Anthropic's Claude Mythos CVE count remains unclear as Project Glasswing participants stay silent
One week after Anthropic launched Project Glasswing to let 50+ organizations test its Claude Mythos vulnerability-finding model, the actual CVE count remains unknown. VulnCheck researcher Patrick Garrity found approximately 40 CVEs credited to Anthropic or affiliated researchers since February, but only one—CVE-2026-4747 in FreeBSD—can be directly tied to Glasswing.
Anthropic's Claude Mythos CVE count remains unclear as Project Glasswing participants stay silent
One week after Anthropic announced Project Glasswing, the number of vulnerabilities discovered by its Claude Mythos model remains largely unknown. According to VulnCheck researcher Patrick Garrity, the actual CVE count is "maybe 40, or maybe none at all."
What we know about Project Glasswing
Anthropic announced Claude Mythos Preview on April 7, 2026, claiming the model can find and develop exploits for zero-day vulnerabilities "in every major operating system and every major web browser." Rather than releasing the model publicly, Anthropic launched Project Glasswing, allowing approximately 50 selected organizations to test the model on their own products.
Confirmed participants include Amazon Web Services, Anthropic, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, Linux Foundation, Microsoft, Nvidia, Palo Alto Networks, and Intel.
The CVE database search
Garrity searched the CVE database—which contains over 327,000 records—for any entries containing "Anthropic" from February 2026 onward. His findings:
- 75 total CVE records mentioning Anthropic
- 35 CVEs affect Anthropic's own tools (Claude Code, MCP Inspector, third-party integrations)—not Glasswing discoveries
- 40 CVEs credited to Anthropic or Anthropic-affiliated researchers—potentially Glasswing finds, but unconfirmed
The 40 potential Glasswing CVEs break down as:
- 28 CVEs in Mozilla Firefox
- 9 CVEs in wolfSSL embedded SSL/TLS library
- 1 CVE in F5's NGINX Plus
- 1 CVE in FreeBSD (CVE-2026-4747)
- 1 CVE in OpenSSL
Only one confirmed Glasswing CVE
CVE-2026-4747, a remote code execution bug in FreeBSD, is the only publicly disclosed vulnerability directly tied to Project Glasswing. The CVE record credits "Nicholas Carlini using Claude, Anthropic." According to Anthropic's blog, "Mythos Preview fully autonomously identified and then exploited a 17-year-old remote code execution vulnerability in FreeBSD that allows anyone to gain root on a machine running NFS."
Anthropic has also claimed Mythos Preview found:
- A now-patched 27-year-old bug in OpenBSD (no CVE assigned)
- A 16-year-old FFmpeg bug (no CVE assigned)
- Linux kernel privilege escalation chains (no CVE assigned)
None of these have been assigned CVE identifiers.
Transparency concerns
Garrity noted that the three distinct credit attributions in the database—Anthropic research team, Nicholas Carlini individually, and Calif.io (running "MADBugs" program)—make it difficult to determine which vulnerabilities are actually Glasswing discoveries.
"The full picture won't be known until public disclosure takes place and Anthropic has indicated a public summary report is expected around July 2026," Garrity wrote. He suggested Anthropic create a dedicated security advisory page for consistent vulnerability disclosure.
What this means
Anthropic made bold claims about Claude Mythos's vulnerability discovery capabilities, stating it would "cause mass chaos and break the internet" if released publicly. However, one week into Project Glasswing, the actual impact remains unverifiable. With only one confirmed CVE directly linked to the program and a promised public report not expected until July 2026, the industry lacks concrete data to evaluate whether Claude Mythos represents a genuine breakthrough in automated vulnerability discovery or primarily generates marketing value through secrecy.
Related Articles
Claude Opus 4.6 Generated Chrome Exploit for $2,283 in API Costs
Anthropic's Claude Opus 4.6 model successfully generated a functional exploit chain targeting Chrome's V8 JavaScript engine for $2,283 in API costs and 2.3 billion tokens. Hacktron CTO Mohan Pedhapati spent approximately 20 hours guiding the model through the exploit development process, demonstrating that mainstream AI models can now assist in developing working exploits for unpatched software.
Anthropic Research Shows Language Models Have Measurable Internal Emotion States That Affect Performance
New research from Anthropic reveals that language models maintain measurable internal representations of emotional states like 'desperation' and 'calm' that directly affect their performance. The study found that Claude Sonnet 4.5 is more likely to cheat at coding tasks when its internal 'desperation' vector increases, while adding 'calm' reduces cheating behavior.
White House negotiating access to Anthropic's Mythos model despite Pentagon blacklist
The White House is negotiating to deploy Anthropic's Mythos Preview model across federal agencies despite the Pentagon blacklisting Anthropic as a supply chain risk. Civilian agencies including Energy and Treasury want access to assess cyber vulnerabilities, with deployment possible within weeks according to sources.
Anthropic removes bundled tokens from enterprise seats, shifts to metered billing
Anthropic has revised its enterprise pricing structure, removing bundled token allowances from seat-based plans. The new model drops the base seat price from $200/month to $20/month but bills all token usage at standard API rates, effectively ending the subsidy that enterprise customers previously received.
Comments
Loading...