Skip to content

anthropic

One of 225 Anthropic-linked CVEs actually got used

Promtime

Attackers have gotten use out of exactly one of the 225 vulnerabilities credited to Anthropic and its Project Glasswing: a critical SQL injection in the Ghost publishing platform, CVE-2026-26980. The count comes from VulnCheck researcher Patrick Garrity, who has tracked the credits since April and shared the tally with The Register.

At a glance

  • Anthropic built Glasswing around a model it said was too dangerous to ship publicly, Claude Mythos Preview, and handed it only to vetted partners for defensive work on their own code.
  • Garrity's tracker cross-checks every Glasswing-credited CVE against VulnCheck's known exploited vulnerabilities index; 225 flaws are listed, and exactly one has confirmed exploitation in the wild.
  • Historically just under one percent to two percent of flaws get weaponized, and fixes lag: patches from ChatGPT-5.5 and Opus 4.8 fully resolved the bug 26 percent of the time in 1Password's analysis.

If you missed April: Anthropic announced Project Glasswing, giving selected partners access to Claude Mythos Preview, a model the company said was too risky to release publicly because its bug-finding and exploitation skills surpass all but the most skilled humans. Vetted participants use it for defensive security work, finding and fixing flaws in their own software products and open source dependencies. Garrity started tracking the credits shortly after the announcement.

One flaw out of 225 has confirmed exploitation

As of Monday the tracker listed 225 CVEs credited to the Anthropic team, Project Glasswing, or both. One of them, the critical SQL injection in Ghost tracked as CVE-2026-26980, has confirmed exploitation in the wild. That is under half a percent.

Garrity's reading is that the distance between finding a bug and anyone bothering to use it carries the whole story.

There's a big difference between finding vulnerabilities and whether they're actually useful to and will be used by threat actors.

He told The Register that what Anthropic is discovering and disclosing is fairly limited in impact, and that as far as the data shows, it is not producing different outcomes from a threat perspective than a random selection of other vulnerabilities would.

How do you tell a scary bug from a used one?

You keep two lists and watch where they overlap. Garrity's Anthropic CVE tracker collects vulnerabilities credited to the Anthropic team and Project Glasswing, then checks each one against VulnCheck's known exploited vulnerabilities index, in his words to get a better read on the real Glasswing "danger factor".

Think of a product recall list held up against actual crash reports. The recall tells you a defect exists; the crash reports tell you whether it hurt anyone. The first list is possible at all because CVE records carry credit for whoever reported the flaw, which is how a model's output becomes countable.

Weaponization has historically run from just under one percent to two percent

Garrity does not dispute that AI finds bugs. What he disputes is the assumption behind the alarm. A lot of the hysteria, he says, treats every vulnerability as likely to be used by threat actors, when only a small fraction ever enters an exploitation campaign: historically, from just under one percent to two percent get weaponized and used in the wild. By that yardstick the Glasswing batch is unremarkable.

He also notes that bug-finding is not a capability unique to one model or harness. Anyone following disclosures over the past few months would struggle to argue that AI models aren't surfacing far more flaws than before, and the recent patch drops from Microsoft, Apple and Palo Alto Networks show the volume, never mind open source projects.

AI-written patches fully fixed the flaw 26 percent of the time

1Password's research team produced and analyzed 6,080 patches developed by two frontier models, OpenAI's ChatGPT-5.5 and Anthropic's Opus 4.8. Those fixes fully resolved the vulnerability 26 percent of the time. About 54 percent either failed to resolve the vulnerability, introduced a new one, or did both.

A separate study from application security shop Veracode covered more than 100 models across 80 coding tasks and found an average security pass rate for AI-generated code of 56 percent.

Which leaves the human part. Garrity's summary: the bar for vulnerability discovery is much lower with AI, but the real gap sits downstream in coordination, triage, remediation and patch deployment, still largely people-intensive work, as he says Anthropic itself has acknowledged.

The tracker measures confirmed exploitation, a trailing number by nature: a flaw can sit unused and surface in a campaign much later, and nothing here says how many of the 225 were quietly probed. In our view the odd part is the mismatch inside the program, a model gated on how well it finds and exploits bugs while triage and patching stayed human work; Garrity puts it as Anthropic possibly not realizing that until after launch.

When the second column moves

225 is a running count, and the number worth watching is the other one: whether anything joins CVE-2026-26980 on the exploited list, and how quickly. Garrity checks new Glasswing credits against the known exploited vulnerabilities index as they arrive. Anthropic has not said when, or whether, Mythos Preview reaches anyone beyond the vetted Glasswing participants, and no date for wider access has been given.

Related stories

  1. Six curl CVEs land after two AI scanners found none
  2. Agent loop finds and fixes bugs across OpenAI systems
  3. Claude cheated on 2.4% of its own safety runs
  4. Self-spreading ideas jump between agents in Anthropic tests
  5. Counting four-letter runs spots Claude Opus 5 text
  6. Agents killed rival agents in an Anthropic test

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.