CVE-2026-#### · published 43 minutes ago

VexedAI watches every CVE that matters and writes the tested, ready-to-paste prompt for it. Drop it into Claude Code, Codex, or any LLM agent — it checks your actual system and hands you remediation steps.

scroll

// live drill

One paste. Full exposure check.

Your agent already has shell access to the machine that matters — yours. VexedAI gives it a battle-tested runbook for the exact CVE, so the check fits your setup, not a generic scanner's guess.

claude — ~/
01

We watch the feed

New CVEs drop constantly; almost none apply to you. We triage for real-world impact — the stacks solo devs and small teams actually run — and skip the noise.

02

We write the runbook

Every alert ships as a tested prompt: correct version checks, config gotchas, edge cases, and the questions a scanner can't ask. Verified before it reaches you.

03

Your agent runs it

Paste it into Claude Code, Codex, or any harness with shell access. Minutes later: exposed or clear, with remediation steps either way.

// the feed

What an alert looks like.

Each entry is severity-triaged and ships with its prompt attached. Try the copy button — this is the whole workflow.

CRITICAL 9.8
CVE-2026-EXMPL1
OpenSSH pre-auth RCE in key exchange
Affects sshd 9.4–9.7 with default config · sample entry
CRITICAL 9.1
CVE-2026-EXMPL2
Rails Active Storage deserialization RCE
Affects Rails 7.2–8.1 apps with proxy mode · sample entry
HIGH 8.2
CVE-2026-EXMPL3
nginx HTTP/3 request smuggling
Affects nginx 1.25–1.27 with quic enabled · sample entry

// sample entries for illustration — real alerts are tied to real CVE IDs

// what this is not

VexedAI checks exposure — whether a vulnerable version or configuration is present on your systems — and guides remediation. It is not a forensics tool and won't promise you haven't been compromised. Anyone who promises that from a prompt is lying to you.

// where it's headed

Copy/paste today. /vex-check tomorrow.

The waitlist gets the email feed first. Early access members get the native integrations as they land:

  • MCP server — your agent pulls the latest runbooks itself. New CVE drops, your next session already knows about it.
  • /vex-check command — one slash command in Claude Code runs the newest checks against the box you're on.
  • Stack profiles — tell us you run Rails + Postgres + nginx on Docker, and only hear about CVEs that can actually touch you.
$ /vex-check
⏺ Fetching runbooks — 2 new since last session…
✗ CVE-2026-EXMPL2 — rails 8.0.1 in ~/apps/api
✓ CVE-2026-EXMPL3 — nginx 1.24, quic off
→ 1 exposure found. Remediation plan ready.

// early access

The next big CVE is coming.
Have the prompt ready.

Join the waitlist and get the drill-ready feed the moment it opens — plus first crack at the MCP server and /vex-check.

No spam. Only the CVEs worth your time.