Anthropic's Project Glasswing initiative has verified at least 129,000 software vulnerabilities between April and July 2026, with more than 33,000 of them rated critical or high severity, the company disclosed on Tuesday alongside an expansion of its security access programs. But independent analysis of the findings tells a surprising story: almost none of the AI-discovered flaws have shown up in real-world attacks.
The Scale of AI-Driven Discovery For more context on this story, see our ongoing AI industry coverage.
The vulnerability totals come from Anthropic's own accounting of Project Glasswing, the initiative it launched in April to apply its frontier Claude models to hardening critical software. In addition to the 129,000 verified vulnerabilities found by Glasswing partners, the company said an open-source scanning effort uncovered a further 5,500 verified vulnerabilities between April and October 2026.
Anthropic cautioned that the severity figures are likely a significant undercount. The 33,000-plus critical and high-severity ratings are based on survey data from only a subset of Glasswing partners, and the company estimates the true impact could be at least five times higher.
For context, the U.S. National Vulnerability Database has in recent years logged roughly 28,000 to 40,000 new CVEs annually across the entire global software ecosystem. A single AI-driven program surfacing more than 129,000 verified issues in roughly three months signals how dramatically models such as Claude Opus 5.5 and Claude Mythos 5.1 are changing the economics of security research.
The Exploitation Gap
The more provocative finding comes from outside Anthropic. In an analysis published in late September, VulnCheck researcher Patrick Garrity examined 300 vulnerabilities credited to Anthropic or Project Glasswing and found that only 2 — approximately 0.67 percent — had been exploited in the wild.
The severity distribution of those 300 vulnerabilities breaks down as 39 critical, 141 high, 81 medium and 18 low. Yet the two that drew active exploitation were unglamorous classics:
- CVE-2026-26980, an SQL injection flaw in Ghost CMS, the popular open-source publishing platform.
- CVE-2026-61500, a session forgery flaw in Rejetto HTTP File Server, a widely deployed file-sharing tool.
Both are the kinds of long-tail web application vulnerabilities that mass scanners and opportunistic attackers have hunted for decades. Neither required frontier-model capability to weaponize — which is precisely the point the data makes. AI is surfacing enormous volumes of flaws that attackers never bothered to look for, and the flaws that get exploited in practice are still dominated by well-worn attack patterns against internet-exposed software.
Why the Gap Matters
The exploitation gap cuts both ways for defenders. On one hand, it suggests AI-driven discovery is running ahead of attacker adoption: defenders who patch AI-found issues are fixing vulnerabilities that might otherwise have lurked undiscovered for years. On the other hand, it warns that the bottleneck in security is shifting. When discovery becomes nearly free, triage, patch distribution and verification become the scarce resources.
"Not every security flaw AI uncovers is necessarily exploitable by threat actors or capable of causing significant impacts," as The Hacker News summarized the VulnCheck findings in its Tuesday coverage of the disclosure.
There is also a caution flag attached to the remediation side of the equation. Research from 1Password and Veracode has demonstrated that AI-generated vulnerability patches can themselves introduce new flaws, meaning the industry cannot simply point models at a CVE queue and consider the problem solved. Human verification remains essential at every step.
Ecosystem Reception
Glasswing has attracted attention well beyond Anthropic's customer base. Cloudflare, one of the program's partners, published its own account of working with the initiative in May, describing what the models surfaced across infrastructure it operates. Security commentators including cryptographer Bruce Schneier have tracked the program's updates, and the initial announcement drew one of the largest Hacker News discussions of the spring.
The 0.67 percent exploitation figure is itself notable in vulnerability economics. Historical analyses of CVE exploitation consistently show that only a small fraction of disclosed vulnerabilities are ever leveraged in observed attacks — but the sheer volume Glasswing is adding means even a tiny exploited fraction represents real incidents, and each unpatched flaw in internet-facing software is a lottery ticket for opportunistic attackers.
From Research Program to Operational Reality
Project Glasswing began in April 2026 with the goal of securing critical software for the AI era, and its initial updates reported rapid progress in finding memory-safety issues and web application flaws. The program now sits at the center of Anthropic's broader security strategy, alongside the newly restructured Cyber Verification Program that gives vetted security teams tiered access to models with reduced safeguards.
Anthropic's disclosure that partner-reported impact "is likely an undercount" also hints at the reporting lag inherent in coordinated vulnerability disclosure. Many of the 129,000 findings are presumably still moving through vendor patch cycles — a process that traditionally takes months and, at the scale Glasswing is producing, may strain disclosure infrastructure itself.
For security teams deciding where to spend scarce patching effort, exploitation still concentrates on a small number of internet-facing, easily weaponized bug classes — SQL injection and session handling flaws among them — while the long tail of AI-found issues waits in the queue.
For software maintainers, the message is blunt: the era in which obscure flaws could safely remain obscure is ending. For security teams deciding where to spend scarce patching effort, the VulnCheck data offers a counterintuitive guide — the AI-found vulnerability backlog is enormous, but exploitation still concentrates on a small number of internet-facing, easily weaponized bug classes.
The numbers from Glasswing's first six months make one thing clear: AI hasn't just joined the vulnerability discovery race, it has broken the scale on which the race was measured. What remains to be seen is whether patching, disclosure and exploitation can keep up with discovery — or whether the industry's to-do list simply grows faster than anyone can work through it.
---
Stay Ahead of AIGet the latest AI news, analysis, and breakthroughs — all in one place.
Read more AI news →