AISLE Discovers 3 Critical Vulnerabilities in FreeBSD

Author

AISLE Research Team

Published

FreeBSD 1

See what AISLE can find and fix autonomously in your own code.

Sovereign AI CybersecurityTalk to Us

When Anthropic announced that Claude Mythos wrote a remote code execution (RCE) exploit for FreeBSD’s NFS server, we wondered if the model had missed something. It turns out it missed quite a bit.

Using AISLE’s multi-model system to analyze the FreeBSD codebase, our autonomous analyzer found multiple critical-severity vulnerabilities, including a two-decades-old RCE vulnerability, a heap buffer overflow, and multiple stack buffer overflows. We also reported a number of bugs, and are still using the AISLE platform to scour for additional vulnerabilities.

FreeBSD is an essential part of the software infrastructure powering modern civilization. It is used by major networking platforms like Cisco, entertainment giants like Netflix, Sony (Playstation) and Nintendo (Switch), as well as NetApp’s storage systems. Thanks to a philosophy of security through simplicity, FreeBSD is widely recognized as one of the world’s most secure operating systems. Its continued defense is vital, and we followed responsible disclosure practices for each vulnerability mentioned in this post.

Each of these vulnerabilities was discovered on April 13th, reported on April 14th, and fixed in the April 29th release. Each of them was disclosed exclusively by AISLE.

The Findings

The remote command execution vulnerability our analyzer found could have been easily exploited by any system on the same local network as the FreeBSD system. First entering the FreeBSD operating system over 20 years ago, the vulnerability we discovered could be exploited by anyone on the same network. After it was identified by AISLE’s analyzer system, it was autonomously evaluated by our triage agents and flagged to our researchers, who verified the security impact. They also verified a remotely triggerable heap buffer overflow in the same functionality.

The same is true of the two stack buffer overflows, each of which was reachable through its own code path. In one case, any local user could exploit the vulnerability by triggering memory corruption in a root process: ping6. In another, a fix that was applied in an older version of FreeBSD had been removed during refactoring.

In all three instances, our autonomous analyzer and triage agents found and investigated the vulnerabilities. After confirming their security impact, Joshua Rogers of AISLE developed a proof of concept and submitted reports to the FreeBSD maintainers. All three vulnerabilities have now been patched.

Given that AI has collapsed the patch window by making it trivially simple for hackers to reverse-engineer security updates, we urge anyone running FreeBSD to update to the latest version.

Securing Software Infrastructure with AISLE

These findings come at an inflection point for AI-powered cybersecurity. It is clear that AI can discover vulnerabilities in highly scrutinized codebases (in fact, security practitioners have known this for years), but an important question remains: do defenders need access to high-powered, expensive models in order to find security issues?

The weight of a growing body of evidence, which includes AISLE’s OpenSSL discoveries (most recently here) as well as original research by AISLE’s Stanislav Fort, suggests a clear answer: no. High-powered, expensive models are certainly exciting, but they can’t match the thoroughness of well-designed cybersecurity systems. Rather than scaling linearly with compute, it seems that security capability is jagged: small models can outperform larger ones at many cyber-relevant tasks. This may be way AISLE matched Mythos in FreeBSD CVE discoveries in April, despite using far cheaper models.

AISLE’s multi-model system has autonomously discovered, triaged, and generated verified fixes for hundreds of security issues severe enough to warrant CVE designation. Yet it is not merely an analyzer: it unifies the complex and time-consuming tasks of triage and remediation so security teams can not only find new vulnerabilities, they can bring their enterprise security backlogs to zero.

Skeptical? See what AISLE can do for you.

Keep reading

More from AISLE

FeaturedResearchAISLE Discovered Six curl CVEs After OpenAI and Anthropic Found ZeroAfter frontier AI systems came up empty, AISLE surfaced six CVEs in curl, one of the world's most audited codebases. Its maintainers patched all six.Stanislav FortSeptember 2, 2026ResearchAISLE Discovers 6 High and Critical CVEs in FFmpegAISLE's AI-native engine found six high and critical CVEs in FFmpeg, including a 9.8 remote heap overflow and a stack overflow that survived 19 years.AISLE Research Team August 27, 2026ResearchAttackers Are Using AI to Find Vulnerabilities in Your Code. Your SAST Was Never Even Looking for ThemCan AI-native code analysis replace SAST, or is it just a complement. Here's what data from real-world results shows.Ondrej VlcekAugust 12, 2026ResearchAISLE Finds 21 Security Issues in FFmpeg, Including 6 New CVEsAISLE uncovered 21 issues in FFmpeg, including 6 new CVEs spanning code execution and out-of-bounds reads. All patched, with commit links inside.AISLE Research Team August 5, 2026ResearchAISLE Discovers a One-Click RCE Vulnerability in Cursor, VS Code, and Google AntigravityLearn how our AI found a one-click RCE vulnerability in 3 code editors: Cursor, VS Code, and Google Antigravity.Stanislav FortJuly 31, 2026ResearchThe Model That Fixes Your Code Might Hack the Linux KernelLearn how easy it is to trojanize a model, and what defenders can do to protect their supply chains from this emerging threat.Patrik MadaJuly 28, 2026PerspectivesThe Economics of Security Vulnerabilities: Why Discovery Is Not CommoditizingIf discovery is cheap, why are people willing to pay more for exploits than ever before? Here's what the market for exploits shows.Ondrej VlcekJuly 23, 2026ResearchAISLE Finds 8 CVEs Across MySQL, MariaDB, and PostgreSQLLearn how AISLE found 8 CVEs in critical databases using autonomous, AI-native analysis and verification.AISLE Research Team July 7, 2026ResearchAISLE Discovers 6 New CVEs in curl, Including the Oldest Issue Ever ReportedAISLE's analyzer discovered 6 new CVEs in curl, more than 2x the nearest AI security platform and including the oldest security issue in the project.AISLE Research Team June 24, 2026