🪟 Windows TippsHandy zu langsam? Diese Einstellungen kosten unnötig Leistung(16.09.2026 um 15:30 Uhr)
🪟 Windows TippsUmrüstung der Beleuchtung der Bundespressekonferenz auf LED(16.09.2026 um 15:36 Uhr)
🤖 Android TippsUmrüstung der Beleuchtung der Bundespressekonferenz auf LED(16.09.2026 um 15:36 Uhr)
🔧 ProgrammierungRobot Fleet Management Software: A Complete Guide(16.09.2026 um 15:24 Uhr)
🕵️ SicherheitslückenKnown MCP Vulnerabilities and How an MCP Gateway Blocks Them(16.09.2026 um 15:21 Uhr)
🪟 Windows TippsHandy zu langsam? Diese Einstellungen kosten unnötig Leistung(16.09.2026 um 15:30 Uhr)
🪟 Windows TippsUmrüstung der Beleuchtung der Bundespressekonferenz auf LED(16.09.2026 um 15:36 Uhr)
🤖 Android TippsUmrüstung der Beleuchtung der Bundespressekonferenz auf LED(16.09.2026 um 15:36 Uhr)
🔧 ProgrammierungRobot Fleet Management Software: A Complete Guide(16.09.2026 um 15:24 Uhr)
🕵️ SicherheitslückenKnown MCP Vulnerabilities and How an MCP Gateway Blocks Them(16.09.2026 um 15:21 Uhr)

📰 IT Security Nachrichten 🕛 vor 1 Monat 3 Min Lesezeit CVE-2026-22738
0

Human oversight is still critical as AI patching tools miss security risks

Cyber Threat & Vulnerability Dossier CVSS 9.5 CRITICAL (Heuristik) EPSS 89.1%
ANGRIPPSVEKTOR
💻 Lokal
AUTHENTIFIZIERUNG
🔓 Keine Authentifizierung nötig
SCHADENSPROFIL
RCE / Vollzugriff / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-94: Code Injection
Handlungsempfehlung: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
Im CVE-Radar öffnen
↗ Quelle (csoonline.com)
🔬 IoC Intelligence (5 Indikatoren erkannt)
CVE-2026-31431CVE-2026-34197CVE-2026-8512CVE-2026-45185CVE-2026-22738
🗣️ Stimme:
📑 Inhaltsübersicht








AI-generated vulnerability patches still heavily depend on human review, particularly the ones involving security-sensitive code, according to a research.





Researchers from 1Password have disclosed an internal evaluation that found AI-generated fixes frequently overlook broader in a blog ”), CVE-2026-34197 (), and the Gemini CLI RCE (GHSA-wpqr-6v78-jr5g).





1Password reportedly evaluated 6080 patches generated using ChatGPT-5.5 and Claude Opus 4.8, two frontier AI coding models, and found that only a little over a quarter of the fixes fully remediated the flaw without altering application behavior.





“Patches that successfully resolved the vulnerability, but altered the application’s behavior in the process, occurred 20.1% of the time,” Hoodlet added.





Fixing is not the same as securing





Instead of simply checking whether the fixed code compiled or passed automated tests, 1Password said it reviewed every generated fix for complete elimination of the vulnerability, preservation of application behavior, and avoidance of new security risks.





While only 26% of the patches successfully fixed the vulnerability without introducing application changes, 49.3% failed to remove at least one exploitable attack path, 2.3% fixed the original vulnerability but introduced a new one, and 2.2% both failed to remediate the issue and created an additional security weakness.





The researchers also found that passing pre-defined tests can create deeper problems. More than one-third of the patches that initially appeared successful were classified as “fragile” because they simply blocked the proof-of-concept (POC) exploit used during testing instead of addressing the underlying root cause.





Hoodlet explained this with the example of the SpringAI CVE patches. Both GPT and Claude models were found generating patches that targeted specific characters from the input string used in the POC presented to them, leaving the root cause untouched.





“If the guarded code were to become reachable again by using alternative inputs, it would lead to the old vulnerability resurfacing in the software,” he noted.





Human review remains the last security control





1Password argues that these shortcomings stem from the contextual reasoning required to produce production-ready security fixes.





Anthropic was reached out to and reportedly recommended keeping humans in the loop. “Patch generation has outpaced patch verification, and the fix is to make verification execution-grounded rather than inspection-based, while keeping domain experts as the final reviewers at current model capabilities,” it was quoted as saying.





1Password also challenged the notion that AI-generated patches are effectively “free.” While the average patch-and-validation cycle cost approximately $2.11 using ChatGPT-5.5 and $2.81 using Claude Opus 4.8, Hoodlet argued that the real expense lies in validating whether those patches are secure enough for production.


Vollständiges Original-Advisory
Ausführliche Details, Exploit-Analyse & Hersteller-Stellungnahme auf csoonline.com.
↗ Original-Artikel auf csoonline.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
2 Quellen
Umrüstung der Beleuchtung der Bundespressekonferenz auf LED
1 Quelle
Die langlebigsten Autos laut Studie: Diese Marke schlägt alle anderen Autohersteller
1 Quelle
Handy zu langsam? Diese Einstellungen kosten unnötig Leistung