Anthropic's AI tool Claude Mythos flagged 23,019 potential vulnerabilities in software systems, raising alarms about the scale of new security risks AI might unleash. However, a deeper look at the data reveals a different story. Out of those thousands, only 126 were officially recognized as Common Vulnerabilities and Exposures (CVEs), and just one has been verified as exploited in real-world attacks.
The research firm VulnCheck examined 1,061 AI-assisted vulnerabilities gathered from projects like Anthropic's Glasswing and the Berkeley Vulnerability Research Initiative. Their findings show only 14 cases, about 1.3%, had confirmed exploitation. This rate aligns closely with exploitation levels for traditional vulnerability discoveries, challenging the fear that AI would drastically escalate active cyber-attacks.
While AI significantly boosts the identification of potential security issues, it hasn't translated into a surge in successful exploits. In the first half of 2026 alone, VulnCheck recorded 495 known exploited vulnerabilities, mostly targeting content management systems and network edge devices. Interestingly, AI software itself is becoming a new focus for attackers, expanding the attack surface as these technologies proliferate.
When Anthropic launched Project Glasswing earlier this year, the pitch highlighted AI's ability to find vulnerabilities faster and in greater numbers than human researchers. The sky-high numbers understandably sparked debates about whether this tech could tip the scales in favor of malicious actors. Yet, the follow-up data on real-world exploitation has been surprisingly restrained, suggesting that while AI accelerates discovery, it doesn't necessarily expedite exploitation at the same pace.
The cybersecurity landscape is watching closely as AI tools evolve, but for now, the dramatic uptick in weaponized software flaws remains more theoretical than actual.
This article is for informational purposes and is not financial advice.


