Our four biggest vulnerabilities: billing trust, the now-closed SpaceX acquisition and two RCE disclosures (DuneSlide, patched; Mindgard's git.exe flaw, fixed quietly with no advisory or CVE yet). Have answers ready.
The $60B SpaceX deal became effective August 14, 2026, per Cursor's own announcement. The 2025 pricing blow-ups still sting. DuneSlide RCE is patched in Cursor 3.0. Mindgard's git.exe auto-executes on Windows with no click; Cursor shipped a fix July 13 but has no advisory or CVE yet.
Reliability on ambiguous work is where we win, and Cognition says so itself.
Their own 2025 review admits Devin 'can't independently tackle an ambiguous coding project end-to-end' and degrades when requirements change mid-task; independent testing found low real-world completion. Cursor's human-in-the-loop catches errors at every step, not only at PR time.
We bring roughly 2x the revenue and a vastly larger installed base.
Cursor's ~$2B ARR is about 2x Cognition's run-rate, which has grown to approaching $1 billion, and Cursor still sits in more than half the Fortune 500, a switching-cost moat Devin has to overcome account by account.
You see the spend before the invoice does.
Cursor's Teams pricing gives every seat two separate included-usage pools, one for first-party Composer and Auto models and one for third-party API usage, so admins can tell exactly where the money goes. A real-time dashboard splits usage by pool, and rebuilt spend alerts fire on dollar thresholds over Slack or email, so budget owners set their own ceilings and get warned well before a bill lands.
Expand section · 5 moreCollapse section▾
Cognition is in early talks for a new funding round that could value it at $40 billion or more, up more than 50% from the $26B Series D it closed in May 2026, per Bloomberg. A raise at that level would put Cognition above the $29.3B private valuation Cursor held before the SpaceX deal. The talks are early, and the company may not raise or may seek different terms.
Expand section · 9 moreCollapse section▾
Cognition acquired The Interaction Company, maker of the consumer texting agent Poke, in a deal valuing it in the low nine figures, announced July 23, 2026. Cognition plans to fold Poke's personality and orchestration into Devin: co-founder Marvin von Hagen told TechCrunch that Poke could run multiple Devin pull requests at once and give Devin memory that persists across sessions. Poke is a consumer messaging assistant used for travel, scheduling and email, so it does not compete with Cursor's coding product today.
On July 8, 2026 Cognition launched SWE-1.7, its own coding model that it says reaches frontier-level quality at a fraction of the cost: about $1.97 per task on its FrontierCode benchmark, running at 1000 tokens/sec on Cerebras inside Devin (Web, Desktop and CLI). On third-party benchmarks it trails Opus 4.8 and GPT-5.5 by a few points (42.3% on FrontierCode 1.1 vs 46.5% and 43.0%; 81.5% on Terminal-Bench 2.1) yet beats GPT-5.5 on SWE-Bench Multilingual (77.8% to 76.8%), and it far outscores Cursor's own Composer 2.5 (25.6% on FrontierCode). SWE-1.7 runs only inside Devin and is not sold as an API.
On July 1, 2026 Cognition launched Devin Security Swarm, an autonomous product that finds, validates and remediates code vulnerabilities, available to enterprise customers globally on day one. Cognition's own benchmark of 50 real-world GitHub Security Advisories says Devin caught 36 (72% recall) at 30% lower cost per finding than the next most accurate tool, and its product page ranks Cursor's security scanning last at 26% recall. This is a Cognition-run benchmark in a category adjacent to core coding, and the product ships with no customer references yet.
Cognition shipped Devin Fusion, a multi-model harness it says cuts cost 35% while holding frontier performance: prep the cost rebuttal. On June 29, 2026 Cognition released Devin Fusion in preview, a 'sidekick' setup that runs a cheaper model in parallel with a frontier model and delegates execution to it while the frontier model plans and reviews. Cognition claims a 35% cost cut (41% with its Fable 5 model) on its own FrontierCode benchmark while matching frontier quality. It is preview-only and the numbers are company-stated on a Cognition-built benchmark, so treat the figure as unverified.
