026-78510: Microsoft Outlook Reading Pane Zero-Click Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-78510",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78510"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-78510",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-78510/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--5ca56e2c-28c4-4e1f-a77e-33619e8b2a35",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-80083",
      "description": "CVE-2026-80083: Windows Hyper-V Virtual Switch Guest-to-Host Remote Code Execution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-80083",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80083"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-80083",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-80083/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--c6f178c7-5848-4b6f-a821-079084eb46da",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-80351",
      "description": "CVE-2026-80351: Remote Code Execution via Dynamic Maven Configuration Eval Injection in Apache Camel K",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-80351",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80351"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-80351",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-80351/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--02ce2fc5-8f09-410f-ae58-c3c2f2d66b6d",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-80352",
      "description": "CVE-2026-80352: Kubernetes Operator Privilege Escalation via Master Trait YAML Injection in Apache Camel K",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-80352",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80352"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-80352",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-80352/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--b4de5417-a59c-4e4a-a583-0c12149282a4",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-8206",
      "description": "CVE-2026-8206: Kirki Customizer Framework Unauthenticated Privilege Escalation to Account Takeover",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-8206",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8206"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-8206",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-8206/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--2bf67a56-8683-4d11-a493-3ef43c0c51d5",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-82331",
      "description": "CVE-2026-82331: Apache BuildStream Tar Plugin Link Resolution and Host File Overwrite",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-82331",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82331"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-82331",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-82331/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--c36e6af1-2c49-4e23-a2d2-1246320d226c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-83020",
      "description": "CVE-2026-83020: Unauthenticated Remote Code Execution in Oracle Platform Security for Java (OPSS)",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-83020",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83020"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-83020",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-83020/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--141467be-82e5-4564-a53c-405a8c6b4d09",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-83021",
      "description": "CVE-2026-83021: Unauthenticated Remote Code Execution in Oracle WebLogic Server Web Container",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-83021",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83021"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-83021",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-83021/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--35e74ba7-339f-4f03-ad3b-9b3898dbc7b7",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-83059",
      "description": "CVE-2026-83059: Unauthenticated Remote Compromise in Oracle Internet Directory (OID) LDAP Server",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-83059",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83059"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-83059",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-83059/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--7c02a693-9316-4438-a4a2-629a63b7c3ad",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-83099",
      "description": "CVE-2026-83099: Unauthenticated Remote Code Execution in Oracle Forms Services",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-83099",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83099"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-83099",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-83099/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--65563cd0-30f3-427a-a4bb-b5ecd7bb7bf2",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-83527",
      "description": "CVE-2026-83527: Unauthenticated Administrative Authentication Bypass in Ivanti Sentry via Alternate Routing Path",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-83527",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83527"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-83527",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-83527/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--90e67ebe-00fb-4e3a-adae-4c67bc025aba",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-83548",
      "description": "CVE-2026-83548: SonicWall SMA1000 Remote Unauthenticated SSRF & Edge Gateway Takeover",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-83548",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83548"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-83548",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-83548/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--ee35cc2c-93c9-4c50-a198-d5aa7a5a95d3",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-8452",
      "description": "CVE-2026-8452: Unauthenticated Heap Buffer Overflow to Root RCE in NetScaler ADC & Gateway via SAML Canonicalization",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-8452",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8452"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-8452",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-8452/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--541b3992-acf1-46e0-a6aa-d75fcefbf31c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-84779",
      "description": "CVE-2026-84779: WordPress Agentimus MCP Endpoint Broken Access Control",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-84779",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84779"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-84779",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-84779/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--4fe6bbbf-a1ed-4444-a4aa-6ddc29b69b81",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-84869",
