Summary
Anthropic’s coordinated vulnerability disclosure dashboard is a new public source for Project Glasswing findings. The May 22 snapshot says Anthropic had disclosed 1,596 vulnerabilities across 281 open-source projects, with 97 patched and 88 assigned a CVE or GitHub Security Advisory.
Bugflation does not count those headline numbers as individual findings. This entry indexes the subset that is publicly revealed, fixed, vendor-confirmed, and backed by CVE or GHSA identifiers in Anthropic’s ledger.
The revealed fixed cluster now includes 27 entries across NGINX, wolfSSL, Mastodon, FreeRDP, MinIO, Nomad, jq, libyang, MapServer, Gitoxide, Temporal, junrar, Ghost, Craft CMS, and ImageMagick. Nineteen of those rows have CVE IDs, with 18 unique CVEs because the two NGINX rows share CVE-2026-27654:
- CVE-2026-27654 in NGINX.
- CVE-2026-5446, CVE-2026-5447, CVE-2026-5448, CVE-2026-5466, CVE-2026-5477, CVE-2026-5479, CVE-2026-5500, CVE-2026-5501, and CVE-2026-5503 in wolfSSL.
- CVE-2026-46349 and CVE-2026-46348 in Mastodon.
- CVE-2026-44420 and CVE-2026-45700 in FreeRDP.
- CVE-2026-7474 in Nomad.
- CVE-2026-32316 in jq.
- CVE-2026-33721 in MapServer.
- CVE-2026-5199 in Temporal.
The GHSA-only side of the cluster includes Craft CMS, one additional FreeRDP row, Gitoxide, ImageMagick, junrar, libyang, MinIO, and Ghost.
Some NGINX and wolfSSL CVEs in this CVD ledger also carry public Calif.io, Claude, and Anthropic Research credit lines. Bugflation keeps that broader Claude-assisted MADBugs entry separate; this page is scoped to the Anthropic CVD ledger’s direct Claude Mythos Preview attribution and fixed-row status.
Attribution
This is a direct-attribution entry. The per-finding Anthropic pages state that the vulnerabilities were discovered by Claude Mythos Preview. The ledger marks the entries as passed triage, vendor-confirmed, disclosed, patched, and fixed.
The dashboard also exposes a machine-readable ledger, which makes the count auditable without relying on screenshots or secondary reporting. The CVE and GHSA records provide the public vulnerability layer; Anthropic supplies the AI attribution and disclosure-status layer.
Why it matters
This is the first public Project Glasswing source that moves beyond isolated examples and exposes an auditable CVD pipeline. The important signal is not the raw number of undisclosed candidates. It is the much narrower, verifiable path from Mythos-generated report to human triage, maintainer confirmation, fix, and public advisory.
The cluster also shows the practical shape of bugflation: the bottleneck is not just model discovery. It is independent triage, vendor coordination, advisory assignment, patch validation, and public disclosure.
References
- Anthropic: Coordinated vulnerability disclosure dashboard
- Anthropic CVD ledger JSON
- Anthropic: ANT-2026-CN7KX43N nomad
- Anthropic: ANT-2026-DJBBBBPE temporalio/temporal
- Anthropic: ANT-2026-H97FY6C8 FreeRDP
- Anthropic: ANT-2026-H5T8XKWR Ghost
- NVD: CVE-2026-7474
- NVD: CVE-2026-5199
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.