June 4, 2026: Cognition launched an 'AI Productivity Guarantee' for enterprise customers: if Devin delivers less engineering value than the customer pays for, Cognition will fund usage until it does, up to $10M. So what for Cursor: it signals enterprise buyers are pushing back on AI ROI claims. Bring measurable-lift proof points to every enterprise deal rather than competing on a financial backstop.
June 2, 2026: Cognition retired the Windsurf brand, relaunching it as 'Devin Desktop' and deprecating the Cascade local agent (hard sunset July 1, 2026) in favor of a Rust-rewritten 'Devin Local.' So what for Cursor: every Windsurf/Cascade user faces a forced migration before July 1, a concrete, time-boxed churn window to target.
May 27, 2026: Cognition closed a $1B+ Series D at a $26B post-money valuation (led by Lux Capital, General Catalyst, 8VC), 2.5x its valuation eight months prior. So what for Cursor: Cognition is well-capitalized for a sustained enterprise push and won't be outspent on GTM. Compete on product fit, not on who has more runway.
April 14, 2026: Cognition restructured Devin's self-serve pricing, retiring the no-minimum Core plan and starting to charge for previously-free products (Ask Devin, DeepWiki, Devin Review); it conceded the change hits lighter users. So what for Cursor: price-sensitive lighter Devin users got pushed to a higher floor, a defection trigger to mine.
August 2025: three weeks after acquiring Windsurf, Cognition laid off 30 staff and offered buyouts to the ~200 remaining; CEO Scott Wu told staff 'We don't believe in work-life balance.' So what for Cursor: raise integration and talent-retention risk with enterprises weighing Devin Desktop continuity: the team that built the IDE was largely cleared out.
Cognition still positions itself as cloud-agent vs local-agent, arguing a local agent's 'ceiling is your attention' and stops when you close your laptop. That line no longer holds against Cursor: since June 29, 2026 Cursor's iOS app lets developers launch always-on cloud agents and steer local Remote Control agents from their phone, then review diffs and merge PRs on the go.
Expand section · 4 moreCollapse section▾
Cognition brands Devin as 'the first AI software engineer' and frames cloud agents as the fastest-growing way to build software (the company's own claim).
Cognition still markets itself as an independent, model-agnostic 'agent lab' that routes tasks across all major foundation models, an implicit contrast with Cursor's model dependence (the company's own claim). But on July 8, 2026 it shipped its own in-house model, SWE-1.7, sold only inside Devin and not offered as an API, adding a proprietary model to the same portfolio it says stays neutral. Cursor now routes across models too: Cursor Router, launched July 22, 2026, classifies every request and sends it to the best-suited model across desktop, web, iOS, CLI and the SDK, closing the gap Cognition's positioning claimed as its own.
Industry analysis frames the AI-coding market as a split bet: IDE-first (keep the engineer in the loop: Cursor) vs agent-first (delegate whole tasks to an autonomous agent: Devin). Useful framing because it lets a Cursor rep define the axis of the comparison on our terms.
Grok 4.5 is the first model Cursor has built for more than software engineering, aimed at long-running work across data science, finance, legal work and other knowledge work in addition to coding. It is live now across desktop, web, iOS, CLI and the SDK, broadening Cursor's pitch from a coding tool to a platform for knowledge work generally.
Devin's self-serve pricing (post-April 2026): Free; Pro $20/mo; Max $200/mo; and Teams at usage-based pricing with an $80/month minimum, plus custom Enterprise. The $80 base plus per-seat cost makes small-team adoption structurally pricier than Cursor's per-seat Teams plan.
Expand section · 4 moreCollapse section▾
Cursor's Teams pricing keeps Standard at $32/seat/mo annual ($40 monthly) and Premium at $96/seat/mo annual ($120 monthly, 5x the usage at 3x the cost), and now splits every seat into two usage pools, one for first-party Composer and Auto models, one for third-party API calls, with a real-time dashboard split by pool and dollar-threshold spend alerts over Slack or email. There's still no flat team base fee, undercutting Cognition's $80 base plus per-seat Teams structure for smaller teams.
