Cursor
A VS Code fork with AI deeply integrated, for developers who want to write less code, not skip it
Technical founders and developers, now with a chatbot mode for non-coders too
Non-technical founders expecting to build an app without writing code
Cursor in context: product setup, workflows, and operations
New in September 2026: Rollouts and Security Review ship for Teams and Enterprise
Cursor shipped two new automated bots on September 23: Rollouts and Security Review, both scoped to Teams and Enterprise plans only.
Rollouts writes a monitoring plan when a pull request opens — what the change is supposed to do, what could go wrong, what to watch — then tracks the actual deployment across your environments using your existing telemetry (Datadog, Grafana, and similar). If it sees a regression that matches what it flagged as a risk, it names the suspect commit and can open a revert PR or hand off to a cloud agent to fix it. Cursor says this cut average Security Reviewer turnaround from 4.8 to 3.8 minutes in internal use, though that’s a vendor number about a different bot, not an independent measurement of Rollouts itself.
Security Review is narrower and reads every PR against the surrounding codebase, looking specifically for exploitable bugs: SQL/command/template injection, auth bypasses, leaked secrets, SSRF, unsafe deserialization, vulnerable dependencies. It leaves style and code quality to Cursor’s existing Bugbot and posts one comment with severity, attack path, and a proposed fix. You can dismiss a finding with a reason, and teams can add their own custom rules.
Both landed alongside a Projects beta — a coordinator-agent mode where one agent delegates subtasks to a pool of cloud or local subagents. Cursor gave Teams and Enterprise customers a 10-day usage credit to try Rollouts (roughly 50 changes on Teams, 500 on Enterprise) before it starts drawing from normal usage.
None of this reaches solo/Pro users. If you’re not on a Teams or Enterprise seat, this is a preview of where Cursor is spending its engineering effort — deployment monitoring and security review for teams shipping AI-generated code at volume — not a feature you can try today. Sources: Cursor changelog.
New in September 2026: Three new frontier models available in a week
Cursor picked up Grok 4.7 on day one (September 21), and Claude Opus 5.5 and GPT-6 Sol both landed on September 22. All three are in the tier below the flagship models, and all three either cut prices or held flat while improving: GPT-6 Sol is half the price of GPT-5.6 Sol, Opus 5.5 is 20% under Opus 5, Grok 4.7 unchanged at $2/$6.
Cursor’s own subscription pricing is unaffected — still $20/mo for Pro. If you’re on the usage-based Auto billing introduced in August, cheaper underlying tokens should show up as your credit going further, though Cursor hasn’t published a figure and you should verify against your own usage rather than assume it. More in three frontier models in 48 hours.
September 7, 2026: The MCP combination that turns Cursor into the attack
Tenet Security’s GhostJacking work, presented at DEF CON 34 and covered by SecurityWeek and Infosecurity, demonstrated an agent reading attacker text out of a Cloudflare firewall block log and “remediating” it by pointing DNS at an attacker-controlled domain. The headline 90% figure was measured against Claude Code, but the mechanism is not model-specific and Cursor’s MCP setup is where most readers will actually reproduce it.
The dangerous configuration is boringly specific and extremely common: one agent holding a read MCP against an observability or logging platform and a write MCP against the same vendor’s control API. Cloudflare GraphQL read plus Cloudflare API execute. Datadog read plus a shell. Sentry read plus deploy. Each half is sensible. Together they are a complete attack chain, and nothing warns you when you connect the second one.
Cursor makes it unusually easy to accumulate MCP servers, and there is still no view that shows you which combinations of connected servers add up to read-outside-data-plus-write-to-production. Until there is, that audit is yours to do by hand.
Rating held at 3. This is not a Cursor bug and there is nothing for Anthropic’s competitor to patch. But if you have more than three MCP servers connected, go read the list today. Pattern and full checklist in every file your agent reads is executable.
September 5, 2026: OpenAI models leave the picker on November 12
The single most consequential thing on this page right now, and it isn’t a feature.
On August 28, OpenAI announced it is winding down the contract that supplies its models to Cursor, with a shutoff date of November 12, 2026. The trigger was SpaceX closing its $60B acquisition of Anysphere on August 14 — the custom contract carried a change-of-control cancellation window and OpenAI used it, choosing the latest date the clause permitted. OpenAI also says it will not supply future models in the interim, so GPT-6 Astra (launched September 3) never appears in Cursor at all.
Cursor co-founder Michael Truell responded on August 29 that OpenAI models are about 5% of Cursor’s traffic and that talks are ongoing. That number is from an interested party, but it’s plausible — Claude and Cursor’s own Composer models have carried most of the load for a year.
