Anthropic Merges Its Two Cyber Access Programs Into Three Tiers, but Patching Still Lags Far Behind Discovery
Key takeaways
- Glasswing and the CVP are now one program with Defense, Red Team and Specialized tiers that loosen model refusals step by step.
- Anthropic reports 129,000 verified vulnerabilities found by partners, but its own tracked figures show only 516 patched out of more than 5,600.
- Outside research questions how many of the discovered flaws matter in practice, and a rival model has weakened claims that Mythos is unique.
Anthropic has restructured how security professionals get access to its most capable cyber-oriented AI models. The two programs it launched in April 2026, Project Glasswing and the Cyber Verification Program (CVP), are now a single offering split into three tiers. The company says the goal is to give more security organizations the capabilities they need to protect their systems, while keeping the riskiest uses behind tighter vetting.
How the new tiers work
Until now, Glasswing was aimed at organizations and the CVP at individual security professionals. Glasswing gave partners early access to Mythos, Anthropic's frontier model, so they could look for vulnerabilities in their own software before attackers did. The CVP offered a way for verified practitioners to get fewer blocks on security-related requests.
The merged program ties model permissions to the kind of work being done:
- Defense Access is for security teams at companies, nonprofits, universities and government bodies focused on protecting systems. Safeguards remain fairly strict here. In Anthropic's test, Claude Opus 5.5 refused 46 of 50 attempts at a set of cyber challenges and succeeded four times.
- Red Team Access covers penetration testing and offensive security evaluation. Refusals still apply to anything that could cause physical harm or mass disruption, but the model completed 34 of 50 tasks with these safeguards on.
- Specialized Access is reserved for a small set of verified organizations authorized to test systems whose failure could affect lives or markets, such as flight systems, power grids, telecom networks, interbank transfer infrastructure and government administrative networks. This tier sees the fewest refusals and looks a lot like Glasswing under a new name.
For comparison, Anthropic says users without any CVP access were blocked on every attempt across five runs of 10 CyScenarioBench challenges. The message is that the gate matters: ordinary users get almost nothing, while vetted users get progressively more.
Big discovery numbers, small patch numbers
Anthropic says Glasswing partners found at least 129,000 verified software vulnerabilities between April and July 2026, and that its own open source scanning turned up another 5,500 between April and October. More than 33,000 of the partner findings were rated critical or high severity, though Anthropic admits that figure comes from survey data covering only some partners. It suggests the real number could be at least five times higher.
The remediation numbers are far less impressive. Of 5,674 confirmed true positives in the company's own figures, 3,014 are high severity and 1,522 are critical. Only 516 have been patched. That gap points to a bottleneck that has little to do with finding bugs. Maintainers, particularly of open source projects, are often volunteers who must triage reports, write and test fixes, and ship updates without breaking downstream users. A flood of machine-generated findings can add to that load rather than relieve it.
It also raises an awkward question for the industry. If AI models are as capable at security work as their makers claim, generating and validating fixes should be a natural next step. So far the evidence suggests discovery is scaling faster than repair.
Questions about impact and uniqueness
Not everyone is convinced the findings translate into real-world risk. VulnCheck researcher Patrick Garrity tracked 225 Anthropic-linked vulnerabilities and found that fewer than 0.5 percent were being exploited in the wild. That does not mean the bugs are harmless, since many vulnerabilities are never exploited, but it does complicate the story that raw counts equal safety gains.
The competitive picture is shifting too. Only a week before this announcement, Anthropic warned about Z.ai's GLM-5.3 and its advanced cybersecurity abilities. That warning, whatever its intent, implies that strong vulnerability-hunting capability is no longer confined to one lab's model. Tiered access can restrict what Anthropic's own systems will do, but it cannot control open-weight models whose guardrails have been stripped out.
That is the central tension in the program. Gating access is a reasonable way to push powerful tools toward defenders first, yet its value depends on defenders actually fixing what they find, and on attackers lacking equivalent tools elsewhere. Neither condition is clearly met today. The reorganization simplifies the offer, but the harder work now sits with patching pipelines rather than with the models.