CVE Disclosures Hit 3.5x Record After Mythos — IBM Deploys 20,000 Engineers in $5B Open-Source Patch Push
Epoch AI published monthly CVE disclosure data updated through July 2, 2026. The chart shows what happened to high- and critical-severity vulnerability disclosures after Anthropic announced Claude Mythos Preview in April 2026.
June 2026: approximately 1,500 high- or critical-severity CVEs from notable organizations. That is more than 3.5 times the previous monthly record, which predates Mythos’ release.
The Mechanism
In April, Anthropic disclosed that Mythos Preview could autonomously discover and exploit software vulnerabilities. Project Glasswing — the coalition of Microsoft, Google, Apple, AWS, and others using Mythos to harden software — had already been running the model against critical codebases before public access was granted. Glasswing’s cumulative count now exceeds 10,000 high- or critical-severity vulnerabilities found.
OpenAI’s parallel effort, Daybreak, operates the same basic model: use frontier cyber-AI offensively on your own systems before the same capabilities become accessible to adversaries.
The CVE spike is the disclosure lag catching up. Organizations that ran Mythos or were swept by Glasswing partners are now publishing what was found.
IBM Responds at Scale
Dark Reading reported that IBM and Red Hat have committed $5B to Project Lightwell, assigning 20,000 engineers to the new subscription-based patch service. The scope: open-source software supply chain vulnerabilities, the category where AI-assisted discovery is generating the most volume.
The commercial logic is straightforward. When Glasswing finds a critical vulnerability in a library used by thousands of organizations, those organizations need patching resources they often don’t have internally. IBM is selling the remediation capacity.
What the Spike Means
The 3.5x jump is not a step-function increase in the underlying attack surface. The software vulnerabilities existed before Mythos. What changed is the discovery rate.
Two interpretations, both true simultaneously: frontier AI is accelerating defensive security work at a scale previously impossible. The same capability in adversarial hands would produce the same discovery rate without the disclosure.
The CVE spike is a lagging indicator of how much latent vulnerability existed in critical software that no human-speed audit would have reached. The more uncomfortable version: it also measures how fast an adversarial scan could proceed, if it hasn’t already.
Glasswing Momentum
Glasswing launched with Amazon, Apple, Google, Microsoft, and Nvidia as founding partners. The coalition has expanded to 200 total partners across 15 countries, adding power grid and healthcare sectors in its second reported update. Month-one disclosed count was 2,100 vulnerabilities. The cumulative figure at last update was over 10,000.
The rate of disclosure has not plateaued. The June CVE spike, per Epoch’s data, is not an artifact of a one-time reporting rush. It reflects sustained throughput.