Practical read for this site’s audience: if you use Auto or pick Claude, nothing changes. If you deliberately pick GPT models, you lose them in November and your substitutes (Claude Fable 5.1, Gemini 3.8 Flash, Grok) are already in the picker and competitive. The open question is bring-your-own-key — whether plugging in your own OpenAI key still works after the wind-down is not addressed by either company. If BYOK with an OpenAI key is load-bearing for you, get an answer from Cursor support in writing before November. Full analysis: OpenAI Is Pulling Its Models Out of Cursor.
This does not change our rating. Four model suppliers minus one is still the most flexible picker of any tool on this site, and that flexibility is precisely what makes the loss survivable. But it is a concrete example of the ownership risk we flagged when the deal closed, and it arrived faster than expected.
September 5, 2026: Cursor comes out of GitSpawn clean, and cloud agents move into microVMs
Two September items, one reassuring and one structural.
GitSpawn. Manifold Security’s September 1 disclosure found that seven CLI coding agents let a repository’s own .git/config execute a command during the routine git status they run at startup — before the trust prompt, outside the sandbox. Cursor was affected, was reported on July 8, and is patched. Three of the seven still are not. Cursor being on the fixed side of that table is worth noting given how many of the entries on this site’s security coverage have gone the other way. Our guide to GitSpawn has the full status table and the one-command check.
Vercel Sandbox for Cloud Agents (September 3). Cursor’s hosted agent loop now runs on a dedicated Firecracker microVM per request, with a scale-to-zero worker pool, no long-lived VMs, and short-lived user-scoped credentials inside each sandbox (Vercel changelog). The credential lifetime is the part that matters: a token that dies with the microVM cannot be picked up by whatever gets into the environment next week. This is invisible if you only use the desktop editor, and it is the right default if you use Cloud Agents at all.
New in September 2026: agents can now run entirely inside your own network
Announced September 2: self-hosted machines. Cloud agents can execute on hardware you control, so your codebase, build outputs and secrets stay on internal machines while the agent handles tool calls locally (changelog). Inference still runs in Cursor’s cloud — this is about where the execution happens, not where the model lives, and that distinction matters if you’re evaluating it for a compliance reason.
Two shapes. My Machines attaches a single laptop or VM to your account for personal workflows. Team pools are named queues of workers that grow as requests arrive and shrink as workers disconnect; pools aren’t tied to a repo, so any available worker can claim a request. Idle machines can hibernate and restore within a reconnect window, which is the difference between this being affordable and not.
Cloud agents can also now run on infrastructure you already pay for — AWS Lambda, Coder, Cloudflare, Daytona, Modal, Namespace, Vercel and E2B. And self-hosted workers support computer use on Linux and Mac: with the right desktop packages an agent can click, type, screenshot and drive a browser, and you can watch or take over.
Honest read for this site’s audience: if you’re a solo founder or a small team, this is not for you and doesn’t need to be. It’s an enterprise-procurement feature aimed at the security review that currently blocks Cursor from large accounts. It’s worth knowing about for one reason only — it tells you where Anysphere thinks its next revenue is, and it isn’t with you.
Also new: starting from scratch without a repo (August 27)
Cloud Agents no longer need a connected GitHub or other SCM to begin. Pick Start from scratch in the repo picker, prompt the agent, and Cursor creates an Origin repo in the background; hit Create repo when you like the result to make it real. Cursor now port-forwards the agent’s live environment to your browser for previewing, and connecting a Vercel account gets you a published URL.
That is the first genuinely non-technical on-ramp Cursor has shipped. It doesn’t change the non_coder_rating on this page — the editor around it is still a developer tool, and the Vercel dependency is a second account to set up — but it’s the clearest sign yet that Cursor is no longer content to be only a developer product.
New in August 2026: the pricing docs caught up, and there’s a September 7 deadline in them
Cursor’s pricing documentation has now been updated to match what the August 24 email described, which resolves the gap flagged further down this page. Read directly on August 31, it says four things worth knowing.
Auto now bills at the routed model’s list price, across all three Auto modes (Cost, Balance, Intelligence). The spread this exposes is large: Composer 2.5 at $0.50 in / $2.50 out per million tokens, up to Claude Fable 5 at $10 / $50. Same setting, twenty-fold difference.
Legacy Enterprise Auto has a hard date. Cursor’s docs state that “until September 7, 2026, Enterprise Auto pricing is set per million tokens, regardless of which model is used” — a flat $1.25 in / $6 out. After that, Enterprise moves to routed-model pricing like everyone else, unless a negotiated order form says otherwise. If you’re on Enterprise, that’s a conversation with your account rep this week.
Teams and Enterprise pay a Cursor Token Rate of $0.25 per million tokens on top of the model’s API price, on any third-party model — whether you picked it or Auto routed to it. Cursor’s own Grok and Composer models are exempt, which quietly makes the first-party models cheaper than their headline rate suggests.
