On July 28, 2026, CVE.org and MITRE designated Anthropic as a CVE Numbering Authority (CNA). This is the 282nd such designation from the United States. The scope is specific: Anthropic is now authorized to assign CVE IDs for vulnerabilities in software, services, and open-source projects they develop, maintain, or distribute. This administrative change marks a structural shift in the cybersecurity ecosystem. AI companies are no longer just potential targets; they have become the primary engine for vulnerability discovery, effectively automating the identification of flaws that have persisted for decades.
The scale of this discovery mechanism is documented in the VulnCheck H1 2026 report. Through Project Glasswing, powered by the Claude proprietary models, Anthropic identified over 23,000 vulnerabilities in the first half of the year. To put this in perspective, the National Vulnerability Database (NVD) has faced a 263% increase in CVE submissions between 2020 and 2025. Projections for 2026 suggest a total exceeding 60,000 vulnerabilities—a nearly tenfold increase from a decade ago. The NVD is under structural strain, and the velocity of discovery is now outpacing the capacity of the traditional disclosure and remediation pipeline.
The data reveals a significant bottleneck. Of the 23,000+ findings generated by Project Glasswing, only 126 resulted in published CVEs. As of May 22, 1,596 vulnerabilities had been disclosed across 281 open-source projects, yet only 97 were confirmed as patched upstream. This represents a remediation rate of approximately 6%. The gap between discovery and remediation is widening, creating a backlog of known but unaddressed security flaws. Anthropic’s role as a CNA is intended to formalize this process, but the sheer volume of findings suggests that the current disclosure infrastructure is ill-equipped for the era of AI-enabled discovery.
The efficiency of these models is evident in the nature of the findings. Before Anthropic’s CNA designation, CVEs were typically assigned by the affected vendors, such as Mozilla, FreeBSD, or OpenSSL. Project Glasswing has surfaced vulnerabilities that survived for years, including a 17-year-old remote code execution flaw in FreeBSD NFS, a 27-year-old crash in OpenBSD, and a 16-year-old flaw in FFmpeg that persisted despite 5 million automated test runs. These are not minor bugs; they are systemic weaknesses in foundational software. Yet, despite the high volume of discovery, only one finding—CVE-2026-26980—has been confirmed as exploited in the wild.
The timing of this designation coincides with the CVE Virtual Event, “CVE in an Era of AI-Enabled Vulnerability Discovery,” held today. The event highlights the tension between the speed of discovery and the speed of defense. The window for exploitation has compressed drastically. In 2018, the median time from disclosure to weaponized exploit was 771 days. Today, that window is measured in single-digit hours, with 28.3% of CVEs exploited within 24 hours of disclosure. The automation of discovery has effectively turned the vulnerability lifecycle into a race against automated exploitation.
Anthropic’s approach to this power is cautious, at least in public. The proprietary models responsible for these findings have not been released publicly, with the company citing insufficient safeguards against misuse. This dual-use dilemma is central to the current AI security landscape. The same models capable of identifying 10,000+ high- or critical-severity vulnerabilities in systemically important software in a single month are also capable of identifying the exploit paths for those same vulnerabilities.
The expansion of the CNA program, which added approximately 150 organizations in 15+ countries in late May, reflects a broader attempt to decentralize vulnerability management. However, the core issue remains: discovery velocity is now automated, while remediation remains manual and slow. As AI companies assume the role of both the source of new attack surfaces—through their own complex software and service stacks—and the primary mechanism for discovering vulnerabilities in the global software supply chain, the traditional CVE model faces a stress test. The current 6% remediation rate is a lagging indicator of a system struggling to process the output of its own automation.
