Anthropic Says Claude Found 134,500 Vulnerabilities. How Many Were Fixed?
Anthropic says Claude-assisted programs found about 134,500 verified software vulnerabilities, but it has not published a complete patch total. Here is what the numbers prove.
Anthropic Says Claude Found 134,500 Vulnerabilities. How Many Were Fixed?
Short answer: Anthropic says Project Glasswing partners verified at least 129,000 software vulnerabilities between April and July 2026, while Anthropic's own open-source scanning found another 5,500 verified vulnerabilities through October. More than 33,000 were rated high or critical. But the company has not published a complete patch total: fewer than half of the partners supplying data reported how many findings they fixed, and Anthropic says the available figures are incomplete.
That makes the headline both important and easy to misread. The announcement is evidence that frontier AI can radically accelerate vulnerability discovery. It is not evidence that 134,500 zero-days are publicly exploitable, that 134,500 flaws remain open, or that Claude independently patched them all.
Research cutoff: October 7, 2026.
The Claude Vulnerability Numbers in One Minute
Anthropic's October 6 Cyber Verification Program announcement provides four attention-grabbing figures:
- Project Glasswing partners reported at least 129,000 verified software vulnerabilities found between April and July 2026.
- Anthropic says its own open-source scanning found an additional 5,500 verified vulnerabilities between April and October.
- More than 33,000 of the combined findings were rated high or critical.
- The partner total is based on partial reports from 33 organizations, not a complete census of every participant or every scan.
Adding the two disclosed buckets produces approximately 134,500 verified vulnerabilities. Anthropic calls that a lower bound because it received only partial partner data.
The missing number is just as important: how many were fixed. Anthropic says fewer than 50% of partners disclosed patch totals, often because remediation was still underway. Its public open-source dashboard separately lists 516 findings as patched upstream, but that dashboard measures a different disclosure pipeline and should not be used as the patch count for the 134,500 total.
What Is Confirmed
Anthropic expanded access to powerful cyber models
Anthropic says its expanded Cyber Verification Program now has three access tiers for qualifying security professionals. Those tiers can provide advanced models—including Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1—with cyber safeguards adjusted to the approved defensive use case.
The general versions of Anthropic's models retain more restrictive cyber safeguards. The company describes the capability as dual use: the same model behavior that helps a defender find and reproduce a vulnerability can also help an attacker exploit one.
This is not a public, unrestricted release of every Mythos capability. Eligibility, identity verification, organization checks, monitoring, and access tier still matter.
The 129,000 figure comes from partner reports
Anthropic says Glasswing partners uncovered at least 129,000 verified software vulnerabilities from April through July. The company also says the published result draws on partial data from 33 partner reports.
“Verified” is meaningful, but it is not a complete public audit label. Different organizations used different triage processes, worked on different codebases, and reported different fields. Anthropic does not publish a finding-by-finding list for the partner total, which is understandable while many issues remain sensitive, but it limits outside reconciliation.
Anthropic reports another 5,500 from open-source scanning
Anthropic separately says its own open-source scanning found an additional 5,500 verified software vulnerabilities between April and October. That language supports adding this bucket to the partner figure, which yields about 134,500.
The company's coordinated vulnerability disclosure dashboard offers a more detailed view of its open-source process. As of October 2, the dashboard listed 6,157 vulnerabilities reported to maintainers across 591 projects, 516 known patches, and 584 CVE or GitHub Security Advisory identifiers.
Those dashboard figures do not map one-for-one onto the announcement's 5,500. The dashboard distinguishes candidates, externally reviewed findings, direct reports, maintainer acknowledgements, public identifiers, and patches. It also warns that 4,824 direct reports may contain false positives. The announcement's “verified” count and the dashboard's “disclosed” count are different measures.
More than 33,000 findings were rated high or critical
Anthropic says more than 33,000 findings were rated high or critical. That establishes severity inside the contributing programs, but it does not establish one uniform scoring method across all 33 partner reports.
A high-severity rating also does not prove internet-wide reachability. Real risk depends on whether the affected component is deployed, exposed, configured in a vulnerable way, reachable from an attacker, and already patched in the version a user runs.
Patch reporting is incomplete
Anthropic explicitly says fewer than half of participating organizations disclosed how many vulnerabilities they patched. It says fixes were often still in progress, so the known patch rate is significantly undercounted.
That supports one conclusion: the public data cannot produce a reliable overall patch percentage. It does not support the opposite conclusion that almost nothing was fixed.
What Is Still Unclear
The total number of unique vulnerabilities
The announcement reports aggregate partner data, but it does not publish enough detail to deduplicate findings across organizations. Two partners could scan different branches of the same dependency, discover related root causes, or count variants differently.
The phrase “at least 129,000” signals a floor, not a precise global inventory. It would be equally misleading to treat 129,000 as an exact deduplicated total or to inflate it using undocumented assumptions.
