Research · curated 5 Jul 2026
Disclosed CVEs: 3.5× Spike After Claude Mythos | Epoch AI
First reported anthropic.com
Coverage timeline
Single-source analysis — first reported, latest, and curated coincide.
Why it matters
Frontier LLMs capable of autonomously finding and exploiting zero-days materially change the offensive/defensive balance, and the surge in disclosures signals both accelerated hardening and a looming risk if malicious actors gain the same capability.
Epoch AI reports a more-than-3.5x spike in high- and critical-severity CVE disclosures (around 1,500 in June 2026) from 21 major organizations, correlated with Anthropic's April 2026 announcement that Claude Mythos Preview can autonomously discover and exploit software vulnerabilities. Anthropic's Project Glasswing and OpenAI's Daybreak have used frontier models to find and fix bugs, with Glasswing claiming over 10,000 high/critical vulnerabilities identified.