Product

Resources

Company

Project Glasswing patches are here.

Thousands of
AI-discovered vulnerabilities.
Patched on your versions.


Glasswing is releasing critical patches for AI-discovered vulnerabilities. Root backports them to your pinned versions, no upgrades required.

Thousands of

AI-discovered vulnerabilities.

Patched on your versions.

Glasswing is releasing critical patches for AI-discovered vulnerabilities. Root backports them to your pinned versions, no upgrades required.

Project Glasswing patches are here.

Live
NEW · CVE-2026-34197 · Apache ActiveMQ ClassicRemote code execution · CVSS 8.8Added to CISA KEV catalog7,500+ exposed servers in the wild13 years hidden9 days from disclosure to active exploitationUncovered by Anthropic's MythosPatched by Root in minutesEvery pinned version backportedApr 17, 2026NEW · CVE-2026-34197 · Apache ActiveMQ ClassicRemote code execution · CVSS 8.8Added to CISA KEV catalog7,500+ exposed servers in the wild13 years hidden9 days from disclosure to active exploitationUncovered by Anthropic's MythosPatched by Root in minutesEvery pinned version backportedApr 17, 2026
BreakingCVE-2026-34197·Apache ActiveMQ Classic·CVSS 8.8 · CISA KEV
Apr 17, 2026

13 years to find. 9 days to exploit. Minutes to patch.

An RCE hid in ActiveMQ Classic for thirteen years. Horizon3.ai traced the chain with Claude in ten minutes. Nine days after disclosure, CISA flagged it as actively exploited. Root backported the fix to every version in the wild.

The Find
13
Years
AI traced the same chain in ten minutes.
The Exploit
9
Days
Public disclosure to CISA KEV catalog.
The Patch
Minutes
Every pinned version backported by Root.

New Threat Advisory

Mythos CVEs are landing.
The fix? Patches, not upgrades.

Anthropic's Mythos has uncovered thousands of critical vulnerabilities across every major OS, browser, and open-source library. The patches are landing — but for most of them, the standard remediation path means upgrading to the latest version. Across dozens of dependencies. All at once.

Root backports every patch to your pinned versions. No upgrades required.

The upgrade trap

Two types of teams right now.

Chasing :latest

Upgrading across 40+ vendors at once.

The standard fix path for most Glasswing CVEs means upgrading to the latest version. You're racing to upgrade dozens of dependencies simultaneously — breaking changes, regression testing, weeks of engineering time. And every patch you ship becomes an exploit blueprint the moment it drops.

Root patches your current version.

Staying pinned

Sitting on known Glasswing CVEs.

You can't upgrade fast enough, so you wait. Meanwhile AI-discovered vulnerabilities sit unpatched in your stack. Time-to-exploit has collapsed to under a day. Scanners flag what you already know, but the upgrade path means breaking things.

Root backports the fix to your pinned version.

Now add AI agents pulling dependencies without checking advisories. Attack surface scales with agent count.

Root is the third option. Glasswing patches, backported to every version you run.

Three steps to safe

Sign up. Point. Patched.

1

Connect your repos

Root inventories every dependency across npm, PyPI, Maven, Go, and 8+ ecosystems.

2

Glasswing CVEs mapped

Every Glasswing vulnerability identified. Every affected package flagged. Nothing missed.

3

Patched. Same version.

Root backports the fix to your pinned version. Not a fork. Not a wrapper. The real thing.

Package

Version

Ecosystem

 

CVEs

Status

openssl

1.1.1w

system

GW-2026-0847

libxml2

2.9.14

system

GW-2026-1203

express

4.18.2

npm

GW-2026-0419

jackson-databind

2.14.2

Maven

GW-2026-0563

pillow

9.5.0

PyPI

GW-2026-0981

Waiting to connect...

Why Root
Fixed open source. Not forked.
We backport security fixes to your pinned versions. Same API. Same functionality. The vulnerability is gone. The dependency is real.
We were sitting on 150 open CVEs with no clean path to fix them. Root patched our pinned versions in place — no upgrades, no breaking changes. What used to eat sprint cycles now runs on autopilot, and our HITRUST posture has never been stronger.
BP
Brendan Putek
Relay Networks

Leading engineering teams trust Root

VERIFIED & COMPLIANT
AICPA SOCDocker Verified PublisherSLSA Level 2
INDUSTRY RECOGNITION
Cyber Security Excellence Awards 2026 WinnerIT-Harvest Cyber 150 Fast Growth Vendor 2026

Glasswing patches are here.
Root backports them.

No upgrades. No breakage.

Try Root free
Talk to a real human