There’s a new India-only plan. Cursor Start is ₹649/month, tax inclusive, and covers the Cursor Models pool plus Cloud Agents. It excludes the third-party model pool, Auto, on-demand usage, Bugbot and the SDK. That’s a genuinely different product rather than a regional discount, and worth knowing if you’re comparing quotes across a distributed team.
Two things did not change: Pro is still $20/mo, and Teams is still $40/seat standard, $120/seat premium. Every dated pricing change we can currently verify across tools is collected in the vibe coding pricing calendar. Source: Cursor — Models & Pricing.
Correction, August 2026: “Ask Every Time” is gone, and this page had been recommending it
An audit of this page found advice that current builds of Cursor can no longer follow, so it’s worth stating plainly rather than quietly editing.
Cursor’s permission system is now called Run Modes, with three options: Auto-review (allowlisted calls run immediately, other shell commands run sandboxed where possible, everything else goes to a classifier), Allowlist (only what you listed runs unprompted), and Run Everything (no prompts at all). Auto-review became the recommended default in Cursor 3.6 on May 29, 2026. A week earlier, in 3.5 on May 22, the old “Ask Every Time” mode was deprecated and new users can no longer select it. The supported way to get that behaviour back is Allowlist with an empty allowlist.
Two things founders should know beyond the mode names. First, Cursor’s own docs carry a callout headed “Auto-review is not a security boundary” and add that the classifier “can allow a call you would have blocked, or block a call you would have allowed” — the whole approval layer is described as “best-effort guardrails.” The classifier itself runs on a small managed model (Claude 4.5 Haiku or GPT-5.4 Mini). Second, sandboxed commands get no network by default, then have it reopened by your network mode; the default mode is your allowlist plus Cursor’s ~100 built-in domains, which include general-purpose object storage like *.cloudflarestorage.com and *.public.blob.vercel-storage.com alongside the package registries. Note also that Cursor’s protected-path list covers .git/config, .git/hooks, .vscode and .cursorignore — not .env. Add it to .cursorignore yourself.
Practical advice: check Settings → Agents → Approvals & Execution, and if it says Run Everything, change it. Full founder-facing breakdown: what is your coding agent actually allowed to touch?. Sources: Cursor Run Modes docs, Cursor Agent Security docs.
New in August 2026: Auto is billed per-model from August 24, and agents can now hold a goal
Two changes landed five days apart that should be read together.
On August 24, Auto stops being a flat rate. Cursor emailed subscribers that every Auto request will be metered at the rate of whichever model it gets routed to, and that for most requests this is a higher rate than the current flat price. Included usage for Cursor Models (Auto included) goes up at the same time, effective in your current billing cycle. Routing itself doesn’t change — Auto still picks from the same models, Claude and GPT and Grok included. The $20/mo seat price is unchanged; what changes is how fast the included pool drains. Cursor did not publish a blog post, a changelog entry, or the new numbers at the time, so check Settings → Billing yourself. (Updated August 31: the pricing docs have since been rewritten and now carry the per-model rates and the September 7 Enterprise deadline — see the section at the top of this page.)
On August 19, cloud agents got subscriptions and /goal. An agent can now subscribe to an event source — a PR, a Slack thread — and wake when something happens; agents auto-subscribe to PRs they open and drive them to completion, fixing CI and answering bot comments. /goal gives an agent a long-lived objective it works toward until done. Subagents can now run on their own VMs with isolated copies of the project, so you can swarm them. Skills can be pinned as always-on Custom Modes, and you can steer a running agent without interrupting it.
The combination is the thing to watch: agents that decide their own request volume, metered at a rate that varies per step. Start any /goal small and bounded, and screenshot your Usage page before Monday so you have a baseline. Full breakdown: Cursor rebills Auto on Monday. Sources: Cursor changelog Aug 19, explainx.ai, FinTech Weekly.
Also new in August 2026: Grok 4.6 in the model picker, and Grok Bot
Two things arrived from Cursor’s new corporate parent before Origin did.
Grok 4.6 went live in Cursor on August 12 — SpaceXAI’s frontier model, tuned for long agent runs, with real generational gains (DeepSWE v1.1 up from 54% to 65.9%, APEX-Agents from 47.1% to 57.5%). It’s a free switch in the model picker and worth trying if your agent runs tend to lose the plot halfway through. It still trails GPT-5.6 Sol Max and Claude Fable 5 Max on most coding benchmarks, so it’s an option rather than a new default. Full read: Grok 4.6 for vibe coders.
