Skip to main content
CybersecurityVulnerability Management

Anthropic Overhauls Cyber Verification Program

Security professional working on laptop in modern office setting.

Anthropic says its security program helped partners identify at least 129,000 verified software vulnerabilities between April and July 2026.

Anthropic folds Project Glasswing and CVP into a single program

In a brief announcement, Anthropic said it has reconfigured two security offerings—Project Glasswing and the Cyber Verification Program (CVP)—into one expanded program. "For the past six months, we’ve enabled trusted access through two programs: Project Glasswing and the CVP," Anthropic wrote. "Now, we’re integrating these programs into one expanded offering, designed to give more security organizations access to the capabilities they need to protect their systems."

Both programs originally launched in April 2026 alongside the debut of Mythos, Anthropic’s frontier model. Project Glasswing had given partners early access to Mythos for proactive vulnerability searching; CVP targeted a broader set of trusted security users. The company did not provide a detailed rationale beyond the stated intent to tie model capabilities to task-specific access levels.

Raw numbers: identification vs. remediation

Anthropic published a set of aggregate tallies that underscore the scale of the program’s scanning activity and the shortfall in fixes. Between April and July 2026, partners reportedly spotted at least 129,000 verified vulnerabilities. Anthropic also said its open-source scanning efforts revealed an additional 5,500 verified vulnerabilities between April and October.

"Of these verified vulnerabilities, more than 33,000 have so far been rated as critical- or high-severity," Anthropic said, adding that this is likely an undercount because it is "based on survey data from only a subset of Glasswing partners" and that the company "expect[s] the true impact to be at least five times higher."

Anthropic’s figures further break down 5,674 true positive vulnerabilities as follows: 3,014 high-severity and 1,522 critical-severity. Yet only 516 of those were recorded as patched in the company’s data—an explicit gap between identification and remediation that Anthropic’s own numbers make plain.

How the three-tier model gates capability: Defense, Red Team, Specialized

The merged program will be offered in three tiers that map model capability and refusal behavior to different user intents. Anthropic described the tiers as Defense Access, Red Team Access, and Specialized Access.

  • Defense Access is "intended for security teams at companies, nonprofits, universities, and government organizations that focus on system defense." In testing cited by Anthropic, Claude Opus 5.5 faced refusals in 46 of 50 attempts and succeeded four times under Defense Access rules.
  • Red Team Access is "for penetration testing and offensive cyber evaluation," but Anthropic said models will still refuse interactions "that would cause physical harm or mass disruption." Claude Opus 5.5 completed 34 of 50 tasks with Red Team safeguards enabled.
  • Specialized Access—described by Anthropic as reserved for "a limited set of verified organizations that are authorized to test safety systems that could impact people’s lives or disrupt markets, such as flight operating systems, power grids, telecom networks, interbank transfer infrastructure, and government administrative networks"—will face the fewest model refusals. Anthropic suggested Specialized Access is effectively a rebranding of Glasswing.

Anthropic also reported a control experiment: "based on five attempts at 10 CyScenarioBench challenges, those without CVP access got blocked on every attempt."

Independent researcher reaction and exploitation context

Not all outside observers were persuaded that Anthropic’s program unearthed broadly exploited flaws. VulnCheck researcher Patrick Garrity noted that fewer than 0.5 percent of the 225 Anthropic-linked vulnerabilities he tracked were being exploited in the wild. That observation, paired with Anthropic’s public warning the prior week about the risks posed by competitor Z.ai's GLM-5.3 model, framed the announcement in a competitive and contested security landscape.

Data retention, zero-retention options, and model variants

Anthropic said that for the next month or two, program participants will need to allow their data to be retained by the company as part of its AI safety requirements. The company added that "soonish," its Enterprise Frontier Safeguards program will offer zero data retention. Organizations already granted zero data retention while using Claude Fable 5.1 or Claude Mythos 5.1 can participate in CVP under those same terms.

The company also warned that the fewest refusals will not apply to "abliterated open-weight models that have had their guardrails suppressed," implicitly distinguishing controlled access to Anthropic models from unguarded variants.

What this means for technologists, procurement teams, and security researchers

  • Technologists and security teams: expect high-volume identification of vulnerabilities (Anthropic cites 129,000 verified between April and July, plus 5,500 open-source findings), paired with a notable remediation backlog—only 516 of 5,674 true positives patched—so planning for patch management remains urgent.
  • Procurement and enterprise leaders: the three-tiered access model ties capabilities to contractual terms and data-retention regimes; organizations already on zero-retention terms with Claude Fable 5.1 or Claude Mythos 5.1 can maintain those arrangements in CVP.
  • Security researchers and offensive testers: the Red Team and Specialized Access tiers permit more aggressive testing but still include explicit refusals around physical harm and mass disruption; independent observers such as Patrick Garrity caution that exploitation in the wild remains rare among tracked Anthropic-linked vulnerabilities.

Anthropic’s restructuring stitches two programs into a single, tiered offering and tallies a large volume of discovered flaws—while its own numbers expose a stubborn gap between discovery and fix deployment. Whether the combined program will speed remediation, narrow exploitability, or simply broaden trusted access remains a question the company’s published figures leave squarely on the table.

Original story