Anthropic-linked CVEs pile up, attackers mostly shrug
Of 225 flaws found by Glasswing and tracked by VulnCheck researcher, just one has confirmed exploitation in the wild
As more vulnerabilities linked to Anthropic and Project Glasswing are discovered, a small fraction of these security flaws are being exploited in the wild, according to VulnCheck researcher Patrick Garrity. Anthropic launched Project Glasswing, a program that grants select partners access to its Claude Mythos Preview model, shortly after announcing the initiative in April.
The model, Anthropic claims, is too risky for public release due to its superior bug-finding and exploitation abilities compared to human experts. Access to this program is limited to vetted Glasswing participants, who utilize the model for defensive security work, including identifying and rectifying flaws in their own software products and open-source dependencies.
As of Monday, Anthropic's CVE tracker records 225 vulnerabilities attributed to Anthropic and/or Project Glasswing. Of these, only one, a critical SQL injection bug in Ghost (CVE-2026-26980), has been exploited in the wild. Analysts suggest that while AI models excel at finding vulnerabilities, they are less effective at creating exploitable ones.
The primary concern, according to Garrity, is that the vulnerabilities discovered by Anthropic and Project Glasswing have minimal impact and are not being weaponized at a higher rate than other, randomly selected vulnerabilities. This data indicates that Anthropic's discoveries and disclosures are limited in their threat potential.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 1 other outlet
- Anthropic-linked CVEs pile up, attackers mostly shrug theregister.com
