What it is
This profile covers public disclosures that credit Claude or Anthropic Research without pinning the entry to Claude Mythos Preview by name. It includes researcher-in-the-loop and collaborator workflows, not only autonomous model runs.
What is verified
The current ledger records a larger high-confidence set:
- Apache ActiveMQ CVE-2026-34197, where Horizon3.ai’s primary finder write-up names Claude in the discovery workflow and Apache/NVD corroborate the accepted vulnerability, affected versions, fix, and CISA KEV status.
- Mozilla Firefox 148 and 149 CVEs credited to researchers using Claude from Anthropic, with Anthropic tying the Firefox 148 collaboration to Claude Opus 4.6.
- Two FreeBSD April 2026 kernel advisories directly credited to Nicholas Carlini using Claude, Anthropic.
- Calif.io MADBugs NGINX and wolfSSL findings credited to Calif.io in collaboration with Claude and Anthropic Research.
- Later direct-credit clusters across LibreOffice, Cloud Foundry UAA, OpenMeter, OpenSSL, Joomla, TYPO3, Twig, Microsoft Windows, Apple platforms, PostgreSQL, and Libgcrypt.
- A 29-CVE Bouncy Castle campaign plus August releases covering JFrog Artifactory, Caliptra, and Gitea; affected-project records directly name Claude-assisted research.
- Three additional Apple CVEs and four PostgreSQL RCE-class CVEs disclosed in July and August 2026.
- Four accepted Linux fixes whose commit messages explicitly describe Claude review, plus Apple’s CVE-2026-43715 and Microsoft’s CVE-2026-50479.
- Shared credit on Microsoft HTTP.sys CVE-2026-33096 alongside the MDASH campaign record.
What is not counted
Vulnerabilities in Anthropic’s own products, such as Claude Code or MCP-related issues, are not counted here because they are AI-product attack-surface issues, not AI-attributed discoveries in third-party software. Embargoed Project Glasswing claims also stay out until public advisories or CVE records exist.
Sources
- Anthropic: Partnering with Mozilla to improve Firefox’s security
- VulnCheck: Tracking Anthropic and Glasswing CVEs
- Horizon3.ai: CVE-2026-34197 ActiveMQ RCE via Jolokia API
- Calif.io: Claude + Humans vs nginx
- FreeBSD-SA-26:10.tty
- LibreOffice security advisories
- Microsoft Security Update Guide
- Apple security releases
- PostgreSQL security information
- Apple iOS and iPadOS 26.5.2 security content
- Microsoft: CVE-2026-50479
- Bouncy Castle Java CVE index
- JFrog security advisories
- Caliptra security advisories
- PostgreSQL August 2026 security release