Anthropic’s models have outrun the people who patch what the models find.

Its disclosure dashboard lists 29,439 findings discovered between November 1, 2025, and October 2, 2026. As of October 2, the company disclosed 6,157 findings across 591 open-source projects. The 6,157 findings were reported to their maintainers, while 516 were patched upstream, to Anthropic's knowledge. However, that “does not guarantee that those patches have been widely installed," the company said.

The Anthropic Cyber Mission the company announced Oct. 8 shifts more of the validating to providers and maintainers.

Outside firms reviewed 6,123 findings and confirmed that 5,674 were valid. Of the 6,157 reported, 1,333 came through that triage. The other 4,824 went “direct to maintainers,” which the dashboard says “may contain false positives.”

Track one is the Critical Infrastructure Defense Program. It sends frontier Claude models, on-site engineers, and Anthropic's threat research to 11 partners: Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation, which Anthropic calls “a small cohort of providers.”

Anthropic says its June program for state, local, tribal, and territorial governments reached “more than half of all US states,” and “security teams of any size” can apply to its expanded Cyber Verification Program.

Anthropic’s Cyber Mission starts with 6,157 findings reported to maintainers and 516 patched

Infographic summarizing Anthropic's vulnerability disclosure pipeline from November 2025 to October 2, 2026. Out of 29,439 findings discovered by Claude models, 6,123 were reviewed by six security firms, 5,674 were confirmed valid (a 92.7% true-positive rate), 6,157 were reported to maintainers, 5,103 were acknowledged, and 516 were patched upstream. Key side stats highlight 11 founding partners in the Critical Infrastructure Defense Program, 7+ states with water utilities reporting PLC attacks, and an undisclosed funding/compute model.

Track two, OSS Scanner, gives enrolled projects free periodic scans with a reproducer, an explanation, and a candidate patch when one exists. “The reports are model-generated and sent without human review,” the announcement says.

Terms unpublished, and fixes that run months or decades in rare cases

Anthropic didn’t specify whether partners will receive free model access or who will cover the computing costs, Axios reported. In Glasswing, Anthropic often saw months pass between a vulnerability being found and being fixed, the company says, and an OT fix “may have to wait” until it is safe to apply to running machinery, where “in some rare cases, this might take decades.”

“Critical infrastructure is hard to defend in many ways that AI cannot fix, but we believe that frontier models can help find and repair weaknesses before those weaknesses are used to cut off power or make water unsafe,” the announcement states.

The infrastructure track reaches operators through their providers

On July 30, the FBI and EPA warned that water and wastewater utilities in at least seven states had reported attacks on internet-facing Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 controllers since July 27, with “loss of pressure and flooding” among the effects. Their first recommendation was “removing PLCs from direct internet exposure via secure gateway and firewalls.” Rockwell Automation is a founding partner of the new program, and the FBI notes other controller brands warrant the same considerations.

Anthropic’s Cyber Mission starts with 6,157 findings reported to maintainers and 516 patched

Flowchart titled "Who gets Anthropic's frontier models, and through whom" detailing access paths for Anthropic's Cyber Mission as of October 8, 2026. Anthropic models and engineers route through three tracks: the Critical Infrastructure Defense Program (via 11 founding providers like Accenture and Rockwell Automation to OT operators), the opt-in free OSS Scanner (sending scans and patches to open-source maintainers across 591 projects), and the expanded Cyber Verification Program (direct to operators and security teams). A sidebar notes key remediation stats, including 516 of 6,157 reports patched upstream and PLC attack impacts across 7 states.

Tom Dobbins of the WaterISAC told CyberScoop that “OT systems that are exposed to the internet are a major challenge, and many of these systems that are older generation need to be not accessible to the internet.”

Cynthia Kaiser, formerly of the FBI and now at Halcyon, told Nextgov in May that “it’s not just about getting access,” and that the question is “where do they start?”

Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, told VentureBeat in an exclusive interview in April, months before CrowdStrike joined the Critical Infrastructure Defense Program as a founding partner, that “the problem is patching.” At ten times today's findings, he said, “they’re going to be completely underwater.”

Anthropic’s Cyber Mission starts with 6,157 findings reported to maintainers and 516 patched

Bar chart titled "Findings grew 3.9x since May and patches 5.3x," comparing Anthropic CVD dashboard snapshots between May 22 and October 2, 2026. Findings reported to maintainers increased from 1,596 to 6,157 (a 3.9x increase), while findings patched upstream grew from 97 to 516 (a 5.3x increase). Patched findings as a share of reported findings rose from 6.1% to 8.4%, across projects growing from 281 to 591.

85 of 97 early scanner findings cleared the disclosure bar

Outside penetration testers checked 97 critical and high findings in 48 projects. Of those, 85 met the disclosure bar, 11 were real but duplicated known issues, and one was a false positive. Anthropic expects a true-positive rate above 90%. Some maintainers have said that “severity ratings can be inflated or the scanner misunderstood the project’s threat model.”

Todd Ouska of wolfSSL said that, “of the 74 reports we received, all but two were valid, and five became CVEs.” Maintainers enroll by pull request, and Anthropic says it will keep manual, human-reviewed disclosure for projects that need it.

A $100 million bill would authorize operators' frontier-model access

Rep. Josh Gottheimer’s AI Cyber Defense Act would authorize $100 million for a CISA pilot from 2027 to 2031, giving critical infrastructure operators free frontier-model access, if appropriators fund it. Meyers made the same point in April: Many “think tokens are free, but they’re not free.” Gottheimer said that “many of our local communities just don’t have the resources they need to pay for AI tokens to do the patching they need,” CyberScoop reported.

Five checks for security leaders

  1. Check provider access. Ask your OT provider whether it is one of the 11 founding partners and what your organization actually receives. Anthropic hasn't published who pays for model access or computing costs.

  2. Remove PLC internet exposure. Work with your OT team to take any PLC off direct internet exposure, as the FBI and EPA recommend. That exposure is a risk today, whatever happens with fix timing. Anthropic says it "often saw months pass" between finding and fix during Glasswing.

  3. Track open-source dependencies. Check the OSS Scanner repository for projects you depend on, then watch their advisories and upstream releases. The reports go to maintainers, not to you.

  4. Verify fixes are installed. Track separately when a patch is released and when it's installed on your systems. Where patching has to wait for a safe maintenance window, track the stopgap protections you rely on in the meantime. Anthropic's dashboard warns that upstream patches may not be widely installed.

  5. Apply for model access directly. If your team does defensive work, apply to the Cyber Verification Program yourself. Your OT provider’s seat in the program is the provider’s, and it does not pass model access through to you. Anthropic says security teams of any size can apply, and it verifies applicants before granting access.