Anthropic reports that about 50 Glasswing partners used Claude Mythos Preview to find more than ten thousand high- or critical-severity vulnerabilities, and that its own scan of over 1,000 open-source projects produced 6,202 model-estimated high/critical findings. Of 1,752 assessed, mostly by six independent firms, 90.6% were true positives; Anthropic estimates 530 high/critical bugs disclosed, of which 75 were patched, and says triage and patching capacity, not discovery, is the bottleneck.
Why it matters
It gives rare pipeline-level numbers showing AI vulnerability discovery outpacing the human capacity to verify, disclose and fix.
Key facts
As stated in the sources, with where to find them.
- Mythos Preview estimated 6,202 high- or critical-severity vulnerabilities (of 23,019 total) across more than 1,000 open-source projects.Section 'Open-source software'
- Of 1,752 high/critical findings assessed by six independent firms or, in a few cases, Anthropic, 90.6% (1,587) were valid true positives and 62.4% (1,094) confirmed high or critical.Section 'Open-source software'
- An estimated 530 high/critical bugs disclosed to maintainers, with 827 more confirmed and awaiting disclosure; 75 patched and 65 with public advisories; average time to patch a high/critical bug about two weeks.Section 'Open-source software'
- Mozilla found and fixed 271 vulnerabilities in Firefox 150 while testing Mythos Preview; Cloudflare found 2,000 bugs, 400 high or critical.Section 'Evidence from our partners and external testers'
Findings that cite this record
Key questions this bears on
- Is AI shifting the balance between finding and fixing vulnerabilities?Discovery is ahead. AI finds real vulnerabilities faster than they are fixed, and simple checks overstate how often AI patches work.
Sources
Related records
Apr 7, 2026
Jul 2, 2026
Jun 30, 2026
Jun 12, 2026
Sep 2, 2026
Aug 4, 2026