Anthropic Opens More Claude Capabilities to Vetted Defenders as Glasswing Flaws Reach Active Attacks

Anthropic expands Claude access for vetted defenders as Glasswing claims are reported with limited verification and reported sample exploitation.

Anthropic Opens More Claude Capabilities to Vetted Defenders as Glasswing Flaws Reach Active Attacks
AI

Illustrative image generated with AI

Anthropic is expanding its Cyber Verification Program (CVP), offering approved cybersecurity teams access to selected Claude models with fewer safeguards and blocking classifiers. The program covers defensive research, authorized penetration testing and, for a smaller group, safety-system testing.

The announcement accompanies Anthropic’s claim that Project Glasswing identified at least 129,000 verified software vulnerabilities between April and July 2026. The company separately reported another 5,500 verified vulnerabilities found through open-source scanning between April and October 2026.

Those are company figures and have not been independently confirmed in the available material. A narrower analysis attributed to VulnCheck researcher Patrick Garrity examined 300 vulnerabilities credited to Anthropic or Project Glasswing and reported that two—CVE-2026-26980 and CVE-2026-61500—had been exploited in the wild.

The report covering Anthropic’s announcement dates it only as “Tuesday,” without a calendar date. The individual discovery, disclosure and exploitation dates of the vulnerabilities are also not provided.

Three access tiers divide defensive, red-team and safety work

The expanded CVP has three levels, each tied to a defined category of authorized cybersecurity activity.

Defense Access is intended for incident response, malware reverse engineering, and vulnerability analysis and validation.

Red Team Access includes the defensive use cases while adding authorized penetration testing and red-team operations.

Specialized Access has the fewest safeguards. Anthropic says it is restricted to a limited number of verified organizations authorized to test safety systems.

Each tier provides access to Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, as well as future models. Access remains subject to verification and tier-specific controls; the program is not a general removal of Claude’s cybersecurity restrictions.

Anthropic describes the models’ cyber capabilities as dual-use. Its stated objective is to make those capabilities available to more defenders so they can secure systems, while recognizing that similar technology could be misused by malicious actors.

A 50-task evaluation measured how often safeguards intervened

According to a CyScenarioBench evaluation, safeguards blocked 46 of 50 tasks when Claude Opus 5.5 operated under Defense Access.

Under Red Team Access, no tasks were blocked and the model completed 34 of 50. The reported completion rate matched the result obtained with no safeguards applied. Without CVP access, all 50 tasks were blocked on the first prompt.

The available source does not establish who conducted the benchmark. Anthropic cited the results as evidence supporting wider access for verified defenders, but the material does not independently reproduce the evaluation or establish how the models would perform against different tools, targets or operational conditions.

The figures also measure more than one outcome. A task that was not blocked was not necessarily completed: Red Team Access allowed all 50 tasks to proceed, but Claude Opus 5.5 reportedly completed 34.

Glasswing’s headline totals and VulnCheck’s sample measure different things

Anthropic says Project Glasswing found at least 129,000 verified vulnerabilities between April and July 2026. It separately attributes 5,500 additional verified findings to open-source scanning conducted between April and October 2026.

Because the figures describe different activities and reporting periods, they should not automatically be merged into one total. The periods are not dates for the discovery, disclosure or exploitation of any individual flaw.

Anthropic also says more than 33,000 verified vulnerabilities have been rated critical or high severity. That figure is based on survey responses from only a subset of Glasswing partners. The company estimates that the actual impact could be at least five times greater, but neither the count nor the projection is independently confirmed by the supplied evidence.

Garrity’s VulnCheck analysis, described only as published “late last month,” covered a smaller set of 300 vulnerabilities attributed to Anthropic or Project Glasswing. It reportedly classified 39 as critical, 141 as high, 81 as medium and 18 as low.

Those severity categories add up to 279, leaving 21 of the 300 records unaccounted for in the reported breakdown. The source does not explain their status.

VulnCheck reported in-the-wild exploitation for two of the 300 vulnerabilities, or 0.67% of that sample. The percentage does not describe all vulnerabilities included in Anthropic’s broader Glasswing claims. Verification of a vulnerability also does not, by itself, show that attackers can exploit it under real deployment conditions.

Ghost installations from 3.24.0 through 6.19.0 require an update

One of the two reportedly exploited vulnerabilities, CVE-2026-26980, affects the Ghost Node.js content management system.

NVD identifies Ghost versions 3.24.0 through 6.19.0 as vulnerable. An unauthenticated remote attacker can use the flaw to perform arbitrary reads from the application’s database. The vulnerability has a CVSS v3 score of 9.4 and is classified as CWE-89.

Its vector is:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

The news report describes CVE-2026-26980 as SQL injection. The supplied NVD entry states the resulting capability—unauthenticated arbitrary database reads—and assigns the CWE-89 classification.

Ghost fixed the issue in version 6.19.1. Operators running versions from 3.24.0 through 6.19.0 should upgrade to 6.19.1 and review whether the vulnerable service was reachable from untrusted networks.

The cited reporting says the vulnerability has been exploited in the wild. However, the available material does not provide associated indicators of compromise, victim details or threat-actor attribution. That limitation applies only to the records reviewed here and does not establish whether such information has been published elsewhere.

Rejetto HFS can expose its cookie-signing key

The other reportedly exploited flaw, CVE-2026-61500, affects Rejetto HFS versions 3.0.0 through 3.2.0.

HFS derives the key used to sign session cookies from the non-cryptographic Math.random() generator. During login, the server also discloses outputs from that generator to unauthenticated clients.

A remote attacker can collect a small number of login responses and reconstruct the generator’s state. This process can recover the signing key, enabling the attacker to create a valid administrator session cookie.

A forged administrative session can lead to full administrative access and remote code execution through the server_code configuration feature. The vulnerability carries a CVSS v3 score of 9.8, is classified as CWE-338 and has this vector:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

The supplied NVD description does not name a fixed version or mitigation. That does not prove remediation is unavailable; it means the cited record does not establish one. Operators using Rejetto HFS 3.0.0 through 3.2.0 should identify exposed instances and consult current vendor guidance before deciding on corrective action.

The supplied records include neither CISA Known Exploited Vulnerabilities status nor a CISA remediation deadline for either CVE. No conclusion about KEV inclusion can be drawn from that omission.

AI-assisted findings still require validation and secure remediation

The Glasswing figures concern vulnerability discovery, while the VulnCheck sample addresses reported exploitation. These are related but distinct measurements: a large number of findings does not establish an equally large number of practical attack paths.

AI-generated code and fixes can also introduce security defects. Veracode reports that approximately 44% of AI code-generation tasks in its tests introduced a risky vulnerability. It calculated an average security pass rate of 56%, compared with 55% in its first report, while reporting growth in the volume of AI-generated code entering development pipelines.

Those are Veracode’s results. The supplied material does not include the underlying methodology or enough scope information to generalize the figures across models, languages and development environments.

For security teams, the immediate priorities are narrower: update Ghost to 6.19.1 where CVE-2026-26980 applies, inventory affected Rejetto HFS deployments, and follow current remediation guidance for CVE-2026-61500. AI can accelerate discovery, but severity, reproducibility, exposure and evidence of exploitation still determine operational risk.

Security dossiers

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →