Pretty much nothing with minimum viable guardrails (restricted shell into Container into MicroVM into VM + Firewall) which any dev knows how to setup, the fact that most don't is mostly about lazyness/recklessness.
Collision counts are absurd. CVE-2026-43739 has roughly twenty credited researchers; CVE-2026-43816 has nearly as many. And ai attribution getting credit.