Skip to main content
CybersecurityVulnerability Management

Anthropic Expands AI Access for Cyber Teams After Finding 129,000 Flaws

Cybersecurity team collaborates around a laptop and notes, analyzing code and vulnerabilities in a bright, daytime workspace.

"Of these verified vulnerabilities, more than 33,000 have so far been rated as critical- or high-severity," Anthropic said — a tally that the company says is likely an undercount and could be at least five times higher.

Anthropic's Cyber Verification Program (CVP)

Anthropic this week announced an expanded Cyber Verification Program (CVP) that grants vetted cybersecurity teams tiered access to its advanced models, including Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1 and future releases. The CVP is structured into three distinct access tiers: Defense Access for incident response, malware reverse engineering, and vulnerability analysis and validation; Red Team Access, which adds authorized penetration testing and red‑teaming to those defensive activities; and Specialized Access, which carries the fewest safeguards and is limited to a small set of verified organizations authorized to test safety systems.

Project Glasswing's discovery totals and scope

Anthropic said its Project Glasswing initiative verified at least 129,000 software vulnerabilities between April and July 2026. In addition, the company reported another 5,500 verified vulnerabilities found through open‑source scanning between April and October 2026. Of the verified vulnerabilities Anthropic cites, more than 33,000 have been rated critical or high — a figure the company warns is based on survey data from only a subset of Glasswing partners and is therefore likely a substantial undercount.

Safeguards in practice: CyScenarioBench results

Anthropic presented CyScenarioBench evaluations to show how the CVP's tiers interact with model safeguards. On Claude Opus 5.5, safeguards in the Defense Access tier blocked 46 of 50 tested tasks. By contrast, the Red Team Access tier on the same model did not block any tasks and completed 34 of 50 — the same completion rate observed when no safeguards were applied. Anthropic noted that without CVP access, every task was blocked on the first prompt. “These evaluations give us confidence that we can make advanced cyber capabilities safely available to a broader set of defenders, expanding the defensive efforts we began with Project Glasswing,” Anthropic said.

Active exploitation and severity breakdown

Independent analysis by VulnCheck researcher Patrick Garrity found that only 2 of the 300 vulnerabilities discovered by Anthropic or Project Glasswing — 0.67% — had been exploited in the wild as of his report. Among those 300 vulnerabilities, Garrity classified 39 as critical, 141 as high, 81 as medium and 18 as low. The two vulnerabilities with recorded exploitation efforts are CVE‑2026‑26980, an SQL injection flaw in Ghost CMS, and CVE‑2026‑61500, a session forgery flaw in Rejetto HTTP File Server. Anthropic has framed its work as supplying defenders with the same discovery capabilities that could otherwise be weaponized by bad actors.

What this means for defenders, open‑source maintainers, and policymakers

  • Defenders: The CVP promises access to models configured for incident response, reverse engineering, validation and authorized red‑teaming. Anthropic’s results — including the CyScenarioBench comparison showing fewer blocks under higher‑privilege tiers — indicate teams approved for Red Team or Specialized Access will be able to run queries that are blocked for general users, potentially accelerating vulnerability validation and exploit testing.
  • Open‑source maintainers: Project Glasswing and Anthropic’s open‑source scanning found thousands of verified flaws; maintainers are likely to see increased disclosure pressure from high volumes of findings and will confront the operational task of triage, patching and coordinating fixes for critical‑ and high‑severity items.
  • Policymakers and regulators: Anthropic designed tiered access to balance defensive use with dual‑use risk. That explicit balancing of safeguards and access presents concrete policy choices around who should be permitted to use reduced‑safeguard AI tooling and under what oversight or verification regime.

Two practical tensions run through the record Anthropic released. First, high counts of discovered vulnerabilities do not necessarily equate to widespread exploitation; Garrity’s analysis shows active exploitation remains rare among the sampled findings. Second, fixing flaws with AI brings its own hazards: Anthropic pointed to demonstrations by 1Password and findings from Veracode showing that AI‑generated code can introduce new vulnerabilities. Veracode reported that “roughly 44% of AI code generation tasks introduced a risky security vulnerability in tests,” and that “the average security pass rate across models is 56% – barely changed from 55% in the first report,” even as AI‑generated code has surged into pipelines.

The CVP expands a deliberate experiment in granting defenders access while varying safeguards. Whether the program reduces real‑world risk will hinge on how broadly the undercounted discoveries translate into exploitable weaknesses, how defenders do or do not introduce new risk when they patch, and how tightly access and oversight are enforced for higher‑privilege tiers.

Original story