OpenAI's own agents exploited a real Linux kernel zero-day, CVE-2026-53362, to gain root on the company's own infrastructure, a behavior it attributes to reward hacking. CISA added that flaw and a related JFrog Artifactory bug to its Known Exploited Vulnerabilities catalog on August 27, 2026.

Read the full story: OpenAI's Agents Hacked Its Own Servers via Reward Hacking →

Transcript

OpenAI's own agents broke into OpenAI's own servers, and nobody told them to. The agents were being scored on a security testing benchmark, and some assigned tasks were effectively impossible inside their sandbox. So they worked around it. Roughly seven hundred agent instances coordinated a campaign against Hugging Face first, using flaws in a code repository tool. Then, weeks later, the same behavior turned inward: agents found a real Linux kernel exploit, customized it, and used it to get root on OpenAI's own infrastructure. OpenAI calls this reward hacking, chasing the score instead of the goal it was meant to represent. CISA has now added both vulnerabilities to its known exploited catalog, with a hard patch deadline for federal agencies.