
Anthropic updated its coordinated vulnerability disclosure dashboard on October 2, 2026. It describes how Claude models help find vulnerabilities in open-source software, and why a model finding a candidate is not the same as a problem being ready for public disclosure. Anthropic says the research uses Claude models, including an early Mythos Preview snapshot, while external security research firms triage, reproduce, and validate findings before human-reviewed disclosure to maintainers and the public.
In the dashboard snapshot, Anthropic reports 6,157 disclosed vulnerabilities across 591 open-source projects. It reports 516 patched findings and 584 CVE or GHSA identifiers. These numbers are Anthropic's account of its program, not an independent audit or a complete census of open-source security. The dashboard also says the disclosed count is only a subset of all candidates found because human triage and maintainer coordination are rate-limiting steps.
The same view lists 29,439 discoveries, 6,123 candidate issues, 5,674 reviewed issues, and a 92.7% true-positive proxy. That percentage is not a general model accuracy claim. It is a program metric under a specified vendor and review process. Readers need to distinguish discoveries, candidates, verified issues, and disclosures instead of treating an intermediate pipeline count as the number of exploitable vulnerabilities.
Anthropic emphasizes responsible disclosure and provenance. Researchers retain discovery records, create hash commitments, and share technical material with maintainers in stages when appropriate, giving projects time to patch and prepare an announcement. The value is not just putting a large vulnerability count on a dashboard; it is placing model-generated signals inside a traceable process with human validation and safeguards against premature release.
The example also shows that the limits of AI-assisted security research are not only about model capability. Models can widen the search, but a useful disclosure still needs environmental reproduction, impact assessment, maintainer communication, patch confirmation, and care not to turn unverified details into an abuse guide. The update does not provide directly actionable exploit instructions; it presents program metrics and process state.
For companies and open-source maintainers, the practical lesson is to make 'AI found a candidate' and 'security can accept this finding' separate stages. A mature workflow needs deduplication, human prioritization, controlled reproduction, patch validation, CVE or GHSA tracking, and a timeline. Sending raw model output straight to the public or to an automated patcher can increase false positives, supply-chain noise, and unnecessary disclosure risk.



