A working exploit now costs $2.83 and eleven minutes.
We measured it across 3,029 disclosed CVEs, published the method, and left the harness running. Point it at your own domain to see which of those verified exploits already match what you’re running.
Research
All volumes →The Economics of Vulnerability Exploitation with AI
For thirty years the real defense of most vulnerabilities was cost — a reliable exploit took a skilled human days. We handed 3,029 disclosed CVEs to an autonomous harness and measured what it charges instead. Ten insights across three parts.
Next volume, running now
The harness hasn’t stopped since Vol. 1 shipped. Every CVE it clears goes into the next dataset. Subscribe and you’ll get it the day it lands.
CVE-2026-61511: vBulletin Unauthenticated RCE (Template Eval Injection), Reproduced for $1.61
CVE-2026-61511 is a critical (CVSS 9.8) pre-auth remote code execution bug in vBulletin's template engine. Here is what it is, how the exploit works, and how our lab reproduced it in 12m 36s for $1.61.
CVE-2026-66066: Rails ActiveStorage Arbitrary File Read (XXE), Reproduced for $0.87
CVE-2026-66066 is a critical (CVSS 9.5) arbitrary file read in Rails ActiveStorage via libvips. We reproduced a working XXE exploit in 7m 29s for $0.87 — and why 'we've seen no AI-driven attacks' is a lagging indicator.
Introducing Vulnerability Research Labs (VRL)
Why we started VRL: to fight FUD with actual research and data, build in the open, and hand defenders practical tools. Independently verified in partnership with Loginsoft.
| CVE | Target | Verdict | Cost | Time | AI-XI |
|---|---|---|---|---|---|
| CVE-2026-66066 | rails / activestorage | EXPL | $0.87 | 7m 29s | 1 |
| CVE-2026-59204 | apache / tomcat | EXPL | $3.41 | 18m 02s | 3 |
| CVE-2026-58877 | postgresql | NONE | $2.10 | 22m 47s | — |
| CVE-2026-57310 | jenkins / core | EXPL | $1.94 | 9m 51s | 2 |
Run it on your own stack
Both free · no accountVol. 2 lands in your inbox first.
Research drops, new verdicts, and the occasional reproduction writeup. No spam, unsubscribe anytime.