      "description": "CVE-2026-84869: Unrestricted File Transfer and Remote Execution in ConnectWise ScreenConnect Client via Active Session Authorization Bypass",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-84869",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84869"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-84869",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-84869/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--ecf701c2-b8ce-4610-a3a7-fd40f79df003",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-84939",
      "description": "CVE-2026-84939: Path Traversal to Remote Template Injection and Code Execution via Malformed Locale in Apache FreeMarker",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-84939",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84939"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-84939",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-84939/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--8e4a8d9a-110c-4df1-a709-3b6ef1fa4aa2",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-85046",
      "description": "CVE-2026-85046: Google Chromium V8 Maglev/TurboFan Type Confusion Zero-Day",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-85046",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85046"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-85046",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-85046/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--c090e06e-1f90-46c0-aac3-03747c6a82a9",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-85165",
      "description": "CVE-2026-85165: n8n Expression Sandbox Escape via Prototype Resolution",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-85165",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85165"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-85165",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-85165/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--625b0634-42f6-4630-a7df-3892789e9b96",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-85654",
      "description": "CVE-2026-85654: awslabs dynamodb-mcp-server CDK Generator Template Injection RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-85654",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85654"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-85654",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-85654/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--9d1b6e59-6ebb-4eb1-a96b-64f3bf3bf1ba",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-85706",
      "description": "CVE-2026-85706: Unauthenticated Path Traversal to Arbitrary File Read in GitLab CE/EE Repository Commits API",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-85706",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85706"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-85706",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-85706/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--1a4e5289-9690-47a6-a4b3-97d363ef700b",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-86218",
      "description": "CVE-2026-86218: Pre-Authentication Remote Code Execution via Static Code Injection in N-able N-central",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-86218",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86218"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-86218",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-86218/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--c1ce26e8-fd2a-4e99-abb1-56daf2ec3a99",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-86297",
      "description": "CVE-2026-86297: D-Link DIR-605 L2TP Parser Off-by-One Buffer Overflow",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-86297",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86297"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-86297",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-86297/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--5474f3b9-f9ab-4eef-ad45-196cc7f63193",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-86510",
      "description": "CVE-2026-86510: D-Link DIR-822A L2TP Parser Out-of-Bounds Write RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-86510",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86510"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-86510",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-86510/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--815c8bac-e5c4-42fc-a933-810e16a410d5",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-87230",
      "description": "CVE-2026-87230: Unauthenticated Remote Financial Ledger Compromise in Oracle Hyperion Financial Management",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-87230",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87230"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-87230",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-87230/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--7e310adc-d229-4811-a785-1c5ff4ba8914",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-87911",
      "description": "CVE-2026-87911: awslabs postgres-mcp-server SQL Parser Desync to Command Injection",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-87911",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87911"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-87911",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-87911/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--ad1265ce-e2c9-4f94-a140-36986451da7b",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-87983",
      "description": "CVE-2026-87983: Mistral Vibe Arbitrary File Read via Quoted Absolute Paths in Auto-Approved Commands",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-87983",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87983"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-87983",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-87983/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--841a893a-8b6a-4f70-a96c-39efdb5e436b",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-87984",
      "description": "CVE-2026-87984: Mistral Vibe Arbitrary File Write via Shell Redirection Target Omission",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-87984",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87984"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-87984",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-87984/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--11ff7c81-b174-4d39-a799-481cc2d3cbfd",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-87985",
      "description": "CVE-2026-87985: Mistral Vibe Arbitrary Remote Code Execution via ANSI-C Quoting in find -exec",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-87985",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87985"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-87985",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-87985/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--f1517580-f022-469c-a95e-ff50a0a1609c",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-87986",
      "description": "CVE-2026-87986: Mistral Vibe Command Injection via Parser Syntax Error Node Bypass",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-87986",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87986"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-87986",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-87986/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--9642af3a-4e09-4747-a555-4149c626605f",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-87987",