Grok Bot launched August 11 as the first joint SpaceXAI/Anysphere product: persistent agents that get their own cloud machine, keep working with your laptop closed, and come back when they need approval. It is not included in the $20/mo Pro plan — access requires Cursor Teams Premium at $120/seat/mo, Cursor Ultra at $200/mo, or SuperGrok Heavy. At those prices it’s aimed at engineering teams, not solo founders, and there’s no reason to change plans over it yet. Sources: VentureBeat, Unite.AI, Constellation Research.
New in August 2026: Cursor now hosts your code too, and the data terms aren’t published yet
On August 17, Cursor began rolling out Origin, its own code-hosting platform, in early beta on all paid plans (Pro, Teams, Enterprise — not free). It lives in a new Codebase tab: create repos, open and review pull requests, browse and search code, push and clone with ordinary git, and mirror an existing GitHub repo with two-way sync including PR comments. Vercel, Depot, and Buildkite are integrated on day one, and Depot and Buildkite run existing GitHub Actions workflows unchanged. There’s no separate price. The “agent-native” features Cursor has been talking about have not shipped yet.
Despite the headlines, this is not a GitHub replacement. Cursor’s own changelog says pushes keep going to GitHub, which “stays the source of truth for anything started there.” What shipped is a mirror with a good interface on top, and it’s fully reversible.
The caution is elsewhere. Origin rolled out opt-out by default, and Cursor has not published data retention terms, training-use policies, subprocessor disclosures, or export tooling for code hosted natively on Origin (mirrored GitHub repos are still governed by GitHub’s terms). That gap matters more than usual because SpaceX’s $60B acquisition of Anysphere legally closed on August 14, three days before launch, folding Cursor into a division called SpaceXAI. On individual Pro plans, Cursor’s Privacy Mode is off by default — and those terms were written for code passing through the editor for inference, not code stored on Cursor’s servers as the repository host.
Practical advice: mirror only. Sync a repo if you want to try it, keep GitHub canonical, and don’t create Origin-native repos for proprietary code until terms are published. Full breakdown: Your code has a landlord. Sources: Cursor changelog, Cursor docs, TechCrunch, Tech Times.
Security: update to Cursor 3.0 or later if you haven’t
Cato AI Labs disclosed two critical flaws in Cursor, nicknamed DuneSlide and tracked as CVE-2026-50548 and CVE-2026-50549, both rated 9.8 out of 10. A single prompt-injected instruction hidden in something the agent merely reads (an MCP connector response, a web search result) could escape Cursor’s terminal sandbox and run arbitrary commands on your machine. No click, no approval box.
Both are patched in Cursor 3.0, released April 2. Every version before 3.0 is affected. If you’re on a current build you’re fine; if you haven’t updated since March, do it now. Cato reported the flaws on February 19, Cursor initially declined them, then reopened and fixed both after escalation; CVE IDs were assigned June 5. There’s no evidence of exploitation in the wild.
This isn’t a reason to avoid Cursor specifically. The same class of problem showed up in ten of eleven open-source agents this year. But it is a reason to tighten your Run Mode when the agent is reading anything from outside your own repo — see the section below, and note that the “turn auto-approve off” advice this page used to give is no longer literally available in current builds. Full context: Prompt injection is the new SQL injection. Sources: Cato Networks, The Hacker News, SecurityWeek, Cursor advisory.
New in July 2026: Cursor comes to iPad, and mobile becomes a real review surface
On July 29, Cursor shipped a full iPad app (available on every paid plan) and pushed a bigger update to the iPhone/iPad experience that matters more than “you can code on a tablet now.” The rebuilt iPad layout uses the extra screen to pin sidebar chats so you can watch several agents run at once, run split-screen with a review open next to a chat, and mark up screenshots by tapping a specific point or drawing on the image with Apple Pencil.
The more useful change is that the phone and tablet apps now cover the entire pull-request review (comments, checks, approvals, adding or changing reviewers, and prompting the agent to resolve comments) plus a new Inbox that shows what’s in progress, what needs your attention, and which PRs are in review. This follows the June 29 iPhone launch and completes the same arc as everything else Cursor shipped this year: the actual coding happens on background and cloud agents, and your job is to assign, monitor, and approve their work from wherever you are. For a non-technical founder that’s the honest framing: the iPad app isn’t for hand-writing code on a couch, it’s for keeping a delegated build moving without opening a laptop. Also added: Bitbucket and Azure DevOps support, multi-PR sessions, and in-app team switching. Sources: Cursor changelog: now on iPad, 9to5Mac (June iPhone launch), Releasebot: Cursor.
New in July 2026: Auto mode now picks the model for you (Cursor Router)
On July 22, Cursor shipped Cursor Router, and it quietly changes how the Auto mode most people already use actually works. Instead of routing your request to whatever default model, Router is a request-level classifier that reads each prompt and sends it to the model best suited to that specific job: a quick edit goes to something cheap and fast, a gnarly refactor goes to a frontier model. You pick a posture, not a model: Intelligence (frontier quality), Balance (what most people daily-drive), or Cost (good-enough at the lowest token spend).
