Project Glasswing: Claude Mythos Discovers 10,000+ Critical Vulnerabilities in Open Source Software
Anthropic's Project Glasswing has delivered its first major results, and the numbers are staggering. Since launching in late April 2026, the initiative has used the restricted Claude Mythos Preview model alongside approximately 50 partner organizations to scan over 1,000 widely-used open-source projects. The result: more than 10,000 high- or critical-severity vulnerabilities identified, with 1,094 confirmed so far. Only 97 have been patched. Among the most significant discoveries is CVE-2026-5194, a critical flaw in the wolfSSL cryptography library that underpins secure communications in countless embedded systems and IoT devices. Additional findings include vulnerabilities in OpenBSD's SACK implementation and FreeBSD tracked as CVE-2026-4747. Anthropic has published a public vulnerability dashboard showing all severities discovered. The initiative marks a paradigm shift in AI-assisted security research — Mythos can identify vulnerability patterns at a scale and speed impossible for human auditors. The bottleneck is no longer finding bugs but fixing them, as open-source maintainers struggle to keep pace with the influx of reports. For organizations relying on open-source infrastructure, Project Glasswing underscores the need for proactive vulnerability management and automated patching pipelines.
Project Glasswing proves AI can find vulnerabilities at a scale humans simply cannot match. The real crisis is the remediation gap — 10,000 bugs found, 97 fixed. This will force a reckoning in how the industry funds and staffs open-source security maintenance.
What is Project Glasswing?
Project Glasswing is Anthropic's cybersecurity initiative that uses the restricted Claude Mythos Preview model to systematically scan critical open-source software for vulnerabilities. It partners with approximately 50 organizations and publishes findings on a public dashboard.