Anthropic-linked CVEs pile up, attackers mostly shrug
VulnCheck finds only one of 225 Anthropic Glasswing-linked CVEs, Ghost SQL injection CVE-2026-26980, exploited in the wild.
VulnCheck researcher Patrick Garrity tracked 225 CVEs credited to Anthropic or Project Glasswing, whose partners use restricted Claude Mythos Preview for defensive bug hunting. Only CVE-2026-26980, a critical SQL injection in Ghost, is on VulnCheck's known-exploited index. Garrity said these disclosures are not producing different threat outcomes than a typical sample, where roughly 1–2% of flaws are weaponized. Separate studies found ChatGPT-5.5 and Claude Opus 4.8 fully resolved vulnerabilities 26% of the time, and Veracode reported a 56% average security pass rate for AI-generated code.