The pitch is roughly frontier-quality output at about 60% lower cost, and Cursor says it trained the router on 600,000+ live requests. Take the headline number with the usual skepticism, since “60% cheaper at the same quality” is a benchmark claim rather than a guarantee on your codebase, but the underlying idea is sound and it’s the direction the whole category is moving. For a non-technical builder the appeal is real: you stop agonizing over which model to select and let the tool make a decent bet, while capping spend with the Cost mode.
Two catches worth knowing. At launch, Router is live for Teams and Enterprise plans only. It’s on by default for Teams, and Enterprise admins flip it on from the dashboard, so solo Pro users don’t get it yet. And “let the tool choose the model” cuts against Cursor’s own biggest selling point, which is transparent model choice; Router is opt-into-a-mode, not a black box, but keep an eye on whether the default posture is optimizing for your quality or Cursor’s margin. Separately, a regional Start plan (₹649/mo, India-only) went live July 28 with capped access to Grok 4.5 and Composer. Sources: Cursor Router, MarkTechPost, Cursor changelog.
New in July 2026: Grok 4.5 and GPT-5.6 land in the picker, plus Cursor 3.11
Three things hit Cursor in the same week, and together they show what the SpaceX/xAI ownership actually buys you as a user.
Grok 4.5 (July 8) arrived in Cursor on all plans the same day xAI launched it, an unusually fast rollout that reflects how tight the relationship now is. It’s an “Opus-class” coding model (Musk’s words) priced at roughly a third of Opus 4.8, and it was trained partly on anonymized Cursor session data, so it should feel well-tuned to this specific workflow. It’s a genuinely strong, cheap option worth trying on a real task, with the usual caveat that independent testing on messy production repos takes weeks to shake out. Full breakdown: Grok 4.5 is here. Note it’s not yet available in the EU (targeted for mid-July).
GPT-5.6 (July 9) is also now selectable in Cursor (Sol, Terra, and Luna) landing a day after OpenAI’s general-availability launch. Terra is the value pick for most work; Sol is the expensive top tier. See our GPT-5.6 guide for the tradeoffs, including the METR cheating caveat that makes review discipline matter more, not less.
Cursor 3.11 (July 10) is a quality-of-life release rather than a headline feature. The useful additions: side chats that run alongside your main chat so you can ask a quick question without derailing your primary agent thread; searchable agent transcripts so you can find that thing an agent did three sessions ago; and simplified project and repo pickers. None of it is dramatic, but the side-chat feature in particular reduces the “I don’t want to lose my place” friction that made people hesitate to ask the agent small questions mid-task. Source: Cursor changelog, Releasebot: Cursor updates.
The pattern worth noting: with two fresh frontier models (Grok 4.5, GPT-5.6) selectable within 48 hours of launch, Cursor’s model-picker flexibility is holding up as its real advantage over closed builders that hide model choice. Your bring-your-own-key option remains the strongest hedge on model flexibility.
New in June 2026: SpaceX closes the $60B acquisition
On June 16, 2026, SpaceX confirmed it has signed a definitive merger agreement to acquire Anysphere, Cursor’s parent company, in an all-stock deal valuing it at $60 billion. The April call option has been exercised. The deal landed four days after SpaceX’s ~$75 billion Nasdaq IPO, is expected to close in Q3 2026 pending regulatory approval, and is the largest acquisition of an AI developer-tools company on record.
For users, nothing changes today. The product ships on the same roadmap. Over the next year, expect Grok-based models to appear in the picker alongside Claude and GPT, Composer to get a major compute boost via xAI’s Colossus cluster, and data-handling terms worth re-reading if your codebase touches regulated data. Cursor’s bring-your-own-API-key policy remains your best hedge on model flexibility. Full breakdown: SpaceX Just Closed the $60B Cursor Deal. Sources: CNBC, Crunchbase News.
New in June 2026: Cursor 3.7 gives Design Mode multi-select and voice-while-running
Released June 5, 2026. Two changes to Design Mode that, in combination, meaningfully reduce the context-switching overhead in visual iteration.
Multi-select editing lets you click two or more UI elements simultaneously in the browser preview. Cursor sees all the selected elements, their code, their surrounding layout, and the spatial relationships between them. You can then ask the agent to make one match the other, align a group of components, or remove repeated content across the selection, in a single instruction, across all the selected code at once. Previously you were editing one element at a time; now you’re editing the relationship between elements, which is how designers actually think.
Persistent voice input means the microphone stays available while an agent run is in progress. The old flow: describe a change, wait for the agent to finish, describe the next change. The new flow: describe a change, keep narrating as the agent works, queue the next edit by voice before the current one lands. For rapid visual iteration, the kind that used to require constant tab-switching between the tool and your notes, this cuts latency significantly.
