Claude Mythos AI Uncovers 10,000+ High-Severity Flaws in Critical Software
Anthropic's Project Glasswing, using Claude Mythos Preview, has identified over 10,000 high- or critical-severity vulnerabilities in widely used software, with patching now the main bottleneck.

Overview
Anthropic has announced that its Project Glasswing initiative, leveraging the Claude Mythos Preview AI model, has uncovered more than 10,000 high- or critical-severity vulnerabilities across systemically important software worldwide since its launch last month. The project grants approximately 50 partners early access to the frontier model to autonomously identify flaws before malicious actors can exploit them.
Key Findings
Of the vulnerabilities discovered, 6,202 were classified as high- or critical-severity, impacting over 1,000 open-source projects. Subsequent analysis of 1,752 of these candidates confirmed 1,587 (90.6%) as valid true positives, with 1,094 (62.4%) assessed as high- or critical-severity. One notable example is a critical flaw in WolfSSL (CVE-2026-5194, CVSS 9.1) that could allow certificate forgery. So far, 97 findings have been patched upstream, and 88 advisories issued.
Impact on Patching
Anthropic acknowledged that the ease of finding vulnerabilities now outpaces the ability to fix them, creating a major cybersecurity challenge. Partners like Cloudflare and Mozilla have reported bug-finding rates increasing by over tenfold. The company urges developers to shorten patch cycles and deploy fixes quickly, noting that Oracle has already shifted to a monthly patch cycle.
Additional Capabilities
Beyond vulnerability discovery, Mythos Preview has been used for fraud detection—one partner bank prevented a fraudulent $1.5 million wire transfer. Anthropic also launched a Cyber Verification Program allowing security professionals to use the model without guardrails for legitimate research, similar to OpenAI's Daybreak program.
Future Plans
Anthropic plans to expand Project Glasswing with government partners and eventually release Mythos-class models publicly once adequate safeguards are developed. The company emphasizes that network defenders should harden configurations, enforce multi-factor authentication, and maintain comprehensive logs.