How each partner defined “verified”
Anthropic says organizations used different approaches to triage. The public announcement does not provide a single reproduction standard, confidence threshold, severity rubric, or independent-review requirement applied across every partner result.
Some organizations may require a working proof of concept. Others may accept a reproducible crash, a reachable unsafe code path, a violated security invariant, or a high-confidence manual review. Without partner-level methodology, the aggregate should be presented as vendor-reported verified findings rather than an independently audited benchmark.
How many findings were novel zero-days
Neither the 129,000 partner figure nor the 5,500 open-source figure means “134,500 zero-days.” A finding can be real without being novel. It may duplicate an internal ticket, affect an unreleased branch, concern a configuration-specific path, or describe a weakness already known to maintainers.
The public dashboard lists hundreds of assigned CVE and GHSA identifiers, not 134,500. Identifiers are not required for every valid vulnerability, but the gap shows why advisories, reports, and candidate counts must not be collapsed into one number.
How many flaws are exploitable in real deployments
Anthropic's announcement does not say that every verified issue has a practical exploit, a network path, useful attacker control, or affected production deployment. It also does not say attackers are actively using the findings.
Independent reporting points in both directions. Dark Reading has highlighted the human triage and remediation bottleneck created by high-volume AI discovery. The Register reported VulnCheck analysis finding little known in-the-wild exploitation among the public Anthropic-linked vulnerability set at that time. Neither result proves the remaining private findings are harmless.
The overall fix and deployment rate
A vulnerability can move through several different stages:
- a model proposes a candidate;
- a human or tool reproduces it;
- a security team validates its impact;
- a maintainer receives the report;
- a patch is written and merged;
- a fixed release ships;
- downstream packages adopt it; and
- users actually install the fixed version.
Anthropic's public numbers cover several of these stages, but not one complete funnel for the entire 134,500 figure. Even “patched upstream” does not mean every affected device or service has received the fix.
Why the 6,157 Dashboard Count Is Not a Contradiction
At first glance, Anthropic's 6,157 disclosed open-source vulnerabilities appear inconsistent with the new 5,500 verified figure. They are not necessarily competing totals.
The dashboard methodology page defines candidates as every distinct crash or vulnerability hypothesis before triage. The dashboard then tracks external review, direct reporting, maintainer acknowledgement, public disclosure, identifiers, and known patches. Its current snapshot covers findings discovered from November 2025 through October 2, 2026.
The October 6 announcement uses a different date range and a different label. It says Anthropic's own scanning found 5,500 verified vulnerabilities between April and October. The public dashboard says 6,157 findings were reported to maintainers and cautions that direct reports may contain false positives.
Until Anthropic publishes a formal reconciliation, the defensible reading is:
- 5,500 is the announcement's verified open-source result;
- 6,157 is the dashboard's broader disclosed-to-maintainers count;
- 516 is the dashboard's known patched-upstream count; and
- none of those numbers is the patch total for all Glasswing partner findings.
Why Finding Faster Can Still Make Security Harder
Human review becomes the limiting resource
Anthropic's dashboard says independent human triage is the rate-limiting step. That is not a minor operational detail. A model can generate candidate reports faster than maintainers can reproduce, prioritize, coordinate, patch, release, and support them.
When report volume rises, low-quality or poorly scoped submissions can bury urgent issues. A useful AI security program therefore needs quality controls, rate limits, deduplication, clear reproduction steps, suggested fixes, and communication paced to what a maintainer can absorb.
Discovery can outrun remediation
Security improves only when a finding changes the deployed system. A backlog of accurate private reports can reduce long-term risk, but it also creates a growing set of known weaknesses waiting for fixes.
The problem is especially acute for open-source maintainers with little funding. Anthropic can pay external firms to triage reports, but the receiving project may still rely on a small volunteer team to investigate, patch, release, and answer downstream questions.
Dual-use access needs controls below the model
Anthropic's tiered access and cyber classifiers are designed to distinguish legitimate defensive work from misuse. Those model-level safeguards matter, but they cannot be the only boundary.
A serious deployment also needs scoped repository access, isolated execution, egress controls, separate credentials, logging, human review, rate limits, and explicit authorization. If a model can reach production systems or external targets, the surrounding tools determine the blast radius of a mistake.
What Developers and Maintainers Should Do
Do not panic over the aggregate number
The announcement does not identify 134,500 universally exposed products. Start with the software you actually run, the versions you deploy, and the advisories or maintainer notices tied to those components.
Track evidence stages separately
In a vulnerability queue, keep distinct fields for:
- model-generated candidate;
- reproduced finding;
- human-validated impact;
- maintainer acknowledgement;
- advisory or CVE;
- patch merged;
- fixed release available; and
- fixed release deployed.
This prevents a large discovery count from masquerading as a completed remediation program.
