On July 28, 2026, Anthropic received official approval from CVE.org and MITRE to act as a CVE Numbering Authority, making it the 282nd such entity in the US. This means Anthropic can now assign CVE identifiers for flaws found in the software and open-source projects they develop or distribute. This shift signals a deeper integration of AI into cybersecurity by turning AI companies from mere targets into active discoverers of long-standing vulnerabilities.

The impact is massive. Anthropic's Project Glasswing, powered by their Claude AI models, revealed more than 23,000 vulnerabilities in the first half of 2026. This surge contributes to a projected total of over 60,000 vulnerabilities reported this year, almost ten times the count from a decade ago. Meanwhile, traditional systems like the National Vulnerability Database are overwhelmed, facing a 263% increase in CVE submissions from 2020 to 2025 and struggling to keep pace with the flood of discoveries.

The widening gap between discovery and remedy

Despite the flood of reported vulnerabilities, actual remediation remains slow. From those 23,000 findings by Project Glasswing, only 126 became official CVEs. Across nearly 300 open-source projects, just under 1,600 vulnerabilities got disclosed by May, with a mere 6% seeing confirmed upstream patches. Experts warn this backlog of unpatched, known flaws could pose serious risks.

Anthropic’s designation as a CNA is an attempt to formalize and manage this new scale of vulnerability detection. The findings include deep-rooted issues, such as remote code execution bugs in FreeBSD’s NFS dating back 17 years and a 27-year-old crash flaw in OpenBSD. AI is exposing problems that persisted despite millions of existing tests and years of oversight.

According to officials, Anthropic’s new role reflects the 'industrialization' of vulnerability detection through AI, a shift transforming the cybersecurity landscape and forcing a rethink of traditional disclosure and mitigation methods.

This material is informational and does not constitute financial advice.