
Anthropic's AI-driven cybersecurity system, Claude Mythos Preview, has identified 23,019 vulnerabilities across widely used software systems within the first 30 days of Project Glasswing. According to the latest update from Anthropic, the discovery was shared as part of the company's Project Glasswing initiative, which provides limited access to select organizations testing the system under controlled conditions. The update reveals that Claude Mythos Preview has scanned more than 1,000 open-source projects, generating 23,019 candidate findings across all severity levels. The system has achieved a 90.6% true-positive rate when routed for formal review by six independent external security firms, with 1,752 confirmed as valid vulnerabilities. Anthropic reports that 6,202 high- or critical-severity vulnerabilities were identified out of the total 23,019 findings, with 90% of those assessed by independent security researchers confirmed as valid positives, and 62.4% confirmed as either high- or critical-severity. The company has officially released its first results after a month of preview testing, with 1,752 vulnerabilities independently identified by the model that were reviewed by security firms.
Under Project Glasswing, Anthropic has worked with approximately 50 partner organizations, including companies maintaining critical infrastructure software. As reported by Anthropic, most partners have individually identified hundreds of high- or critical-severity vulnerabilities within their own systems. In aggregate, this has crossed 10,000 vulnerabilities, while several partners reported that their bug discovery rates increased by more than 10 times after using the system. Cloudflare identified around 2,000 bugs across its systems, including 400 classified as high or critical severity, with a false-positive rate that Cloudflare's security team described as better than that of human testers. Mozilla found and fixed 271 vulnerabilities in Firefox 150 using Mythos Preview, more than ten times the number identified in Firefox 148 using Claude Opus 4.6. Microsoft has stated that future Patch Tuesday releases will "continue trending larger for some time" due to Mythos findings. Anthropic highlighted that partners found "hundreds of critical or high-severity vulnerabilities in their software," demonstrating the system's effectiveness across diverse software ecosystems.
A significant portion of the discovery effort has focused on open-source software, with Anthropic scanning over 1,000 open-source projects and identifying 23,019 vulnerabilities in total. According to Anthropic, 1,900 findings were routed for formal review by six independent external security firms, yielding a 90.6% true-positive rate. The system identified a particularly concerning flaw in a widely used cryptography library that could allow attackers to forge digital certificates and impersonate trusted websites, demonstrating the depth of analysis capabilities. Notably, Mythos Preview identified a 27-year-old vulnerability in the OpenBSD kernel and a 16-year-old flaw in FFmpeg, underscoring its ability to detect latent bugs that human researchers had missed for decades. The model could account for nearly 3,900 confirmed high- or critical-severity vulnerabilities in open-source software alone, in addition to those found for Project Glasswing partners.
While discovery has accelerated, the remediation pipeline has not kept pace with the discovery rate. As reported by Anthropic, 1,596 findings have been reported to maintainers, of which 1,451 have been acknowledged. However, only 97 have been patched upstream, and 88 security advisories have been published as of May 22, 2026. The company noted that 827 confirmed high- or critical-severity vulnerabilities are awaiting disclosure, with patches lagging due to overloaded open-source maintainer ecosystems. Even when prioritized, fixing high-severity vulnerabilities takes an average of around two weeks. Some maintainers have actively asked Anthropic to slow its disclosure rate due to capacity constraints, highlighting the growing crisis in the security ecosystem's patching capacity. The most concerning statistic is that fewer than 1% of the vulnerabilities Mythos found have actually been patched, creating a massive backlog of undiscovered security debt across software ecosystems.
According to Anthropic, software companies are beginning to increase the volume and frequency of patches, with some vendors releasing significantly larger patch updates than usual and others accelerating vulnerability response cycles. The company has launched Claude Security in public beta for Enterprise customers, which has already been used to patch over 2,100 vulnerabilities in three weeks. Anthropic has released scanning skills, codebase-mapping harnesses, and threat model builder tools to qualifying security teams, while a new Cyber Verification Program expands access for security professionals. The company has additionally partnered with the Open Source Security Foundation's Alpha-Omega project to help maintainers process the surge of incoming AI-generated bug reports. However, Anthropic noted that models with comparable cybersecurity capabilities are likely to become more widely available in the near future, increasing the risk that attackers could use them to identify and exploit vulnerabilities at scale. The company remains cautious about releasing Mythos Preview publicly, warning that such powerful capabilities could also be exploited if widely available, and emphasized that "there is a clear need for a larger effort across the software industry to manage the volume of findings that these models will generate."