CVE-2026-26980
CVSS 9.4 CRITICAL: ghost is a Node.js content management system. EPSS 70% (99th percentile).
Vulnerabilities & Exploits
VulnCheck’s tracker for Anthropic’s Claude Mythos Preview and the Glasswing program reached 225 CVEs, but only one has confirmed exploitation in the wild: CVE-2026-26980 in Ghost. Patrick Garrity says that puts the exploit rate at well under 0.5 percent, far below the fear that AI-assisted discovery automatically means more attacks.
The gap is simple: a model can help surface flaws, but turning a disclosure into a working weapon still takes human effort, targeting, and time. In this set, the bottleneck sits between finding the bug and making it useful to threat actors, so discovery volume alone does not predict live abuse.
For security teams, the map is still familiar: more AI-assisted findings can add to patch queues, but the exposure that matters is the small share that attackers actually operationalize. If your workflow assumes every new disclosure will quickly become a campaign, this tracker argues that assumption is too aggressive.
1 source · 2h ago
CVSS 9.4 CRITICAL: ghost is a Node.js content management system. EPSS 70% (99th percentile).
The Register Security
Anthropic-linked CVEs pile up, attackers mostly shrug
Of 225 flaws found by Glasswing and tracked by VulnCheck researcher, just one has confirmed exploitation in the wild
originalPart of the PlainSec briefing for 2026-09-21
Every edition of this story: Anthropic Bug Finds Outpace Real Exploits