Skip to content
Security & Trust

Anthropic has disclosed 6,157 flaws in open source; 516 are known patched

AI now finds bugs faster than people can check and fix them. The scarce resource is human attention.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Anthropic has disclosed 6,157 flaws in open source; 516 are known patched
In brief
  • Anthropic says it has disclosed 6,157 vulnerabilities across 591 open-source projects, and to its knowledge 516 are patched.
  • Anthropic says human review, not AI discovery, is the rate-limiting step, so its disclosed count is a subset of what its models found.
  • Ask which open-source components you depend on, and how fast your team can absorb fixes once they ship.

The hard part of security used to be finding the flaw. The numbers Anthropic published this month suggest that is changing. The hard part is now deciding which findings are real, and getting someone to fix them.

What Anthropic reports

Anthropic points its Claude AI models at open-source code and asks them to hunt for security holes. One of those models is an early build of Claude Mythos Preview. As of October 2, 2026, the company says it has disclosed 6,157 vulnerabilities across 591 projects. To its knowledge, 516 of those have been patched.

6,157
Vulnerabilities disclosed
Source: Anthropic, Coordinated Vulnerability Disclosure page (snapshot October 2, 2026)
516
Known to be patched
Source: Anthropic, Coordinated Vulnerability Disclosure page (snapshot October 2, 2026)

That is roughly one fix for every twelve disclosures. Anthropic calls patches a lagging indicator, because fixes take a long time to build. A patch also does not mean the fix has been widely installed.

The pipeline, step by step

The process explains the gap. Claude models first produce candidate vulnerabilities. Anthropic then sends them down one of two paths.

On the first path, one of six external security research firms reproduces each issue. The firm decides whether it is a real bug, rates its severity and writes a report for the maintainer. On the second path, Anthropic discloses directly to maintainers without that independent check. This happens, for example, when a maintainer asks for untriaged findings.

From there, maintainers acknowledge the report, build a fix and sometimes publish an advisory. Anthropic's ledger shows 584 public tracking IDs in total. Of these, 219 are CVE records and 365 are GitHub Security Advisories. One finding can carry both. Whether to publish an advisory is the maintainer's call.

584
Identifiers issued
Source: Anthropic, Coordinated Vulnerability Disclosure page (snapshot October 2, 2026)

Attention is the scarce resource

Anthropic is direct about the limit. The slowest link in its chain, it says, is independent human checking of each finding. Its disclosed count is therefore a subset of what its models found. It adds that many confirmed bugs have not been reported to maintainers because of capacity limits.

The lesson here is that cheap discovery moves the queue; it does not remove it. Think of an emergency room that suddenly receives ten times the patients. The scanner is not the problem. The nurses, the doctors and the beds are. In this picture, the nurses are the triage firms, and the doctors are the volunteer maintainers of open-source projects.

That should change how executives read any claim of AI-found vulnerabilities. A large number measures how much work has been created. It does not measure how much risk has been removed.

Read the numbers with care

Anthropic's own caveats matter. Its "true positive" rate counts findings the triage firms confirmed as real. That includes bugs later found to be duplicates, and "won't fix" cases that a maintainer judges outside the project's threat model. Anthropic calls it one proxy for impact, and says patches are the more reliable one.

Severity is also contested. Claude's initial ratings are made before any maintainer input. Maintainers apply project-specific rules, so what one rates critical another may rate low. Anthropic says the external firms' assessments tend to be lower than Claude's.

Anthropic also publishes a ledger of SHA-3-512 hash commitments. Each hash locks in a finding before details are public. Anyone can later check that the revealed details match. Project, identifier and bug class appear only when the disclosure window closes.

What this means for pentesting claims

The lead article for this story comes from Picus, which sells autonomous pentesting and says so. It argues that agentic pentesting proves whether a flaw is exploitable. It also argues that the method has two limits: timing and coverage. It says live exploitation cannot safely touch business-critical production systems or air-gapped zones. Used alone, Picus argues, the method would cover only 20 to 30% of the real exploitable ground in a typical enterprise. That figure is the vendor's own estimate.

Anthropic's data shows a related limit from another side. Finding and confirming a flaw is one task. Getting it fixed is another, and it runs on human time.

Questions for your team

Start with dependencies. Can your team list the open-source components your products and internal systems rely on? A flood of disclosures only helps if you know which ones are yours.

Next, ask about intake. When a fix ships upstream, how long does it take to reach your production systems? Anthropic notes that a released patch does not guarantee wide installation.

Finally, ask your testing vendors what their tools cannot reach. Ask what share of your estate is out of scope and who covers it.

Finding flaws is getting cheaper. Fixing them is still done by people, and that is where the budget question now sits.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Anthropic.

Share this insight