Vulnerabilities.ai™ — AI-Era Vulnerability Intelligence & Solutions Hub
The AI Era of Vulnerability Management

AI is finding your vulnerabilities. It's also become one. Get ahead of both.

Tell us where your gaps are and we'll connect you with a vetted partner — or start with the free readiness assessment. Vulnerabilities.ai™ is the independent hub tracking AI-discovered vulnerabilities, the eight categories of risk in the AI you've deployed, and the BOD 26-04, FedRAMP, and EU AI Act deadlines already in force.

Get Matched with a Partner → Take the Free AI Security Assessment →
202
Project Glasswing findings actually fixed, of 2,736 on its public ledger and 26,153 claimed — see Ledger for the full picture
48,000+
CVEs documented in 2025, up 20% year over year
26%
KEV vulnerabilities fully remediated in 2025 (2026 Verizon DBIR)
72hrs
Maximum remediation window for critical-tier findings under CISA BOD 26-04
What We Cover

The full map of AI-era vulnerability risk.

Regulated Vulnerability Management

CISA BOD 26-04 replaced CVSS-based patching with a four-variable risk model and 72-hour critical timelines. FedRAMP made aligned rules mandatory by December 7, 2026 — with certification revocation after March 7, 2027. Our compliance hubs give agencies and cloud providers the practitioner-grade guidance the directives themselves don't.

AI-Discovered Vulnerability Response

The vulnerabilities found through Project Glasswing are moving through coordinated disclosure now — unevenly, and slower than the headline numbers suggest. They'll surface as CVEs and emergency patches in software you run — and no one is tracking them for the general market. We are. Ledger connects frontier-AI findings to the remediation obligations they trigger.

Security for AI

78% of enterprise security leaders now hold a dedicated "security for AI" budget, yet 91% rate their AI security maturity as early-stage (Felicis, spring 2026). Eight AI-specific asset classes — from agent identities to training data to the AI-generated code already in your repos — mapped to the problems CISOs actually name.

What Changed

Discovery is industrialized. Remediation is the bottleneck. Access is gated.

In April 2026, Anthropic's Claude Mythos Preview demonstrated that frontier AI can autonomously discover zero-day vulnerabilities — including a 27-year-old flaw in OpenBSD's TCP stack — for less than the cost of a nice dinner. Within weeks, Project Glasswing partners had surfaced tens of thousands of candidate findings — though the verified, published disclosure count has settled at a fraction of that, a gap Ledger tracks in detail. Anthropic itself now says the bottleneck in cybersecurity is no longer finding vulnerabilities, but verifying, disclosing, and patching them.

The industry's response arrived first as gated coalitions, and is now starting to widen. Project Glasswing began with roughly 200 vetted organizations; Mythos-class capability is now also reaching Enterprise customers through Claude Security and an expanding Cyber Verification Program. CrowdStrike's Project QuiltWorks started as an enterprise-only, Falcon-platform offering and extended to SMBs in August through seven channel partners. Coverage is genuinely growing — but it's still growing toward the organizations best positioned to notice and act on it first.

Everyone else — the mid-market, the FedRAMP ISV ecosystem, agencies under BOD 26-04 deadlines, the companies whose software is being scanned whether they know it or not — needs an independent place to understand what's coming, what's required, and who can actually help. That's what this site is.

Start Here

Where does your AI security posture actually stand?

Our free self-assessment takes five minutes and maps your organization against the frameworks that matter: NIST AI RMF, MITRE ATLAS, BOD 26-04's four-variable model, and the agent-governance controls CISOs cite as their biggest gap. You get a scored readiness report with specific gaps identified — no sales call required to see your results.

Free Diagnostic · 12 Questions

Two domains. A 0–100 score. Your top three gaps, mapped to the solutions that close them.

Take the Assessment — Free →
No vendor sponsorship influences assessment scoring. Your results are yours.
Key Deadlines

The compliance clock, at a glance.

AUGUST 7, 2026
{{ d1 }}
FCEB agency policy deadline

BOD 26-04 · all agencies must have risk-tiered remediation policies in place.

DECEMBER 7, 2026
{{ d2 }}
FedRAMP VDR/VER mandatory adoption

All FedRAMP-certified cloud service offerings must comply.

MARCH 7, 2027
{{ d3 }}
FedRAMP Certification revocation begins

Corrective action plans must be active before this date — not submitted on it.

DECEMBER 2, 2027
{{ d4 }}
EU AI Act high-risk obligations

Annex III standalone systems, as deferred by the Digital Omnibus.

Ledger

Who's finding vulnerabilities with AI — and whether they're keeping their word.

Five programs — Project Glasswing, Project QuiltWorks, Daybreak, Gold Eagle, and the open-source coordination efforts around them — are scanning the world's software with frontier models. Ledger profiles each one, tracks the disclosures we've verified, and follows the open questions: whether Glasswing's disclosure ledger is keeping pace with its own deadlines, and whether faster discovery is actually closing the remediation gap.

Get Help

Get matched with a vetted partner.

For Security Teams
Tell us where your gaps are.

A short qualification form — your biggest current gap, what would actually be useful, and how you're covered today. We'll connect you with a vetted partner. Takes under a minute.

Get Matched with a Partner →
For Solution Providers
Distribute the assessment. Build the benchmark.

We're building the independent readiness benchmark for BOD 26-04 and AI-era vulnerability response. Share the free assessment with your customers and prospects — a newsletter link, a LinkedIn post, a slide in a QBR. In return: early access to aggregate benchmark data, acknowledgment as a founding distribution partner in the report's methodology section, and first position in your marketplace category. Commission terms unchanged.

Apply as a Founding Partner →

Independent by design.

We don't sell scanners, platforms, or remediation services. We track the landscape, maintain intelligence built on public authoritative sources, and curate the solution ecosystem — including the organizations still waiting on access as these coalitions slowly widen. Basic marketplace listings are free because the full landscape should be visible, not just the vendors with the largest budgets.

About Vulnerabilities.ai™ →