New serious vulnerabilities spiked around release of Claude Mythos Preview

Hacker News Top News

Summary

A spike in high- and critical-severity CVE disclosures followed Anthropic's release of Claude Mythos Preview, which can autonomously discover software vulnerabilities, leading to a 3.5x increase in monthly records.

No content available
Original Article
View Cached Full Text

Cached at: 07/03/26, 11:17 PM

# Disclosed CVEs: 3.5× Spike After Claude Mythos Source: [https://epoch.ai/data-insights/cve-severity-spike](https://epoch.ai/data-insights/cve-severity-spike) Severe cybersecurity vulnerability disclosures \(CVEs\) spiked in 2026\. In June, notable organizations published around 1,500 high\- and critical\-severity CVEs — more than 3\.5× the monthly record prior to Mythos’ release\. The spike follows Anthropic’s April announcement that Claude Mythos Preview could[autonomously discover software vulnerabilities](https://red.anthropic.com/2026/mythos-preview/), and that the company’s Project Glasswing partners — including Microsoft, Google, Apple, and AWS — had been using it to find and fix bugs ahead of the model’s public release\. Since its commencement, Project Glasswing[claims to have found over 10,000 high\- or critical\-severity vulnerabilities](https://www.anthropic.com/research/glasswing-initial-update), many of which have yet to be individually disclosed\. Similar efforts have been undertaken by OpenAI with their[Daybreak](https://openai.com/daybreak/)product\. Epoch's work is free to use, distribute, and reproduce provided the source and authors are credited under the Creative Commons BY license\. ## Learn more about this graph In April 2026, Anthropic[announced](https://red.anthropic.com/2026/mythos-preview/)that its latest internal model \(Claude Mythos Preview\) was capable of autonomous cybersecurity vulnerability discovery and exploitation\. Since then, both[Anthropic](https://www.anthropic.com/glasswing)and[OpenAI](https://openai.com/daybreak/)have launched efforts to use frontier models to harden critical software before malicious actors are able to use the same models for harm\. We show that the number of Common Vulnerabilities and Exposures \(CVEs\) jumped significantly following these announcements\. Compared to the previous monthly record before the Mythos Preview announcement, the number of high\- and critical\-severity vulnerabilities increased more than 3\.5x in June\. ### Data ### Assumptions and limitations ## Download this data [https://epoch.ai/data/charts/cve-severity-spike-di/cve_severity_monthly.csv](https://epoch.ai/data/charts/cve-severity-spike-di/cve_severity_monthly.csv)Monthly high\- and critical\-severity CVEs from 21 notable organizations CSV,Updated Jul\. 2, 2026

Similar Articles

Cloudflare just published what they found after running Anthropic's Mythos Preview against 50+ of their own repos and the results are worth reading

Reddit r/artificial

Cloudflare shares their experience with Anthropic's Mythos Preview model, which autonomously discovered high-severity vulnerabilities across major OS and web browsers. The model demonstrates senior-level reasoning in chaining exploit primitives but has inconsistent guardrails, highlighting the need for hardened safeguards before public release.

Anthropic Claude Code Leak Reveals Critical Command Injection Vulnerabilities

Lobsters Hottest

Critical command injection vulnerabilities (CVE-2026-35022, CVSS 9.8) discovered in Anthropic's Claude Code CLI and SDK allow attackers to execute arbitrary commands and steal credentials through environment variables, file paths, and authentication helpers. The flaws enable poisoned pipeline execution attacks in CI/CD environments, requiring immediate patching and configuration changes.