Anthropic said on Oct. 6, 2026, that Project Glasswing partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026. Anthropic also said its own open-source scanning efforts found another 5,500 verified vulnerabilities between April and October. More than 33,000 of the verified findings have so far been rated critical or high severity, according to the company.
The bottleneck has moved from finding to fixing
Together, the partner and open-source figures add to at least 134,500 verified vulnerabilities, but they should not be treated as one uniform public dataset. Anthropic described the Glasswing results as a lower bound based on partial data from 33 partner reports and its open-source partnerships. It also said organizations used different triage methods, and fewer than half of partners disclosed patched numbers because fixes were often still in progress.
Anthropic’s coordinated vulnerability disclosure dashboard shows the follow-through challenge in one slice of the work. As of Oct. 2, 2026, the dashboard listed 6,157 disclosed vulnerabilities across 591 open-source projects. To Anthropic’s knowledge, 516 had been patched.
That dashboard is separate from the full Glasswing partner count, so the numbers should not be blended. Still, it shows the operational pattern Anthropic now emphasizes: models can surface vulnerabilities faster than disclosure, triage, owner routing, and safe patch deployment can absorb them.
Anthropic made that point more directly on Oct. 8, when it introduced its Cyber Mission. The company said Project Glasswing had uncovered many vulnerabilities but had not yet produced a sufficient reduction in cyber risk, because verifying, prioritizing, and fixing findings remained difficult.
Anthropic is widening access, but not removing controls
The vulnerability numbers arrived alongside an expanded Cyber Verification Program, which gives qualified security professionals access to advanced cyber capabilities with reduced blocking. Anthropic said the program now includes Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and future models.
The access model is tiered.
- Defense Access: for defensive work such as security operations, incident response, malware reverse engineering, and vulnerability validation. Anthropic says many defensive organizations, open-source maintainers, and individual researchers with reported-vulnerability records may qualify.
- Red Team Access: for organizations doing authorized penetration testing and red teaming. Anthropic says actions linked to physical harm or mass disruption remain blocked.
- Specialized Access: for a limited set of verified organizations testing safety systems that could affect lives or markets, such as power grids, telecom networks, interbank transfer infrastructure, flight operating systems, and government administrative networks. Anthropic says it reviews this tier with the U.S. government.
The company’s own tier testing shows how much the controls change model behavior. On CyScenarioBench, Anthropic said a non-CVP setup blocked every task at the first prompt. Defense Access blocked 46 of 50 trials at some point. Red Team Access had no blocks, and Claude Opus 5.5 completed 34 of 50 tasks, effectively equivalent to the 67.6% success rate Anthropic reported with no safeguards applied.
Customer examples show where AI changes the work
The most useful examples are not only about finding one more bug. They show models connecting code, configuration, identity, permissions, and runtime behavior across systems.
In an Anthropic-published customer article, Comcast reported using Claude Mythos Preview during an assessment covering 258 business-critical systems and about 170 million lines of code. The model identified a critical authentication issue in a public-facing platform; Comcast validated it against the running application and remediated it before observing evidence of exploitation.
Booz Allen described a different effect. Anthropic’s article said one analyst reviewed eight production systems across 138 repositories in 12 days with Mythos-class support. Booz Allen said similar portfolio coverage would otherwise have taken several months with a larger team.
Those examples do not prove that every organization will see the same result. They do show why vulnerability volume can surge once a model can follow a security hypothesis across many repositories, languages, and system boundaries.
Anthropic’s newest move is about capacity
On Oct. 8, Anthropic launched the Critical Infrastructure Defense Program and OSS Scanner under its broader Cyber Mission. The critical infrastructure program brings Claude models, on-site engineers, and threat research to providers that secure operational technology, including power, water, transportation, industrial, and government systems.
OSS Scanner is aimed at open-source maintainers. Anthropic says enrolled projects can receive periodic scans from its strongest models at no cost. Those reports are model-generated and sent without human review, which means maintainers receive them faster but may see errors, including wrong severity ratings. Anthropic says it expects a true-positive rate above 90% and plans to improve it over time.
This is the tradeoff at the center of AI-assisted defense. Human review is slower but safer. Automated reporting is faster but can shift more validation work onto maintainers who may already be overloaded.
Anthropic’s 129,000 number is not a final answer to whether AI favors attackers or defenders. The next question is how many findings can be verified, prioritized, assigned to owners, safely patched, and measured after deployment. That is the metric that will show whether AI-assisted security is reducing risk, not just expanding the backlog of known weaknesses.

Tech Help Canada Staff researches, writes, and reviews practical content for business owners and professionals. Our coverage spans business, marketing, SEO, technology, and the tools and systems people use to grow and operate online. We focus on clear, useful information backed by research, hands-on experience, and editorial review. Learn more about our team and editorial standards. Need help with something? Contact Us







