AI system reported to have found 12 new OpenSSL vulnerabilities

THE BRIEF
Schneier on Security reports that an AI system called AISLE was responsible for the original discovery of 12 previously unknown-to-maintainers OpenSSL vulnerabilities disclosed in the project’s January 27, 2026 security release. According to the post, AISLE found and responsibly disclosed all 12 to the OpenSSL team during fall and winter 2025. Ten vulnerabilities received CVE-2025 identifiers and two received CVE-2026 identifiers. The account also says AISLE had already been credited with finding three vulnerabilities in OpenSSL’s fall 2025 release. Taken together, the post says AISLE surfaced 13 of the 14 OpenSSL CVEs assigned in 2025 and 15 across both releases. Schneier describes this as an unusually concentrated result for one research team and an AI-driven one in particular. The excerpt identifies CVE-2025-15467 as a stack buffer overflow in CMS message [truncated in supplied text], but provides no further technical detail about the other findings, affected versions, or remediation requirements.
WHY IT MATTERS
This report highlights a notable shift in vulnerability research: an AI system is described as identifying a large share of OpenSSL CVEs across two releases, rather than producing only theoretical or low-impact results. The supplied account specifically says the findings were responsibly disclosed and included at least one stack buffer overflow, while withholding enough detail to assess severity across the set. For defenders, the story is a reason to track OpenSSL’s January 27 release and understand that AI-assisted discovery may change the volume and concentration of findings reaching security projects.
WHO SHOULD CARE
OpenSSL maintainers, teams responsible for software that uses OpenSSL, vulnerability-management staff, and security researchers should care. The report is especially relevant to people tracking the project’s January 27, 2026 security release, CVE assignments, and the emerging role of AI in vulnerability discovery.
WHAT TO DO NOW
- Review OpenSSL’s January 27, 2026 security release and identify whether internal systems use affected versions.
- Check the CVE-2025 and CVE-2026 identifiers in the release against internal vulnerability inventories.
- Prioritize investigation of CVE-2025-15467, described as a stack buffer overflow in CMS message, using official OpenSSL guidance.
- Document this report as a data point when evaluating future AI-assisted vulnerability research and disclosure activity.