      "description": "CVE-2026-87987: Mistral Vibe Remote Code Execution via Environment Variable Assignment Stripping",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-87987",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87987"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-87987",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-87987/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--39871ca1-d251-427a-a959-662f4ca6c4a8",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-87988",
      "description": "CVE-2026-87988: Mistral Vibe Arbitrary Read/Write via Discrepancy Between Auto-Approved Commands and Path Control List",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-87988",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87988"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-87988",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-87988/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--46533786-2a76-4a5a-ab7e-31d6c89da1d0",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-90562",
      "description": "CVE-2026-90562: Authentication Bypass and Administrative Takeover via Low Entropy Password Recovery in LangBot",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-90562",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90562"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-90562",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-90562/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--daa49e61-46e8-4409-a2fa-d6b692ec1d28",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-90692",
      "description": "CVE-2026-90692: D-Link DIR-878 SetDynamicDNSIPv6Settings Stack Overflow RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-90692",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90692"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-90692",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-90692/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--76501d71-d6f4-4fac-aa04-dd453fb24208",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-90693",
      "description": "CVE-2026-90693: D-Link DIR-878 SetWan3Settings Stack-Based Buffer Overflow RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-90693",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90693"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-90693",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-90693/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--39398cec-07b9-4d84-a7ca-8ef8d2857d26",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-90711",
      "description": "CVE-2026-90711: Client IP Address Spoofing and Trust Boundary Bypass via IPv4-Mapped IPv6 CIDR Parsing Flaw in proxy-addr",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-90711",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90711"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-90711",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-90711/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--79fe0cfe-86d6-4ba6-a06e-9e820d029b28",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-90770",
      "description": "CVE-2026-90770: Spug Deployment Platform ping_check OS Command Injection RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-90770",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90770"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-90770",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-90770/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--198187b4-ca29-4171-a843-047799cac47d",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-90777",
      "description": "CVE-2026-90777: Arbitrary Code Execution via Insecure torch.load Checkpoint Deserialization in ESPnet",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-90777",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90777"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-90777",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-90777/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--1780689e-2d87-4dc4-a994-053e89551205",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-90894",
      "description": "CVE-2026-90894: Parallels Desktop ParaShells Virtual Machine Host Escape & LPE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-90894",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90894"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-90894",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-90894/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--2744f301-6978-45d9-a2cc-35edd0ce6e01",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-91843",
      "description": "CVE-2026-91843: Check Point Security Management Server Stack Buffer Overflow RCE",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-91843",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-91843"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-91843",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-91843/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--7450b3b7-bf58-4531-a18a-c5182f91a64f",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-9186",
      "description": "CVE-2026-9186: Langflow Localhost Restriction Bypass Arbitrary IDE mcp.json Overwrite",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-9186",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9186"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-9186",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-9186/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--e30973a3-dcae-43aa-a192-476d55f0dfd4",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-92574",
      "description": "CVE-2026-92574: CRI-O Container Checkpoint-Restore Destination Security Context Bypass",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-92574",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92574"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-92574",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-92574/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--c32a93f7-9d87-446c-a8cc-325cafc1b208",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-93372",
      "description": "CVE-2026-93372: Google Chrome Android WebGL Heap Buffer Overflow GPU Sandbox Escape",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-93372",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93372"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-93372",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-93372/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--cbaedc7d-7998-442a-a953-3592067cbf17",
      "created_by_ref": "identity--72de2c61-6c3d-4736-a8f2-a1ef6fb725d4",
      "created": "2026-09-19T00:00:00.000Z",
      "modified": "2026-09-24T12:24:25.103Z",
      "name": "CVE-2026-9586",
      "description": "CVE-2026-9586: Unauthenticated SQL Injection to Remote Code Execution in Sangoma Switchvox PBX",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-9586",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9586"
        },
        {
          "source_name": "hermes-codex",
          "external_id": "CVE-2026-9586",
          "url": "https://hermes-codex.vercel.app/cve/2026/cve-2026-9586/"
        }
      ],
      "custom_properties": {
        "x_hermes_threat_score": 95,
        "x_hermes_cvss": 9.8
      }
    }
  ]
}