Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Cognition

Cognition Vendor Cyber Rating & Cyber Score

cognition.ai

Makers of Devin, the first AI software engineer. We are an applied AI lab building end-to-end software agents. We’re building collaborative AI teammates that enable engineers to focus on more interesting problems and empower engineering teams to strive for more ambitious goals.


Cognition A.I CyberSecurity Scoring

Cognition
Company Information
Website:https://www.cognition.ai
Employees number:295
Number of followers:63,706
NAICS:5112
Industry Type:Software Development
Homepage:cognition.ai
Cognition Risk Score (AI oriented)
Between 750 and 799
logo
CognitionSoftware Development
Updated:
17/04/2026
755/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Cognition Global Score (TPRM)
xxxx
logo
CognitionSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

CognitionFair
Current Score
755Baa (FAIR)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
755Before Incident
AUGUST 2026
755Before Incident
JULY 2026
755Before Incident
JUNE 2026
755Before Incident
MAY 2026
755Before Incident
APRIL 2026
755Before Incident
MARCH 2026
755Before Incident
FEBRUARY 2026
755Before Incident
JANUARY 2026
755Before Incident
DECEMBER 2025
755Before Incident
NOVEMBER 2025
754Before Incident
OCTOBER 2025
754Before Incident
JANUARY 2025
755Before Incident
Vulnerability
01 Jan 2025Cognition
Anthropic, Windsurf, LiteLLM and Agent Zero: Critical Vulnerability in Flowise Allows Remote Command Execution via MCP Adapters

Critical MCP Vulnerability Exposes AI Ecosystem to Remote Command Execution

753After Incident
CRITICAL-2
ANTCOGAGELIT1776429692
Critical MCP Vulnerability Exposes AI Ecosystem to Remote Command Execution Security researchers at OX Security have uncovered a systemic design flaw in Anthropic’s Model Context Protocol (MCP), a widely adopted framework for AI agent communication. The vulnerability enables remote command execution (RCE), allowing attackers to fully compromise affected systems. Unlike isolated software bugs, this flaw stems from MCP’s core architecture, making it difficult to mitigate universally. It affects official MCP SDKs across Python, Java, Rust, and TypeScript, with over 150 million downloads tied to MCP-based components. More than 7,000 publicly accessible MCP servers and an estimated 200,000 vulnerable instances worldwide amplify the risk, creating a software supply chain threat for developers integrating MCP into their applications. ### Attack Vectors & Impact The vulnerability enables multiple exploitation methods, including: - Unauthenticated UI injection in AI frameworks - Zero-click prompt injection in AI IDEs like Windsurf and Cursor - Malicious package distribution via marketplace poisoning - Security bypasses in protected environments, such as Flowise, where attackers can execute arbitrary commands, access databases, API keys, and sensitive data ### Affected Tools & CVEs The flaw has led to multiple CVE disclosures across popular AI tools: - GPT Researcher (CVE-2025-65720) - Agent Zero (CVE-2026-30624) - Fay Framework (CVE-2026-30618) - Langchain-Chatchat (CVE-2026-30617) - Jaaz (CVE-2026-33224) - Windsurf (CVE-2026-30615 – zero-click prompt injection) - Upsonic (CVE-2026-30625 – allowlist bypass) Some platforms, including LiteLLM and Bisheng, have released patches, but Anthropic has not altered MCP’s architecture, stating the behavior is "expected." This leaves organizations to implement their own safeguards, such as restricting public access to MCP services, treating inputs as untrusted, and running services in isolated environments. The incident underscores the growing risks in AI supply chains and the need for secure-by-design architectures as AI adoption expands.
INCIDENT DETAILS -
TYPE
Remote Command Execution (RCE)
IMPACT
DatabasesAPI keysSensitive dataAI frameworksAI IDEs (Windsurf, Cursor)Protected environments (Flowise)Operational Impact: Full system compromise, arbitrary command executionBrand Reputation Impact: Potential reputational damage due to supply chain risks
DATA BREACH
DatabasesAPI keysSensitive dataSensitivity Of Data: High

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Cognition ?
?
What was Cognition's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Cognition's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Cognition's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Cognition's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Cognition's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Cognition's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Cognition's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Cognition's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Cognition's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Cognition's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Cognition's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on Cognition's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Cognition ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Cognition's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Cognition Cyber Scoring History | Rankiteo