Anthropic's Project Glasswing — Claude Mythos identifies 10,000+ critical vulnerabilities, kept restricted-access for safety
TL;DR: Anthropic published a Project Glasswing update on May 26, 2026: Claude Mythos Preview — the company’s unreleased frontier model — has identified more than 10,000 high- or critical-severity vulnerabilities in production software through the program’s partner channel. Notable findings include a 17-year-old FreeBSD remote-code-execution flaw (CVE-2026-4747) that the model identified and exploited autonomously. Partners: AWS, Apple, Broadcom, Cisco, Cloudflare, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, Mozilla, NVIDIA, Palo Alto Networks, plus open-source community partners. Status: Mythos remains restricted-access. Anthropic’s framing: “no company — including Anthropic — has developed safeguards strong enough to prevent such models from being misused.” This is the most concrete demonstration to date that a frontier-grade model can autonomously find production-software vulnerabilities at scale — and the first one where the model’s creator explicitly chose not to ship it generally available.
What was reported
The reporting from Anthropic’s official Glasswing pages, Help Net Security, The Hacker News, Cybersecurity News, and other security press confirms:
- Date of update: May 26, 2026
- Model: Claude Mythos Preview (unreleased; restricted-access only)
- Vulnerabilities identified: more than 10,000 high- or critical-severity
- Scope: every major operating system, every major web browser, plus a range of other critical software components
- Notable specific finding: CVE-2026-4747 — a 17-year-old FreeBSD remote-code-execution flaw in the NFS implementation, autonomously identified and exploited by Mythos Preview
- Disclosure model: vulnerabilities reported to vendors via Project Glasswing’s coordinated disclosure channel
The full partner list
Project Glasswing’s announced partners across the program lifecycle:
- AWS (Amazon Web Services)
- Apple
- Broadcom
- Cisco
- Cloudflare
- CrowdStrike
- JPMorgan Chase
- The Linux Foundation
- Microsoft
- Mozilla
- NVIDIA
- Palo Alto Networks
- Plus open-source community partners
This is one of the more substantial cross-industry security partnership lists assembled by a single program in recent memory. Notably it includes both major cloud providers (AWS, Google, Microsoft), both major browser vendors (Mozilla, plus indirect via Apple and Google), and both major endpoint-security companies (CrowdStrike, Palo Alto Networks).
The restricted-access decision
The structural story most coverage misses: Anthropic chose not to make Mythos generally available. The Anthropic statement quoted by Help Net Security:
“At present, no company — including Anthropic — has developed safeguards strong enough to prevent such models from being misused.”
This is a meaningful change in the public framing of frontier-model safety. Through 2024-2025, the standard pattern was “we’ll release with safety mitigations.” Glasswing flips that to “we won’t release, full stop, until safeguards are stronger” — and the company says so publicly.
For a security capability of this scale — finding and exploiting zero-days at the pace Mythos demonstrates — the dual-use concern is concrete. The same capability that lets AWS patch a kernel flaw also lets an attacker chain it with privilege escalation. Anthropic’s restricted-access stance reflects that asymmetry: hostile actors don’t need 10,000 vulnerabilities to do damage; they need one. Releasing a model that can find one is releasing a model that can find tens of thousands.
What this signals about Anthropic’s positioning
This is the eighth major Anthropic positioning signal in roughly two weeks:
- May 13 — Ramp AI Index crosses OpenAI in U.S. business adoption
- May 14 — Gates Foundation $200M partnership
- May 18 — Stainless acquisition
- May 19 — Karpathy joining pre-training team
- May 19 — KPMG global alliance
- May 20 — First projected profitable quarter + $30B raise at $900B valuation
- May 22 — OpenAI’s confidential S-1 filing (the competitive context)
- May 26 — Project Glasswing 10K-vulnerability milestone (this story)
The pattern is consistent: enterprise positioning, capital, talent, profitability, and now safety leadership. Project Glasswing is the safety-credibility leg of the four-legged stool that the Anthropic IPO target of October 2026 will rest on. “We have a frontier-grade security model we chose not to ship” is a story that investors and regulators both find more reassuring than “we shipped everything we built.”
What it means for Claude users
Practically: nothing changes about your Claude Pro or Claude Code subscription. Mythos is a separate model and is not exposed via the public API.
What changes structurally: when Mythos-class capabilities do eventually become broadly available — whether through Anthropic’s own product surface or via a comparable model from another lab — the security industry’s threat model has to update. Coordinated-disclosure programs, vendor-side patching velocity, and end-user update discipline all need to account for the possibility that any single weekend, a model run can produce 100+ exploitable zero-days in production software. The Glasswing partner list is the security-industry’s pre-positioning for that world.
For Claude Code and Claude reviews, the immediate implication is that Anthropic’s safety reputation tightens further. The company is becoming the AI lab most likely to be trusted with regulated-industry deployments, in part because it visibly leaves capability on the table when the downside risk is severe.
The honest caveats
Two caveats worth surfacing:
The 10,000 number depends on classification. “High or critical severity” is a standard CVSS-based bracket, but the exact severity assignments come from Anthropic and partner triage. Independent verification of all 10,000 isn’t publicly available; the number should be treated as Anthropic’s claim, not as an audited public dataset.
“Restricted-access” is not “permanently held.” Anthropic states Mythos-class models will eventually be made available, contingent on safeguards. The actual release timeline isn’t specified. If a competing lab ships an equivalent-capability model first, Anthropic’s restraint becomes a competitive disadvantage rather than a leadership signal.
What it changes for Pick Right readers tomorrow
If you’re a Claude subscriber, nothing changes about your subscription. If you’re a Claude Code user, the model you use is unaffected.
What the news does confirm is the trajectory of Anthropic’s positioning: enterprise-leadership (KPMG alliance, Ramp lead) → capital ($30B raise) → talent (Karpathy) → profitability (Q2 projected operating profit) → safety leadership (today). That’s a coherent IPO narrative for the October 2026 target.
For broader context, see the Claude review, the Claude Code review, and the head-to-head Claude vs ChatGPT comparison.
Sources
Related tool reviews
Questions or corrections? Email Pick Right. Want the full list? See all news.