Vulnerabilities · 1h ago

Anthropic Bug Finds Outpace Real Exploits

VulnCheck’s tracker for Anthropic’s Claude Mythos Preview and the Glasswing program reached 225 CVEs, but only one has confirmed exploitation in the wild: CVE-2026-26980 in Ghost. Patrick Garrity says that puts the exploit rate at well under 0.5 percent, far below the fear that AI-assisted discovery automatically means more attacks.

The gap is simple: a model can help surface flaws, but turning a disclosure into a working weapon still takes human effort, targeting, and time. In this set, the bottleneck sits between finding the bug and making it useful to threat actors, so discovery volume alone does not predict live abuse.

For security teams, the map is still familiar: more AI-assisted findings can add to patch queues, but the exposure that matters is the small share that attackers actually operationalize. If your workflow assumes every new disclosure will quickly become a campaign, this tracker argues that assumption is too aggressive.

CVE-2026-26980

NVD KEV

CVSS 9.4 CRITICAL: ghost is a Node.js content management system. EPSS 70% (99th percentile).

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-09-21

Editions

Related stories