CVE Tools

Anthropics

7 CVEs tracked since 2026. Since Feb 2026, none of them reached CISA KEV.

Anthropics CVEs per month

Feb 2026 to Feb 2026. Point at a month, or focus the strip and use the arrow keys.
Anthropics CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2026-0270

Products

The products that kept showing up in Anthropics's monthly top three, with their CVEs summed over those months.

  1. Claude-code71 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Anthropics.

  1. CVE-2026-47751Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration—
  2. CVE-2026-55407Buffa: Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation—
  3. CVE-2026-55406Buffa: Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref—
  4. CVE-2026-55607Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution8.8
  5. CVE-2026-46406Claude Code: Insecure Temporary File in /copy Command Enables Response Disclosure and Symlink-Based File Write6.1
  6. CVE-2026-54316Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch9.1
  7. CVE-2026-44470Claude Desktop: Local Privilege Escalation via Directory Junction in CoworkVMService7.8
  8. CVE-2026-44467Claude Desktop: SSH Host Key Verification Bypass Allows Man-in-the-Middle Attack on Remote Sessions6.8
  9. CVE-2026-40068Claude Code arbitrary code execution via git worktree commondir trust dialog bypass8.8
  10. CVE-2026-41686Claude SDK for TypeScript has Insecure Default File Permissions in Local Filesystem Memory Tool4.4
  11. CVE-2026-39861Claude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside Workspace10.0
  12. CVE-2026-35603Claude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on Windows7.3
  13. CVE-2026-34451Claude SDK for TypeScript: Memory Tool Path Validation Allows Sandbox Escape to Sibling Directories5.4
  14. CVE-2026-34450Claude SDK for Python: Insecure Default File Permissions in Local Filesystem Memory Tool4.4
  15. CVE-2026-34452Claude SDK for Python: Memory Tool Path Validation Race Condition Allows Sandbox Escape5.3

The record

Peak rank
#140 in Feb 2026
Busiest month shown
Feb 2026, 7 CVEs
Months with a KEV entry
0 since Feb 2026
Monthly snapshots
1 since 2026
Anthropics's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store