Researchers working with the FreeBSD project disclosed an AI-assisted security audit that found 15 kernel vulnerabilities, including five local privilege escalation flaws, one bhyve guest-to-host escape, and multiple memory disclosure and denial-of-service issues. The effort was coordinated directly with FreeBSD maintainers, with the researchers saying many reports moved from disclosure to fix within days and that the goal was to surface serious, actionable bugs rather than inflate vulnerability counts.
The researchers also publicly released exploits and AI-generated writeups for three verified local privilege escalation vulnerabilities: CVE-2026-45250, CVE-2026-45253, and CVE-2026-45251. They said their workflow focused on reporting only high- and critical-severity issues, keeping submissions concise, and optionally proposing patches while maintaining direct communication with maintainers; they added that similar AI-assisted auditing is underway for other open-source infrastructure projects.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Researchers conducting an AI-assisted audit said they reported 15 FreeBSD kernel bugs to the FreeBSD team, including five local privilege escalations, one bhyve guest-to-host escape, and several memory disclosure and denial-of-service issues. The reports were coordinated directly with FreeBSD maintainers, and many reportedly moved from disclosure to fix within days.
On 2026-05-28, the researchers published exploits and writeups for three verified local privilege escalation flaws in FreeBSD: CVE-2026-45250, CVE-2026-45253, and CVE-2026-45251. The writeups were described as AI-generated.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.