EU Cybersecurity Agency Uses OpenAI to Find Flaws in Code
ENISA and CERT-EU utilized an OpenAI model to identify four vulnerabilities in code for an EU project, as reported by Politico on September 10th, 2026. One of these flaws was deemed high-risk, enabling potential account hijacking by attackers.
The Details:
- Flaw Description: The high-risk flaw, linked to CVE-2026-73431, relates to a software oversight regarding activation and recovery tokens.
- Impact: An attacker could replay a valid token link to reset passwords repeatedly, taking control of an account.
- Resolution: The flaws have since been patched.
Background:
- Access to US Models: The EU gained access to advanced US AI models in July after months of requests, specifically targeting Anthropic’s Mythos model.
- ENISA’s Role: ENISA is part of OpenAI’s trusted access program for cyber models through its Daybreak cyber defense initiative.
- Collaboration: ENISA partnered with CERT-EU and other European entities to leverage OpenAI’s capabilities in security analysis.
Additional Findings:
- Poland’s CERT Discoveries: CERT Polska, Poland’s national response team, also identified six vulnerabilities in MikroTik’s RouterOS using OpenAI’s GPT-5.5-cyber and GPT-5.6-sol models.
- AISLE Review: AISLE conducted an AI code review of ENISA’s new CRA reporting platform.