At a glance
- What changed
- Anthropic’s dashboard says Claude Mythos Preview has generated thousands of vulnerability findings, with 1,596 issues disclosed across 281 open-source projects as of May 22, 2026.
- Why it matters
- Security-focused agent use is moving from demos to operational workflows. Public reporting on what was found, what was disclosed, and what got patched helps teams judge whether these systems are reliable enough for real security programs.
- Who is affected
- security teams, open-source maintainers, developers
- What to do next
- Watch how many disclosed issues get patched over time, whether severity filtering changes the headline numbers, and how maintainers respond to AI-generated reports versus tradit…
What changed
Anthropic published a public dashboard for its coordinated vulnerability disclosure work, saying that since February 2026 it has used Claude Mythos Preview to surface vulnerability candidates and has disclosed 1,596 findings across 281 open-source projects as of May 22, 2026.
Why it matters
Security-focused agent use is moving from demos to operational workflows. Public reporting on what was found, what was disclosed, and what got patched helps teams judge whether these systems are reliable enough for real security programs.
In plain English
Anthropic is publicly tracking how many security bugs its Claude Mythos model found and how many of those bugs have been disclosed and fixed.
What this means for you
Who is affected: security teams, open-source maintainers, developers
Next move: Watch how many disclosed issues get patched over time, whether severity filtering changes the headline numbers, and how maintainers respond to AI-generated reports versus tradit…
- The dashboard reports counts for findings discovered, triaged, reviewed, and disclosed, plus a breakdown by vulnerability class.
- Anthropic says it uses external security firms and internal triage before reporting issues to maintainers.
- It also lists a “disclosure ledger” meant to prove findings existed during the disclosure window without revealing details early.
What remains uncertain
Watch how many disclosed issues get patched over time, whether severity filtering changes the headline numbers, and how maintainers respond to AI-generated reports versus traditional human reports.