News · curated 21 Sep 2026
Anthropic-linked CVEs pile up, attackers mostly shrug
First reported theregister.com
Coverage timeline
Single-source analysis — first reported, latest, and curated coincide.
Why it matters
AI models capable of finding and exploiting 0-days have raised fears of a flood of weaponized CVEs, but the data suggests AI-discovered flaws are so far not translating into meaningful real-world exploitation, tempering expectations for defenders.
The Register reports that of 225 CVEs credited to Anthropic or its Project Glasswing initiative (which gives vetted partners access to the Claude Mythos Preview model for bug-finding), only one — a critical SQL injection flaw in Ghost (CVE-2026-26980) — has confirmed exploitation in the wild, according to VulnCheck researcher Patrick Garrity's tracker. Garrity argues that what Anthropic's AI is discovering is limited in impact and produces outcomes no different from a random selection of vulnerabilities.