Cursor's individual tiers run Hobby (free), Pro $20/mo, and Ultra $200/mo (20x Pro usage), matching Devin's $20 entry and $200 power tier on headline price while keeping the engineer in the loop.
On July 8, 2026 Cursor released Grok 4.5, trained jointly with SpaceXAI, priced at $2 per million input tokens and $6 per million output tokens, with a faster variant at $4 per million input tokens and $18 per million output tokens. It is included in individual and team plans today, with double usage for the first week, and Composer 2.5 remains available alongside it.
Cursor Router is on by default for Teams plans, and enterprise admins turn it on from the dashboard with per-team controls, mode restrictions and model allow/block lists (Grok 4.5 cannot be excluded from routing). Balance and Intelligence modes bill at the routed model's rate rather than a flat price: Balance runs $4.63 per commit and Intelligence $6.76, versus $7.34 for Opus 4.8 and $12.69 for Fable 5.
Competitive Battlecard9 across 3 zones›
Reliability on ambiguous work is where we win, and Cognition says so itself.
Best for Technical evaluatorTheir own 2025 review admits Devin 'can't independently tackle an ambiguous coding project end-to-end' and degrades when requirements change mid-task; independent testing found low real-world completion. Cursor's human-in-the-loop catches errors at every step, not only at PR time.
Expand · 4 moreCollapse▾
We bring roughly 2x the revenue and a vastly larger installed base.
Best for Economic buyerCursor's ~$2B ARR is about 2x Cognition's run-rate, which has grown to approaching $1 billion, and Cursor still sits in more than half the Fortune 500, a switching-cost moat Devin has to overcome account by account.
You see the spend before the invoice does.
Best for Economic buyerCursor's Teams pricing gives every seat two separate included-usage pools, one for first-party Composer and Auto models and one for third-party API usage, so admins can tell exactly where the money goes. A real-time dashboard splits usage by pool, and rebuilt spend alerts fire on dollar thresholds over Slack or email, so budget owners set their own ceilings and get warned well before a bill lands.
Cursor now ships its own frontier model, priced to beat lock-in.
Best for Eng-led championGrok 4.5, released July 8, 2026 and trained jointly with SpaceXAI, runs across Cursor's desktop, web, iOS, CLI and SDK, priced at $2 per million input tokens and $6 per million output tokens (a faster variant at $4 input and $18 output), and sits alongside Composer 2.5 rather than replacing it. Devin's answer, SWE-1.7, only runs inside Devin and is not sold as an API, so teams building multi-surface workflows have nowhere to take it.
Cursor Router cuts cost per commit without cutting quality.
Best for Economic buyerCursor's per-request classifier picks the right model for each task instead of defaulting to one daily-driver model for everything, and reports frontier-quality performance at 60% lower cost in online A/B tests across millions of live requests. Three high-volume enterprise accounts with thousands of users saved 30-50% on routed requests versus sending everything to Opus 4.8, with no drop in quality. Cost per commit lands at $4.63 for Balance mode and $6.76 for Intelligence mode, against $7.34 for Opus 4.8 and $12.69 for Fable 5.
Daily developer mindshare is ours, but the lead has stopped widening.
Best for Eng-led championJetBrains' early-2026 survey of 10,000+ developers shows Cursor used at work by 18%, now tied with Claude Code, with growth that 'has slowed down.' Devin-style async agents are still niche for most teams. We have to keep earning this ground.
Expand · 1 moreCollapse▾
"Cursor for devs, Devin for enterprise" is outdated. We compete for the same enterprise deals now.
Best for Exec / top-downSome enterprises run both (Cursor for senior architectural work, Devin for a parallel maintenance fleet), so deals increasingly hinge on governance, predictability and which workflow the team actually lives in.
Devin wins the 'fleet of async agents' use case.
