Artificial intelligence has developed the astonishing capability to detect software vulnerabilities significantly faster than the cybersecurity industry can effectively analyze and patch them. However, this explosive surge in new vulnerability reports has not yet precipitated a corresponding wave of real-world cyberattacks. By September 21, an independent vulnerability tracker had accumulated 225 Common Vulnerabilities and Exposures (CVEs) directly linked to Anthropic and its ambitious Project Glasswing. Remarkably, researchers have confirmed active exploitation in the wild for only a single vulnerability from this extensive list.
The Independent Tracker and Project Glasswing
Patrick Garrity, a prominent specialist at VulnCheck, meticulously maintains this independent tracker. He systematically aggregates public CVEs where the official descriptions or acknowledgments explicitly mention the Anthropic team, its affiliated employees, or contributors to Project Glasswing. Consequently, the figure of 225 does not imply that a single AI model autonomously discovered every entry, nor does it guarantee that every vulnerability can be unequivocally attributed to Glasswing. The attribution methodology for CVEs remains notoriously inconsistent across the industry. For a deeper understanding of this data, you can examine the raw information regarding Anthropic credited CVEs curated by Garrity.
Anthropic officially launched Project Glasswing on April 7, strategically granting restricted access to the Claude Mythos Preview model to massive technology corporations and developers responsible for critical software infrastructure. By May, the company boldly proclaimed the discovery of over 10,000 high and critical severity software flaws. At that juncture, executives deliberately chose not to release the Mythos Preview broadly, citing profound concerns regarding its unprecedented capabilities in identifying and potentially exploiting software vulnerabilities.
The Sole Exploited Vulnerability: A Ghost SQL Injection
The glaring anomaly within these statistics is CVE-2026-26980, which earned a staggering critical CVSS 3.1 score of 9.4. This devastating SQL injection vulnerability afflicted Ghost versions 3.24.0 through 6.19.0. It empowered unauthenticated attackers to arbitrarily read sensitive data directly from the database via the Content API. Developers successfully neutralized this catastrophic error in Ghost version 6.19.1. However, VulnCheck subsequently detected malicious actors deploying the corresponding exploit against their strategically deployed honeypot systems.
Having merely a single confirmed exploitation among 225 recorded vulnerabilities yields an exploitation rate of less than 0.5%. Garrity astutely compares this result to the broader cybersecurity landscape, noting that historically, only a minuscule fraction of published CVEs ultimately materialize in real-world attack campaigns. Nevertheless, the glaring absence of observable malicious activity does not conclusively prove that threat actors ignored or failed to weaponize the remaining 224 vulnerabilities.
Anthropic’s Internal Statistics Reveal a Bottleneck
Anthropic’s proprietary statistics present a vastly different narrative, as they encompass significantly more than just officially published CVEs. As of August 26, the company officially reported identifying 26,153 potential vulnerability candidates. They submitted 5,008 for external verification and subsequently confirmed 4,576 distinct flaws. Of those, developers received 2,300 detailed reports, leading to the successful remediation of 421 specific problems. Ultimately, formal identifiers were assigned to 177 CVEs and 285 GitHub Security Advisories. You can find more comprehensive details on their disclosure process in the official Anthropic coordinated vulnerability disclosure documentation.
One cannot directly compare these disparate figures. Anthropic’s internal registry accurately reflects its proprietary coordinated disclosure process, naturally including significant discoveries that never received a public CVE designation. Conversely, Garrity exclusively compiles publicly available records explicitly mentioning Anthropic and its associated teams. This glaring discrepancy perfectly illuminates the primary bottleneck in the modern vulnerability lifecycle: even following instantaneous automated discovery, human engineers must still manually reproduce the flaw, rigorously verify its impact, coordinate with the respective maintainer, and ultimately engineer a secure patch.
The Chasm Between Machine Detection and Practical Risk
VulnCheck also identified a profound disconnect between automated vulnerability scanning and practical, human-led risk assessment. Among the discoveries where both the AI model’s assessment and the project developers’ evaluations were accessible, Claude aggressively categorized 91.5% of the problems as high or critical severity. In stark contrast, human maintainers assigned those severe classifications to a mere 51.3% of the identical issues. While this discrepancy does not render the remaining discoveries false positives, it exponentially inflates the arduous manual labor required for proper vulnerability prioritization.
Automated code remediation remains a significant vulnerability in this emerging ecosystem. The 1Password security team meticulously evaluated 6,080 distinct patch variations generated by ChatGPT-5.5 and Anthropic Opus 4.8 targeting six recent CVEs. A remarkably low 26% of these AI-generated patches successfully eradicated the vulnerability without simultaneously introducing noticeable, detrimental changes to the program’s intended behavior. Alarmingly, 53.9% either utterly failed to close the original security loophole or inadvertently introduced an entirely new vulnerability, frequently combining both catastrophic failures.
Artificial intelligence undeniably slashes both the financial cost and time required to hunt for software weaknesses. However, genuine operational risk is not solely determined by the raw volume of new database entries. A successful attacker inherently requires an accessible target, a reliable exploitation methodology, and a tangible, valuable outcome. For defenders, the primary consequence of this AI revolution is an endlessly burgeoning queue for the verification and remediation of vulnerabilities—flaws that tireless machines now produce at a velocity that vastly exceeds human processing capabilities.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.