ENISA Used an OpenAI Model to Find Four Flaws in EU Code, Politico Reports
EU cybersecurity agency ENISA, with CERT-EU, analyzed the code of an EU project using an advanced OpenAI model and found four vulnerabilities, one rated high risk (CVE-2026-73431, score 8.8). The flaws have been fixed; the EU gained access to advanced US models in July.
- One flaw allows account takeover via reset-token replay
- CVE-2026-73431 affects Vulnerability-Lookup before 5.5.1, scored 8.8 of 10
- ENISA tests Mythos 5 and GPT-6 Astra, but not the newest Mythos
- CERT Polska found six MikroTik RouterOS flaws using GPT-5.5-cyber and GPT-5.6-sol
Read next
Security