Best for Technical evaluatorWhen the buyer wants to assign well-scoped tickets and review PRs later (migrations, vulnerability fixes, batch maintenance), Devin's sandboxed-VM, run-to-PR model is purpose-built for it, and Cognition has published ROI like Mercedes-Benz compressing an eight-month modernization to eight days. Our background agents are newer and narrower here.
Expand · 1 moreCollapse▾
Devin has marquee regulated and government references we can't fully match.
Best for Security & regulatedCognition names Goldman Sachs, Citi, Mercedes-Benz, Santander, the U.S. Army and U.S. Navy as customers. In defense and big-bank deals, that reference base is a real objection we have to meet head-on.
Sentiment4 signal›
Sentiment: developers repeatedly call Devin's ACU (Agent Compute Unit) billing opaque and hard to budget: 'ACU are entirely too opaque/confusing/complicated' (Hacker News). A recurring friction point across independent reviews, useful when a prospect prizes predictable spend.
Sentiment: independent reviewers report low real-world task completion (one widely-cited hands-on test had Devin succeed on just 3 of 20 tasks), reinforcing a 'doesn't finish the job' perception among developers.
Sentiment: Windsurf users cite instability and eroded trust post-acquisition: its Trustpilot page is 'mostly 1-star reviews, highlighting wasted credits, unstable performance', compounded by roadmap uncertainty under Cognition and the looming Cascade sunset.
Sentiment (our own side, for objection prep): Cursor's 2025 pricing changes drew heavy developer backlash over surprise overages, and a perception persists that agent-mode limits 'tighten quarterly' and real spend runs above the $20 headline. Reps should expect this raised in deals.
Objection Handling7 objections›
"Devin actually ships PRs autonomously while my team sleeps. Cursor just autocompletes."
Raised by Technical evaluatorDevin runs end-to-end to a PR, and Cognition says 89% of its own code is now committed by Devin. But Cursor runs long autonomous background and cloud agents too, and since June 29, 2026 you can launch one from the Cursor iOS app, close your laptop, and come back to review the diff and merge the PR from your phone. The real difference is oversight granularity: Cognition's own review admits Devin struggles on ambiguous, changing work, and Cursor keeps an engineer checking the work at every step, not only at PR time.
"Cognition just raised $1B at $26B. They have all the momentum."
Raised by Economic buyerReal, and they're well-funded, with their run-rate now approaching $1 billion, roughly double what it was in May. But Cursor's roughly $2B ARR is still about 2x that, we're in more than half the Fortune 500, and Cognition's revenue multiple remains a bet on catching up, not evidence they have. Capital doesn't close the product-fit gap on your team's daily work.
"I've seen the Cursor pricing blow-ups. How do I know our budget won't explode?"
Raised by Economic buyerFair: the 2025 rollout was botched and our CEO apologized publicly. Since then we've rebuilt Teams pricing around spend predictability. Every seat now carries separate usage pools for first-party models and third-party API calls, admins get a real-time dashboard split by pool and spend alerts fire on dollar thresholds over Slack or email. For budget certainty, sign an enterprise contract with a capped monthly pool rather than per-seat usage-based plans. Cursor Router now also works to hold spend down directly: it's on by default for Teams plans and reports frontier-quality performance at 60% lower cost in live A/B tests, with early enterprise accounts saving 30-50% on routed requests versus sending everything to Opus 4.8, with no drop in quality.
Updated"SpaceX just closed its acquisition of Cursor. Who am I contracting with now, and does the product I bought change?"
Raised by Security & regulatedA regulatory filing confirms the deal closed effective August 14, 2026, two months after the June 16 merger agreement: Cursor now operates as part of SpaceX's SpaceXAI unit. Cursor's own announcement says the closing also gives it access to SpaceX's GPU fleet to build stronger, more economical models. That answers who you're contracting with. It does not reset what you get today: Cursor still ships its own frontier model, Grok 4.5, across desktop, web, iOS, CLI and SDK, and Cursor Router still cuts cost per commit 30-50% versus a single daily-driver model, backed by roughly $2B in ARR and adoption across more than half the Fortune 500.
"Didn't DuneSlide leave Cursor's sandbox wide open?"