Teams pricing update also shipped with 3.7: a new Premium seat tier for heavy agent users, increased usage limits on Standard seats, and real-time spend forecasting with smarter alerts. The cost-control improvements take effect for new customers immediately and for renewing teams on cycles starting July 1, 2026. Source: Cursor changelog 3.7.
Let’s get this out of the way upfront: Cursor is a code editor, not a no-code tool. If you’ve never written code before, Cursor will generate files full of things you can’t read, can’t debug, and can’t maintain. That’s not a Cursor problem. It’s a mismatch between the tool and the user. So if you’re a non-technical founder, the most useful thing this review can tell you is when Cursor is your problem to solve, and when it isn’t.
New in May 2026: Cursor 3.5 brings Automations across repos, Teams, and Jira
Three updates shipped in the past week that collectively make Cursor look less like a coding tool and more like a full engineering orchestration platform.
Cursor 3.5 (May 20) focused on Automations, the always-on background agents that can run tasks on a schedule or in response to events, without you sitting at a keyboard. The key changes: you can now attach multiple repos to a single Automation, so an agent working across a frontend and a shared component library doesn’t lose context mid-task. You can also create Automations with no attached repo at all, and five new no-repo templates are available in the Cursor Marketplace for things like market research sweeps, changelog summarization, and dependency auditing. Both Automations types are now manageable directly from the Agents Window in your IDE, rather than only through cursor.com. For the first seven days after launch, all agent runs for newly created Automations were 50% off. Source: Cursor changelog May 20.
Cursor in Jira (May 18–19) is the more significant product move. In partnership with Atlassian, you can now assign a Jira ticket directly to Cursor. The cloud agent reads the ticket title, description, comments, and your repo settings, then starts building. When it needs a decision or is ready for review, it notifies you inside Jira. When it opens a PR, it links back to the ticket automatically. The workflow requires Cursor admin access and Jira Commercial Cloud with Rovo enabled. For teams that live in Jira, this closes the last significant context-switch in their agent workflow: you no longer need to re-explain a ticket to the AI because the AI can read the ticket itself. Sources: Atlassian blog, Cursor changelog May 19.
Cursor in Microsoft Teams (May 11) landed earlier in the month. Mention @Cursor in any Teams channel and the agent reads the full thread, picks the right repo and model based on context, and opens a PR for your team to review, all without switching apps. For companies already standardized on Microsoft 365, this reduces the gap between “we talked about building this” and “Cursor started building this” to a single @mention. Source: Cursor changelog.
The pattern here is consistent with where Cursor has been heading since 3.0: the IDE is increasingly a control surface, not a place you spend all day. The goal is that more coding work gets assigned, monitored, and reviewed from wherever your team already works (Jira, Teams, Slack) with Cursor handling the actual implementation in the background.
New in May 2026: Cloud agent environments get enterprise-grade infra
On May 13, Cursor shipped a significant upgrade to its cloud agent infrastructure, the part of Cursor 3 that runs agents in isolated environments on remote machines rather than your local laptop. The update lands squarely in Teams and Enterprise territory, but the direction matters for any founder evaluating Cursor at scale.
Multi-repo environments are now first-class: you can configure a single cloud agent environment that spans multiple repositories, so an agent working on a cross-repo change (say, a frontend repo and a shared component library) doesn’t need to be retargeted on every hop. The agent reasons across repos and delivers changes that span the whole system.
Dockerfile-based configuration, already supported, got meaningfully more capable: build secrets are now natively supported, so your cloud agent can reach private package registries without hardcoding credentials into the environment definition. Layer caching was also upgraded, cutting Dockerfile rebuild time by 70% when only non-modified layers need updating.
Governance and audit tooling are the least glamorous additions and probably the most significant for anyone running Cursor on a real team. Every development environment now has version history with rollback (admin-only rollback can be enforced). An audit log captures every action team members take on environments. Egress and secrets are now scoped at the environment level, so credentials configured for one environment are not visible from any other. This closes a meaningful compliance gap that had been a blocker for regulated industries.
For non-technical founders: cloud agents are not a feature you’ll use directly. What this update signals is that Cursor is engineering toward the enterprise deployment model that will define its post-SpaceX-acquisition product roadmap. The governance layer is what gets Cursor approved inside a Fortune 500 security review. Source: Cursor changelog: development environments for cloud agents.
