The number of high‑ and critical‑severity Common Vulnerabilities and Exposures (CVEs) reported by 21 notable organizations rose to approximately 1,500 in June 2026, exceeding th...
The number of high‑ and critical‑severity Common Vulnerabilities and Exposures (CVEs) reported by 21 notable organizations rose to approximately 1,500 in June 2026, exceeding the prior monthly record by more than 3.5 times, according to a dataset released July 2, 2026.
The increase follows Anthropic’s April 2026 announcement that its Claude Mythos Preview model could autonomously identify software vulnerabilities, and that its Project Glasswing initiative, which includes Microsoft, Google, Apple, and Amazon Web Services, had been using the model to locate and remediate bugs before the model’s public release. Project Glasswing reported finding more than 10,000 high‑ or critical‑severity vulnerabilities since the program began, many of which have not yet been individually disclosed. OpenAI also launched its Daybreak product to harden software using similar AI capabilities.
The spike in disclosed CVEs was recorded after the Claude Mythos Preview announcement, with the monthly total surpassing the previous record set before the announcement. The data, compiled from monthly disclosures by the participating organizations, shows a sharp upward trend beginning in June.
The broader effect of AI‑driven vulnerability discovery on software security remains uncertain, and further monitoring will be needed to assess whether the elevated CVE count reflects a lasting change in the threat landscape.
- Publisher
- Hacker News
- Reliability
- high
- Published
- 7/4/2026, 10:00:21 AM
- Retrieved
- 7/4/2026, 10:00:21 AM
- Relevance
- 80%
- Confidence
- 85%

