security
May 23, 2026
By Teun
Anthropic Says Claude Mythos Found 10,000 Security Flaws
Anthropic says its Project Glasswing program has helped uncover more than 10,000 high- or critical-severity vulnerabilities since launching last month. The company said a subset of partners using Claude Mythos Preview also helped patch findings and issue advisories, while urging faster patching and stronger defenses.
Anthropic said Friday that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities in widely used software since the cybersecurity program launched last month. The company described the effort as focused on some of the world’s most “systemically” important software and said a small group of about 50 partners received access to Claude Mythos Preview, a frontier model designed to find vulnerabilities in widely used code.
According to Anthropic, 6,202 of the vulnerabilities identified through the program were classified as high- or critical-severity and affected more than 1,000 open-source projects. The company said later analysis found 1,726 of the candidates were valid true positives, and that 1,094 of those were assessed to be high- or critical-severity flaws.
One example Anthropic highlighted was a critical weakness in WolfSSL, tracked as CVE-2026-5194 and given a CVSS score of 9.1. The company said the flaw could let an attacker forge certificates and impersonate a legitimate service.
Anthropic said the work has already led to 97 findings being patched upstream and 88 advisories being issued. Upstream patching means the fix is made in the original software project so downstream users can pick it up.
The company also acknowledged a broader problem: finding bugs is easier than fixing them. “The relative ease of finding vulnerabilities compared with the difficulty of fixing them amounts to a major challenge for cybersecurity,” Anthropic said. “Confronting this challenge successfully will make our software far safer than before.”
The disclosure comes as software vendors are shipping more fixes, in part because AI tools are helping researchers find bugs faster. Microsoft has said the number of monthly patches it expects to release will continue trending larger for some time. Autonomous offensive security platform XBOW said Mythos Preview is “a major advance” and described it as substantially better than earlier models at finding vulnerability candidates and analyzing source code with a security mindset.
Anthropic said the model is also useful beyond vulnerability discovery. In one case, the company said, a Glasswing partner bank used the model to detect and prevent a fraudulent $1.5 million wire transfer after an unknown threat actor breached a customer’s email account and made spoofed phone calls.
The company warned that models with similar capabilities could become broadly available in the near future, and said software developers should shorten patch cycles and release security fixes faster. Anthropic pointed to Oracle’s recent move to a monthly patch cycle for critical security issues as an example of that shift.
“Network defenders should shorten their patch testing and deployment timelines,” Anthropic said. It also recommended hardening default network configurations, enforcing multi-factor authentication, and keeping comprehensive logs for detection and response.
To support legitimate security work, Anthropic said it has launched a Cyber Verification Program that lets security professionals use its models without guardrails for tasks such as vulnerability research, penetration testing, and red teaming. The company said this is similar to OpenAI’s Daybreak program, which gives defenders access to GPT-5.5-Cyber for specialized workflows.
Anthropic said models like Mythos Preview and GPT-5.5-Cyber have not been released publicly because it believes there are still no adequate safeguards to prevent large-scale misuse. The company said Glasswing is intended to give major cyber defenders an advantage, but added that many organizations still need to improve their security posture.