Raised by Security & regulatedCato Networks disclosed two critical RCE flaws in Cursor, DuneSlide (CVE-2026-50548 and CVE-2026-50549), both rated 9.8 CVSS. A zero-click prompt injection delivered through an MCP server request or a poisoned web result could escape the terminal sandbox and reach full RCE on the developer's machine and any connected SaaS workspace, no click needed from the user. Every version before 3.0 was exposed. Both are already patched in Cursor 3.0, released April 2, 2026, and neither source reports any active exploitation.
"Devin's new SWE-1.7 hits frontier quality for $1.97 a task. Why pay more for Cursor?"
Raised by Eng-led championSWE-1.7 is genuinely cheap and it does beat Cursor's own Composer 2.5 on Cognition's FrontierCode benchmark (42.3% to 25.6%). But it still trails Opus 4.8 and GPT-5.5 on that same benchmark and on Terminal-Bench 2.1, and it only runs inside Devin: it is not sold as an API you can build on elsewhere. Cursor Router now routes each request to the model best suited to the task, reporting frontier-quality performance at 60% lower cost in live A/B tests.
"Cursor has an unpatched RCE. Why should we trust it?"
Raised by Security & regulatedMindgard disclosed on July 14, 2026 that a malicious git.exe placed in a repo's project root auto-executes on Windows, no click, prompt or warning, first reported to Cursor in December 2025. Cursor quietly shipped a fix on July 13, one day before that disclosure, but as of July 17 has issued no security advisory, assigned no CVE and not said which version contains the fix, so no customer can confirm their build is patched.
Cut Log6 removed / revised›
as_of = the date the fact is true as-of · verified_on = when grounding last confirmed the exact wording · is_new = a monitor run touched it <48h ago.| subject_key | section | as_of | verified_on | is_new |
|---|---|---|---|---|
| cognition | competitive-position | current | executive_summary | 2026-08-12 | — | false |
| cursor-vs-cognition | revenue-scale-comparison | current | executive_summary | 2026-08-12 | — | false |
| devin | reliability-limitation | current | executive_summary | 2025-11-14 | 2026-06-05 | false |
| cursor | adverse-objections-readiness | current | executive_summary | 2026-08-14 | — | false |
| devin-desktop | windsurf-migration-opening | current | executive_summary | 2026-06-02 | 2026-06-05 | false |
| cognition | valuation | current | snapshot | 2026-05-27 | 2026-06-05 | false |
| cognition | funding-total | current | snapshot | 2026-05-27 | 2026-06-05 | false |
| cognition | revenue-run-rate | current | snapshot | 2026-08-12 | — | false |
| cognition | company-profile | current | snapshot | 2026-02-26 | 2026-06-05 | false |
| cognition | flagship-product | current | snapshot | 2026-06-02 | 2026-06-05 | false |
| cognition | acquisition | windsurf | snapshot | 2025-07-14 | 2026-06-05 | false |
| cognition | productivity-guarantee | launch | recent_moves | 2026-06-04 | 2026-06-05 | false |
| cognition | windsurf-rebrand | launch | recent_moves | 2026-06-02 | 2026-06-05 | false |
| cognition | latest-funding-round | series-d | recent_moves | 2026-05-27 | 2026-06-05 | false |
| cognition | pricing-change | self-serve-2026 | recent_moves | 2026-04-14 | 2026-06-05 | false |
| cognition | windsurf-layoffs | 2025 | recent_moves | 2025-08-05 | 2026-06-05 | false |
| cognition | positioning | cloud-agent-vs-local | positioning | 2026-06-29 | — | false |
| cognition | positioning | first-ai-software-engineer | positioning | 2026-05-27 | 2026-06-05 | false |
| cognition | positioning | model-independence | positioning | 2026-07-22 | — | false |
