
Anthropic Widens Vetted AI Cyber Access After 129,000 Flaw Finds
Anthropic says Project Glasswing found 129,000 verified vulnerabilities and will let more vetted teams use Claude with fewer safety blocks.
Anthropic announced on Tuesday that it is expanding a program that lets vetted cybersecurity professionals test its advanced artificial intelligence models with reduced safeguards and blocking classifiers. The company said its Project Glasswing initiative uncovered at least 129,000 verified software vulnerabilities between April and July 2026, and another 5,500 verified flaws between April and October 2026 through open-source scanning.
Of those verified vulnerabilities, more than 33,000 have been rated as critical or high severity, according to Anthropic. The company cautioned that this number is likely an undercount because it comes from survey data covering only a subset of Glasswing partners. As a result, Anthropic expects the true impact to be at least five times higher.
The expanded offering is called the Cyber Verification Program (CVP). It has three access tiers, and each tier includes access to Anthropic's models, specifically Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and new models as they become available. The first tier, Defense Access, is meant for defensive work such as incident response, malware reverse engineering, and vulnerability analysis and validation. The second, Red Team Access, adds authorized penetration testing and red teaming, where testers simulate real attacks with permission, on top of the defensive use cases. The third, Specialized Access, has the fewest safeguards and is reserved for a limited group of verified organizations that are authorized to test safety systems.
Anthropic also shared evaluation results from a benchmark called CyScenarioBench. On Claude Opus 5.5 in the Defense Access tier, the built-in safeguards blocked 46 of 50 tasks. In the Red Team Access tier on the same model, no tasks were blocked and the system completed 34 of 50, the same completion rate as when no safeguards are applied. Without any CVP access, every task was blocked on the first prompt. Anthropic said these results give the company confidence that advanced cyber capabilities can be made safely available to a broader set of defenders, expanding the defensive work begun with Project Glasswing. The company said it is offering the tools because of their dual-use nature, meaning the same capabilities that could be misused by an attacker can also help defenders secure systems.
An analysis by VulnCheck researcher Patrick Garrity, published late last month, looked at 300 vulnerabilities discovered by Anthropic or Project Glasswing. Only two of them, or 0.67 percent, have been exploited in the wild. The severity distribution among those 300 was 39 critical, 141 high, 81 medium, and 18 low. The two actively exploited flaws are CVE-2026-26980, an SQL injection flaw in Ghost CMS, and CVE-2026-61500, a session forgery flaw in Rejetto HTTP File Server. An SQL injection flaw allows an attacker to insert unauthorized database commands through a form or input field, while a session forgery flaw lets an attacker create a fake logged-in session to impersonate a user.
The broader picture is that AI is lowering the barrier to finding vulnerabilities, but not every flaw an AI uncovers is necessarily exploitable by real attackers or capable of causing significant damage. Separate work by 1Password and Veracode has shown that AI-generated vulnerability patches can themselves introduce new security risks. Veracode reported that roughly 44 percent of AI code generation tasks introduced a risky security vulnerability in tests. The average security pass rate across models was 56 percent, barely changed from 55 percent in the first report. In other words, security performance has stayed flat while the amount of AI-generated code entering pipelines has surged. For website owners and IT teams, the small share of exploited flaws does not mean the rest are harmless, but it does suggest that patching should be based on actual exploitability where possible rather than treating every automated finding as an emergency.
For website owners and IT teams, the takeaway is that AI-assisted vulnerability discovery is useful, but automated fixes still need human review before they reach production. Managed WordPress hosting such as AEU Hosting can handle routine patching and security monitoring, giving teams a protected baseline while they evaluate any AI-assisted changes.
How to Protect Yourself
- Keep your website software, plugins, and themes updated, but test updates on a separate staging copy before applying them to your live site.
- Use a unique strong password for every admin account and turn on two-factor authentication so stolen or forged sessions are harder to use.
- If you run Ghost CMS or Rejetto HTTP File Server, check for patches for CVE-2026-26980 and CVE-2026-61500 and install them as soon as possible.
- Do not blindly deploy AI-generated code or patches; ask a developer to review them for new security mistakes before putting them on a real website.
- Back up your website and database regularly to a safe location so you can restore quickly if a vulnerability is exploited or a bad update breaks things.
Vulnerabilities & Fixes
- CVE-2026-26980 An SQL injection flaw in Ghost CMS; the source says it was one of two vulnerabilities exploited in the wild. View the fix & details →
- CVE-2026-61500 A session forgery flaw in Rejetto HTTP File Server; the source says it was one of two vulnerabilities exploited in the wild. View the fix & details →
Terms Explained
- Artificial intelligence (AI) Computer systems that can perform tasks that normally require human intelligence, such as finding patterns in code.
- Vulnerability A weakness in software that an attacker could use to break in or cause damage.
- Red teaming Authorized simulated attacks that test how well a system defends itself.
- Penetration testing A security test where an approved tester tries to break into a system to find weaknesses.
- SQL injection An attack that sends malicious database commands through a form or input field.
- Session forgery An attack that creates a fake logged-in session to impersonate a user.
- CVE Common Vulnerabilities and Exposures, a public list that gives standard names to known security flaws.
- Patch A software update that fixes a vulnerability.