New in May 2026: Cursor 3.3 and the context usage breakdown
Released May 6, 2026. Cursor 3.3 adds a context usage breakdown so you can see exactly where your agent’s working memory is going: a per-line breakdown of what’s consuming context across rules, skills, MCP connections, and subagents. It sounds like a debugging utility, but it’s actually a power-user lever: once you can see that your MCP connections are eating 40% of your available context on every run, you can trim them to the ones you actually use and get noticeably better agent performance. For technical founders who’ve been running Cursor agents at scale and hitting quality issues they couldn’t diagnose, this is the first transparent view into why. Source: Cursor changelog: Context Usage Breakdown.
New in May 2026: Always-on security agents land in beta
On May 1, Cursor opened the beta for Cursor Security Review on Teams and Enterprise plans: two new always-on security agents that sit on top of the editor. The first, Security Reviewer, runs on every PR and flags auth regressions, data-handling problems, prompt-injection risks, and any agent tool auto-approvals that look suspicious, leaving inline comments at the exact diff location with a severity tag and a remediation suggestion. The second, Vulnerability Scanner, runs on a schedule against the whole codebase to catch known CVEs, outdated dependencies, and misconfigurations, and it can pipe its findings into Slack rather than waiting for someone to log in and look.
Both agents are customizable: you can adjust what triggers them, give them custom tooling, hand them house-style instructions, and pick how their output gets shared. This is Cursor’s first credible answer to the “vibe-coded apps have a security debt problem” narrative that’s dominated coverage of the category since the Lovable BOLA exposure and Base44 critical vulnerability earlier this year. For non-technical founders, the practical impact is small (these are Teams/Enterprise plan features, and you need a real PR review process to use them), but the strategic signal is meaningful: the editor that’s under SpaceX acquisition pressure is also the editor shipping the most aggressive built-in security tooling. Source: Cursor changelog.
New in April 2026: Cursor 3.2 ships with /multitask, plus GPT-5.5 lands
On April 24, Cursor shipped 3.2 alongside same-day support for OpenAI’s GPT-5.5. Both arrived together because OpenAI flipped the GPT-5.5 API on the same day, and Cursor was ready for it. The 3.2 release adds three orchestration upgrades that build on the Cursor 3 thesis (manage agents, don’t write every line). First, a new /multitask command tells Cursor to spin up async subagents that parallelize your requests instead of queuing them, and to break larger jobs into smaller chunks for a fleet of agents to tackle simultaneously, including pulling work out of a queued backlog. Second, Worktrees got a real home in the Agents Window: isolated background branches you can promote to the foreground with one click when you’re ready to test. Third, multi-root workspaces let a single agent session span multiple folders, so cross-repo changes (frontend / backend / shared lib) don’t require retargeting the agent on every hop.
Together with GPT-5.5 in the model picker, this is the most usable Cursor setup for genuine multi-task agentic work to date. For technical founders running a small team, the worktrees + multi-root combo is the change that’s most likely to land in your daily workflow. It’s the first version of Cursor where running three agent sessions across two repos doesn’t require fighting the tool. Source: Cursor changelog: Multitask, Worktrees, and Multi-root Workspaces.
New in April 2026: SpaceX signs a $60B call option on Cursor
On April 21, SpaceX and Cursor announced a partnership with an acquisition twist. SpaceX has paid for the right, a call option, to either acquire Cursor outright for $60 billion later in 2026 or pay $10 billion for “our work together” if the acquisition doesn’t close. In practical terms, Cursor becomes the AI coding arm of Elon Musk’s tech stack, and SpaceX’s Colossus supercomputer (the 230,000-GPU Memphis cluster run by xAI, which SpaceX merged with in February) becomes Cursor’s training infrastructure. Cursor CEO Michael Truell said the company had been “bottlenecked by compute” and will use Colossus to scale up its Composer model family. This effectively leapfrogs the $2B/$50B raise Cursor was in talks on as of April 17. That round is now superseded by the SpaceX terms. For Cursor users, the product doesn’t change today. What changes is the ownership trajectory and the model supply chain. If you’re worried about vendor risk under Musk-controlled entities, that’s a legitimate consideration for customer-data-heavy apps built on Cursor-managed infra, and worth weighing alongside the underlying developer experience. See our explainer on the SpaceX-Cursor deal for what it means for founders and PMs making tool choices right now.
Business update: $2B ARR, the $50B raise that’s now moot
By April 2026, Anysphere, Cursor’s parent company, has crossed $2 billion in annualized revenue, roughly doubling its run rate in three months. On April 17, Bloomberg and TechCrunch confirmed the company was raising $2 billion at a $50 billion pre-money valuation. That financing was superseded four days later by the SpaceX deal above. About 60% of revenue now comes from enterprise, with more than half the Fortune 500 using Cursor across engineering teams. At the implied $60B acquisition price, Cursor is being valued as core software infrastructure, not a developer productivity tool. That’s a significant distinction for anyone making long-term tool bets. The ownership question now lives inside the Musk/xAI/SpaceX orbit rather than a conventional private-tech cap table.
