
Despite the high capability of AI models like Claude Mythos Preview from Anthropic to find vulnerabilities, the level of their exploitation by malicious actors remains low. According to Patrick Garrity, a security researcher at VulnCheck, less than 0.5% of vulnerabilities related to Anthropic or Project Glasswing are subject to exploitation in real-world conditions. Garrity began tracking vulnerabilities related to Project Glasswing after the company's announcement in April 2026 about providing access to its model product only to vetted partners for work in defensive security. Analyzing CVE data, he noted that there are currently 225 registered vulnerabilities, of which only one, a critical SQL injection in Ghost (CVE-2026-26980), has been exploited in practice.
Garrity emphasized: "There is a big difference between finding vulnerabilities and whether they are actually useful and will be used by malicious actors." He added that the data shows that Anthropic's discoveries have a rather limited impact. Although modern AI models do find more vulnerabilities, they also do not always effectively fix them. For example, according to an analysis by the research group 1Password, AI-generated patches resolved the issue only 26% of the time, while in 54% of cases they either did not eliminate the vulnerability or introduced a new one.
"The bar for detecting vulnerabilities is significantly lower with AI, but the real gap lies in coordination, triage, remediation, and deployment of patches, which still requires significant human effort,"– noted Garrity. These findings cast doubt on the notion that all discovered vulnerabilities will be immediately used in malicious attacks.





