Only one of 225 Anthropic and Glasswing CVEs exploited in the wild
VulnCheck researcher Patrick Garrity tracked 225 vulnerabilities credited to Anthropic and Project Glasswing and found confirmed exploitation of just one — a critical SQL injection in Ghost (CVE-2026-26980). Fewer than 0.5 percent of these CVEs are being attacked in the wild.
- Only one of 225 Anthropic and Glasswing CVEs is exploited in the wild
- The sole confirmed case is a SQL injection in Ghost (CVE-2026-26980)
- Historically just 1–2 percent of vulnerabilities get weaponized
- AI models fully fix a vulnerability only 26 percent of the time
Read next
Security