Claude Mythos Preview Is Finding Critical Bugs Faster Than Anyone Can Fix Them

Anthropic has revealed that its Claude Mythos Preview critical vulnerabilities count has crossed 10,000 in just one month, and the pace of discovery is already outrunning the industry’s ability to respond. The findings come from Project Glasswing, a collaborative effort involving around 50 partners running and building software that sits at the core of the internet and critical infrastructure.
Each partner has flagged hundreds of high or critical severity flaws. Several report their bug discovery rate jumped more than tenfold after working with the model. Cloudflare flagged 2,000 bugs, 400 of which were high or critical severity, with a false positive rate that beat human testers. Mozilla found and fixed 271 vulnerabilities in Firefox 150 more than ten times what Claude Opus 4.6 caught in the previous version. Palo Alto Networks shipped five times as many patches as usual in its latest release, while Microsoft warned that patch volumes will “continue trending larger for some time.”
Beyond partner work, Anthropic scanned more than 1,000 open-source projects and the model returned an estimated 6,202 high or critical severity findings, with over 23,000 total across all severity levels. Of the 1,752 high and critical findings reviewed so far, 90.6 percent were confirmed as true positives. Based on those triage rates, Anthropic estimates close to 3,900 confirmed high or critical vulnerabilities are sitting in open-source code. Only 97 have been patched so far.
The bottleneck is real. Some open-source maintainers have asked Anthropic to slow down disclosures because they simply need more time to build patches. On average, fixing a critical bug takes two weeks. Meanwhile, 827 confirmed vulnerabilities are still waiting to be disclosed. Maintainers are also dealing with a flood of low-quality, AI-generated bug reports that makes sorting through legitimate findings even harder.
The UK’s AI Security Institute confirmed that the latest Mythos Preview checkpoint is the first AI model to fully solve both of its in-house cyber ranges, which simulate multi-stage cyberattacks. Independent security platform XBOW called it a major step beyond all prior models, citing “unprecedented precision.”
Anthropic is not treating this as a win without serious caveats. The company warns that Claude Mythos Preview critical vulnerabilities being discovered this quickly creates a dangerous transition window where bugs are found far faster than they can be fixed. Models with similar capabilities will soon be widely available, some may already be. Anthropic says no company, itself included, has built safeguards strong enough to prevent misuse of these models.
For now, Anthropic is urging software teams to shorten their patch cycles, make updates easier for users to apply, and lean on security fundamentals like multi-factor authentication, hardened configurations, and thorough logging. The expectation is that over time, AI will help developers catch flaws before code ships. But that future has not arrived yet, and the gap between discovery and remediation is widening.





