Z.ai Security Disclosure Z.ai, an AI company, disclosed a ledger of 2,436 vulnerabilities, of which 53 are public and 2,383 are undisclosed, with 1,097 rated critical or high, spanning 269 open-source projects and 45 years, with the earliest flaw dating to 1981 and an average latency of 26.6 years before discovery. The disclosure includes recent high-severity vulnerabilities in Linux kernel, Apple Safari, FreeBSD, and GStreamer, highlighting the long-standing security risks in widely used software. 披露账本 2,436 已收录漏洞 53 已公开 2,383 未公开 1,097 严重及高危 269 覆盖开源项目 45 影响时间跨度(年) 这些漏洞的影响时间跨度达 45 年——最早的缺陷可追溯至 1981 年,平均每个漏洞在被发现前已潜伏 26.6 年。 严重程度分布 Critical107High990Medium1,286Low53 漏洞引入年份 19812026 最近收录 查看全部 2,436 项 → /ledger/ 高危 Linux 内核 6lowpan 修复错误路径上 NHC 条目的 use-after-free · Linux CNNVD-2026-18058465潜伏 11 年已公开披露 CNNVD-2026-18058465CVE-2026-64452 高危 WebKit 内存处理缺陷:精心构造的 Web 内容导致意外的进程崩溃 · Apple Safari CNNVD-2026-38995661已公开披露 CNNVD-2026-38995661CVE-2026-43663 高危 FreeBSD ptrace PT SC REMOTE 参数验证缺失:32GiB memmove 下溢 + sysent 越界调用 · FreeBSD CNNVD-202605-4608已公开披露 CNNVD-202605-4608CVE-2026-45253 高危 GStreamer librfb rfb decoder fill rectangle 写入粒度错误导致堆越界写 · GStreamer CNNVD-2026-15357103已公开披露 CNNVD-2026-15357103CVE-2026-59691 中危 SMTP MIME message/rfc822 封装解析状态未重置导致附件文件名与解码内容检测绕过 · Suricata CVE-2026-57229已公开披露 CVE-2026-57229 中危 Joomla com installer 更新列表存储型 XSS(description/detailsurl 未转义) · Joomla CNNVD-2026-49148613已公开披露 CNNVD-2026-49148613CVE-2026-48952