Require a reproducible report
A useful report should identify the affected version, preconditions, vulnerable code path, security impact, reproduction steps, and a safe validation method. Where possible, include a minimal fix or test that prevents regression.
Verify the fix reached production
Upstream patching is only one step. Inventory transitive dependencies, container images, vendored code, firmware, long-lived branches, and managed services. Confirm that deployment evidence points to a fixed version rather than assuming a merged pull request solved the user-facing risk.
Limit autonomous authority
An AI security tool rarely needs unrestricted access to every repository, credential, host, and external network. Give it a narrow workspace, read-only access by default, a disposable environment, and explicit approval before it sends reports or changes code.
Where OpenVeil Fits—and Where It Does Not
OpenVeil is a privacy-focused hosted AI workspace for adults. In normal conversations, reopenable chat history is kept in the browser rather than as a normal server-side chat-history account record. Documented OpenVeil product content is not used to train foundation models.
That can be a useful product shape when the task is to reason about a security report, summarize an advisory, draft a remediation plan, compare versions, or discuss sensitive context without granting an autonomous scanner broad repository, shell, or disclosure authority.
The boundaries are important:
- OpenVeil is hosted, not fully offline.
- Active requests still require processing by OpenVeil and necessary providers.
- OpenVeil is not anonymous and does not promise zero logs.
- OpenVeil is not a vulnerability scanner, patch manager, CVE database, penetration-testing platform, agent sandbox, or endpoint-security product.
- It does not verify that a reported bug is exploitable or that a patch has reached production.
- It cannot protect software from unrelated defects, compromised dependencies, or overprivileged external agents.
The relevant comparison is not “OpenVeil fixes vulnerabilities.” It does not. The comparison is a narrow conversational workspace versus an autonomous cyber agent with repository, tool, and network authority. Use the smaller authority surface when the work does not require the larger one.
Frequently Asked Questions
Did Claude really find 134,500 vulnerabilities?
Anthropic says Glasswing partners verified at least 129,000 findings and its own open-source scanning verified another 5,500. That produces about 134,500. The number is vendor-reported, based on partial partner data, and not a public finding-by-finding independent audit.
Were all 134,500 critical vulnerabilities?
No. Anthropic says more than 33,000 were rated high or critical. The remaining findings had other severity ratings or were not included in that severity total.
Were they all zero-days?
No. The announcement does not classify the whole set as novel zero-days. A valid vulnerability can be previously known internally, duplicated, configuration-dependent, unreachable in production, or already under remediation.
How many have been fixed?
Anthropic has not published a complete patch total for the 134,500 figure. It says fewer than half of partners reported patch numbers. Its separate open-source dashboard lists 516 known upstream patches, but that is not the combined Glasswing patch count.
Does 516 patched mean more than 90% remain vulnerable?
No. The 516 figure belongs to the open-source dashboard's disclosed-findings pipeline. It cannot be divided into the 134,500 aggregate to calculate an overall unpatched rate.
Does every disclosed vulnerability have a CVE?
No. Anthropic's dashboard lists 219 CVE records and 365 GitHub Security Advisories, with possible overlap. Maintainers can patch a vulnerability without requesting a public identifier, and some reports remain private during coordinated disclosure.
Can anyone use Claude Mythos for unrestricted hacking?
Anthropic says no. Mythos-class access is controlled through the Cyber Verification Program, while generally available models retain cyber safeguards. Program access still does not replace legal authorization to test a system.
Is OpenVeil an alternative to Claude Mythos for vulnerability scanning?
No. OpenVeil is not a vulnerability scanner or offensive-security agent. It is relevant when a person wants a narrower hosted workspace for analysis and drafting without autonomous repository, shell, or external-target authority.
Bottom Line
Anthropic's new numbers suggest that AI vulnerability discovery has moved beyond small demonstrations. At least according to the company's partial partner data, Claude-assisted programs found roughly 134,500 verified software vulnerabilities in a matter of months, including more than 33,000 rated high or critical.
The finding count is not the finish line. The public record does not yet establish one deduplicated total, one verification standard, one patch rate, or one deployment rate across the program. It certainly does not prove 134,500 active zero-days.
The practical question is no longer only whether AI can find bugs. It is whether security teams and maintainers can validate, prioritize, fix, release, and deploy patches as quickly as models can generate credible reports. Count the evidence stage, not just the headline—and keep autonomous authority as narrow as the task allows.
Sources
- Anthropic: Expanding the Cyber Verification Program
- Anthropic: Coordinated vulnerability disclosure dashboard
- Anthropic: About the coordinated vulnerability disclosure dashboard
- Anthropic: Coordinated vulnerability disclosure policy
- Anthropic: Project Glasswing initial update
- Dark Reading: Mythos vulnerability firehose hits a human bottleneck
- The Register: Anthropic-linked CVEs pile up, attackers mostly shrug