Aeon AI Risk Management
Security research, from finding to responsible disclosure.
A static evidence record for security teams, customers, procurement reviewers, and trusted-access programs evaluating Aeon's authorization-first, human-verified defensive research capability.
Questions this page answers
- What does the CyberGuard evidence snapshot cover?
- The page preserves a stable aggregate research and disclosure record, then adds independently verified public advisories and CVEs as maintainers publish fixes.
- What is the difference between 101 findings and 34 disclosure records?
- The 101 figure is validated research output. The 34 figure counts records submitted or advanced through disclosure channels in the historical aggregate. They are different denominators.
- Can a reviewer verify any outcome independently?
- Yes. Four patched records are public: CVE-2026-15015, CVE-2026-70436 / SECURITY-3907, GHSA-vg83-hcp4-5qcc, and GHSA-4rm9-rfp2-j39q. Two have assigned CVEs and two are GitHub Security Advisories without assigned CVEs.
- How does Aeon control advanced cybersecurity capability?
- Aeon uses owned labs, public source code, or written Rules of Engagement; human verification; prior-art and scope gates; minimal proof; code-level remediation; stop conditions; and coordinated disclosure.
- Are private findings named?
- No. Unpatched vendors, private advisory identifiers, exploit details, and embargoed CVEs remain excluded until an authoritative disclosure source publishes them.
Historical aggregate
The aggregate counts remain frozen as a stable research record. Publicly verified advisories and CVEs are added separately.
Validated research output
Aeon's owned-lab research produced 101 human-verified findings across 60 projects, including 4 Critical, 32 High, and 92 access-control findings.
Disclosure activity
Thirty-four records across 33 projects were submitted or advanced through disclosure channels: 25 awaiting triage, 5 confirmed, accepted, or public outcomes, and 4 closed by duplicate or program-scope controls.
Verified public track record
Four coordinated disclosure records are public and patched, including two assigned CVEs and two additional GitHub Security Advisories. Severity ranges from Moderate to Critical.
CVE-2026-15015
A Critical WordPress AI MCP connector authorization bypass was fixed in version 1.6.4.
CVE-2026-70436 / SECURITY-3907
A Medium Jenkins workspace permission-boundary issue was fixed in External Workspace Manager Plugin 1.4.2.
GHSA-vg83-hcp4-5qcc
A Moderate MCP write-authorization boundary issue was fixed in DOMShell 2.0.8. No CVE is assigned.
GHSA-4rm9-rfp2-j39q
A High MCP release-asset project-scope boundary issue was fixed in version 2.1.41. No CVE is assigned.
Bounty status
Wordfence awarded a USD $33 bounty for the Critical WordPress finding. Payment receipt remains pending and the award is not presented as paid.
Trusted-access controls
Research is limited to owned labs, public source code, or written Rules of Engagement, with human verification, prior-art review, minimal proof, stop conditions, code-level fixes, and coordinated publication.
Defensive-use statement
Aeon requests advanced capability only for defensive source review, owned-lab validation, authorized client testing, remediation, and coordinated disclosure, not unrestricted offensive access.
Private evidence boundary
Unpatched vendors, private advisory identifiers, exploit detail, and embargoed CVEs remain excluded until an authoritative source publishes them.
Reviewer contact
Aeon AI Risk Management Corporation can provide a private walkthrough at info@airiskmanagement.ca.