| ai-coding-market | structural-framing | ide-vs-agent | positioning | 2026-05-29 | 2026-06-05 | false |
| cognition | pricing-model | devin-self-serve | pricing | 2026-04-14 | 2026-06-05 | false |
| cursor | pricing-model | teams-2026 | pricing | 2026-07-01 | — | false |
| cursor | pricing-model | individual-2026 | pricing | 2025-06-16 | 2026-06-05 | false |
| devin | battlecard-strength | autonomous-delegation | battlecard | 2026-05-27 | 2026-06-05 | false |
| devin | battlecard-strength | enterprise-references | battlecard | 2026-05-27 | 2026-06-05 | false |
| cursor-vs-cognition | battlecard-contested | developer-adoption | battlecard | 2026-04-01 | 2026-06-05 | false |
| cursor-vs-cognition | battlecard-contested | enterprise-overlap | battlecard | 2026-05-29 | 2026-06-05 | false |
| devin | battlecard-weakness | reliability | battlecard | 2025-11-14 | 2026-06-05 | false |
| cursor | battlecard-strength | revenue-scale | battlecard | 2026-08-12 | — | false |
| devin | sentiment | pricing-opacity | sentiment | 2026-02-01 | 2026-06-05 | false |
| devin | sentiment | reliability-doubt | sentiment | 2025-07-13 | 2026-06-05 | false |
| windsurf | sentiment | post-acquisition-trust | sentiment | 2026-05-12 | 2026-06-05 | false |
| cursor | sentiment | pricing-backlash | sentiment | 2026-03-18 | 2026-06-05 | false |
| objection | devin-autonomy | competitor-strength | objection_handling | 2026-06-29 | — | false |
| objection | cognition-momentum | competitor-strength | objection_handling | 2026-08-12 | — | false |
| objection | cursor-pricing-trust | cursor-adverse | objection_handling | 2026-07-22 | — | false |
| objection | cursor-spacex-ownership | cursor-adverse | objection_handling | 2026-08-14 | — | true |
| cursor | spacex-acquisition | tracked_facts | 2026-06-16 | 2026-06-16 | false |
| cognition | devin-fusion | launch | recent_moves | 2026-06-29 | 2026-07-02 | false |
| cognition | security-swarm | launch | recent_moves | 2026-07-01 | 2026-07-02 | false |
| cursor | battlecard-strength | spend-predictability | battlecard | 2026-07-01 | — | false |
| cursor | product-launch | ios | tracked_facts | 2026-06-29 | 2026-07-02 | false |
| cursor | security-incident | duneslide-rce | tracked_facts | 2026-07-01 | 2026-07-03 | false |
| cursor | security-objection | duneslide-rce | objection_handling | 2026-07-01 | — | false |
| cognition | swe-1-7-model | launch | recent_moves | 2026-07-08 | 2026-07-09 | false |
| cursor | product-launch | grok-4-5 | tracked_facts | 2026-07-09 | 2026-07-09 | false |
| objection | cognition-swe17-own-model | competitor-strength | objection_handling | 2026-07-22 | — | false |
| cursor | model-pricing | grok-4-5 | pricing | 2026-07-09 | — | false |
| cursor | positioning | beyond-coding-grok | positioning | 2026-07-09 | — | false |
| cursor | battlecard-strength | own-frontier-model | battlecard | 2026-07-09 | — | false |
| cursor | security-incident | mindgard-gitexe-rce | tracked_facts | 2026-07-15 | 2026-07-16 | false |
| cursor | security-objection | mindgard-gitexe-rce | objection_handling | 2026-07-17 | — | false |
| cursor | product-launch | router | tracked_facts | 2026-07-22 | 2026-07-23 | false |
| cursor | pricing-model | router | pricing | 2026-07-22 | — | false |
| cursor | battlecard-strength | router-cost | battlecard | 2026-07-22 | — | false |
| cognition | acquisition | poke | recent_moves | 2026-07-23 | 2026-07-25 | false |
| cursor | spacex-integration-plan | tracked_facts | 2026-08-09 | 2026-08-12 | false |
| cognition | revenue-run-rate | snapshot | 2026-08-12 | 2026-08-15 | false |
| cognition | valuation | recent_moves | 2026-08-12 | 2026-08-15 | false |