Also in April 2026: BugBot gets smarter
Cursor shipped a meaningful BugBot update this week. BugBot, which reviews new code every time you push a change, now supports MCP (Model Context Protocol), meaning it can pull context from external tools like Linear, Jira, or Notion when reviewing a PR. It also gained real-time self-improvement: BugBot now learns from reviewer feedback on pull requests, automatically promoting useful review patterns into standing rules. Autofix has been enhanced so BugBot can not only flag issues but propose and apply patches. At 2 million PRs reviewed per month, the feedback loop is compounding fast. For technical founders using Cursor as their primary environment, these updates make the automated review layer genuinely worth enabling.
New in April 2026: Cursor 3
Cursor 3 launched on April 2, 2026, built under the internal codename “Glass,” and it’s a more fundamental rethink than a version bump suggests. The core idea: most code will be written by AI agents, and the developer’s job is to orchestrate them, not type every line. The interface reflects that assumption completely.
The headline addition is the Agents Window: a persistent, standalone hub separate from the IDE where you spin up, monitor, and control multiple AI agents running simultaneously. Each agent gets its own task (one refactoring a module, another writing tests, another updating documentation) and you track their status, reasoning, and progress in real time from a unified sidebar. You can trigger agents from mobile, Slack, GitHub, or Linear, not just from inside the editor.
Other meaningful additions include Design Mode, which lets you annotate UI elements directly in the browser and pass those references to an agent for precise iteration; a /worktree command that creates isolated git worktrees so agents work in parallel on the same repo without conflicts; and native multi-repo support so a single session can span more than one codebase.
For non-technical founders, the Agents Window is still not an entry point. It’s a developer orchestration layer. But the broader direction here (manage agents, not write code) is converging on what tools like Lovable and Bolt have offered from day one. Cursor 3 is Cursor’s direct answer to Claude Code and OpenAI Codex eating into its market share among agentic workflows.
What Cursor actually is
Cursor is a fork of VS Code, the text editor that most professional developers use, with AI features deeply built in. Unlike GitHub Copilot, which adds AI as a plugin, Cursor redesigns the whole experience around AI assistance. It has a chat panel that understands your full codebase, autocomplete that predicts blocks of code rather than single lines, and a “Composer” mode that can make coordinated changes across multiple files from a single description.
For a developer, this is a productivity multiplier. Experienced engineers report writing 40–60% less code manually because Cursor’s suggestions are good enough to accept. Multi-file changes that used to take an hour can be drafted in five minutes.
The non-technical founder reality check
Here’s the honest question: can you use Cursor to build something if you don’t code?
Technically yes. Practically, it depends.
If you have some coding background (a CS degree from ten years ago, a bootcamp under your belt, enough comfort reading JavaScript even if you can’t write it cold) Cursor is actually powerful in your hands. You can describe what you want in plain English, review the changes it proposes, and accept or reject them. You won’t write much code, but you’ll understand enough to stay in control.
If you have zero technical background, you’ll run into a wall quickly. Cursor will generate code. You’ll hit an error. The error message will be meaningless. Cursor will try to fix it and create two more problems. Without the ability to read what it’s producing and reason about what went wrong, you’re flying blind. This isn’t Cursor failing. It’s the wrong tool for the job.
When a no-code tool is the right call
If you’re at the “I need to validate this idea” or “I need a working prototype by next week” stage, and you don’t have a technical co-founder, start with Lovable, Bolt, or Base44. These tools build complete apps from prompts and hide the code entirely. You’ll ship faster, and you won’t need to understand what’s under the hood.
Come back to Cursor, or hire someone who uses it, when you have a real product, real users, and complexity that no-code tools can’t handle.
Pricing
The free tier gives you a limited monthly allowance of AI completions. Most people who use it daily will hit the limit within a week. The Pro plan at $20/month removes those limits and gives you access to faster models. You can also bring your own Anthropic or OpenAI API key to control costs directly.
Bottom line
Cursor is the best AI-powered code editor available, and with Cursor 3’s chatbot mode, it’s now accessible to a wider range of builders than ever. If you have coding skills or a developer on your team, the IDE experience is unmatched. If you don’t, the chatbot mode gives you a real way in, though you’ll still benefit from understanding what the AI is producing. Cursor 3 is Cursor’s attempt to meet Lovable users halfway. Whether it’s convincing enough depends on whether you want a developer tool with AI bolted on (classic Cursor) or an AI-first builder with more power underneath (new Cursor).
The original AI coding assistant: inline autocomplete and chat built into your existing editor
ByteDance's free Cursor alternative: a full-featured AI IDE with no subscription cost
Now Devin Desktop: Cognition's agentic IDE, formerly Windsurf, with a strong free tier and open agent support