Anthropic's Claude Mythos Preview finds over 10,000 critical vulnerabilities faster than teams can patch them
THE DECODER · May 23, 2026
AI Summary
•Anthropic's Claude Mythos Preview AI model, working with about 50 partners, has found more than 10,000 high- or critical-severity vulnerabilities in system-critical software. Partners including Cloudflare (2,000 bugs), Mozilla (271 vulnerabilities in Firefox 150), Palo Alto Networks, Microsoft, and Oracle report bug-discovery rates jumping more than tenfold in some cases.
•In parallel scanning of over 1,000 open-source projects, the model found 6,202 estimated high- or critical-severity vulnerabilities. Independent review of 1,752 high- or critical-severity findings showed 90.6 percent were true positives and 62.4 percent were confirmed as genuinely high or critical. Based on those rates, Anthropic estimates Mythos Preview uncovered close to 3,900 confirmed high- or critical-severity vulnerabilities in open-source code.
•The model now spots security flaws faster than teams can verify, disclose, and patch them, creating a transition period where vulnerabilities are found rapidly but fixed slowly. Of 23,019 total vulnerabilities found in open-source projects, only 97 have been patched so far, while 530 confirmed high- or critical-severity bugs remain waiting to be disclosed to maintainers.