P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

One in 225 Anthropic-credited CVEs is confirmed exploited, and that number proves less than it seems

A public tracker of CVEs credited to Anthropic lists 225 entries and one exploited bug, a Ghost CMS SQL injection. We rechecked all 225 against CISA KEV, EPSS and CISA's SSVC data: the rate is indistinguishable from the normal base rate, and the sample is small and young.

By Parminder Kumar Sharma · · 13 min read

Editorial illustration for the briefing: One in 225 Anthropic-credited CVEs is confirmed exploited, and that number proves less than it seems

One in 225, and what that number cannot carry

On 21 September 2026 the public tracker of vulnerabilities credited to Anthropic listed 225 CVE entries. We checked every one of them against the CISA Known Exploited Vulnerabilities catalogue (version 2026.09.21, 1,717 entries). None is in it. VulnCheck's own KEV list, which the tracker uses, flags exactly one: the Ghost CMS SQL injection CVE-2026-26980, added on 21 May. One in 225 is 0.44 per cent, which is the figure behind The Register's headline that attackers "mostly shrug".

Here is what that number does not establish. With only 225 items and one event, the 95 per cent confidence interval for the true exploitation rate runs from roughly 0.01 per cent to 2.45 per cent. That range comfortably contains the historical base rate of "just under one percent to two percent" that the tracker's own author, VulnCheck researcher Patrick Garrity, cites. At the 1.4 per cent KEV-to-CVE ratio VulnCheck measured for the first half of 2026, you would expect about 3.2 exploited entries in a set this size, and you would see one or fewer about 18 per cent of the time. The data cannot tell "less exploited than normal" from "normal".

That is, to be fair to Garrity, close to what he actually told The Register: that Anthropic's disclosures are not producing outcomes that differ from a random selection of other vulnerabilities. "Shrug" is a headline. "Indistinguishable from average, so far, on a small and young sample" is the finding.

What the 225 actually are

The dataset is Garrity's Anthropic CVE tracker on GitHub, which describes itself as tracking vulnerabilities that credit the Anthropic research team "and are possibly discovered by Project Glasswing". It is a personal project, "maintained on a best effort basis". A scheduled GitHub Action scans the official CVE list and GitHub advisories for keywords, opens a pull request for each match, and a human merges or rejects it. A separate script marks entries that appear in VulnCheck KEV.

We cloned the repository at its state on the morning of 22 September (the CVE records last changed on 19 September, so this is the same 225 entries The Register reported) and parsed each record. The keyword list is broader than Anthropic: it includes Calif.io, Doyensec, Ada Logics, Trail of Bits and named researchers. That breadth matters, because it means the headline set is not "CVEs found by Glasswing", which is how The Register's standfirst describes it.

Composition of the 225 tracker entries, computed from the tracker's cves/ files on 22 September 2026

MeasureCountWhat it shows
Published CVE records2187 are reserved, with no public record yet
Reserved entry now rejected1CVE-2026-35022 concerns Anthropic's own claude CLI; VulnCheck rejected it as documented behaviour
Linked to Anthropic's disclosure ledger81The other 144 rest on credit text alone
Credit field names Anthropic or Claude20421 do not; 10 of those are tied in via the ledger
Credit names Mythos or Glasswing1Model provenance is almost never stated
Dated before Glasswing was announced (7 April)43Anthropic says Mythos snapshots were in use from February
Credited to OpenAI Codex, not Claude1CVE-2026-49975, Apache HTTP Server, via the Calif.io keyword

The vendor mix is lopsided. Mozilla (32), Bouncy Castle (29) and wolfSSL (20) account for 81 entries, 36 per cent of the set. Apple (11), OpenSSL (9), the Linux kernel (7) and LibreOffice (7) follow. Much of this is browser code and cryptographic libraries, which is exactly where you would point a code-reading model at open source, and not where VulnCheck says exploitation concentrates: content management systems made up a third of the 495 vulnerabilities it added to its KEV list in the first half of 2026, with network edge devices another persistent target.

On severity, 138 entries carry a CVSS score of 7.0 or above as the tracker records it (33 critical, 105 high, 68 medium, 12 low, 7 unscored). Those scores are mixed: the tracker takes the CNA's own score, preferring CVSS 4.0, and falls back to NVD. The Ghost bug shows why that matters: GitHub, as the CNA, scored it 9.4; NVD scored it 7.5.

Five signals, five different answers

The Register's story rests on one exploitation signal, VulnCheck KEV. We ran the same 225 identifiers through four others that any UK team can query for free.

Horizontal bar chart of the 225 Anthropic-credited CVE entries. 218 are published, 138 have a recorded CVSS score of 7 or above, 29 are marked proof of concept in CISA's SSVC assessment with none marked active, 17 have an EPSS probability of 1 per cent or more, one is in VulnCheck KEV (Ghost CVE-2026-26980) and none is in the CISA KEV catalogue. A footnote gives the 95 per cent interval for a 1 in 225 rate as roughly 0.01 to 2.45 per cent.
Drawn from the Anthropic CVE tracker, the CISA KEV JSON feed (2026.09.21), CISA-ADP SSVC entries in CVE.org records and FIRST EPSS scores dated 21 September 2026.

Exploitation signals for the same 225 entries, checked 21 to 22 September 2026

SignalResultWhat it establishesWhat it does not establish
CISA KEV0 of 225No US federal patch mandate for any of themThat none is exploited; Ghost was, and is absent
VulnCheck KEV1 of 225Public evidence of exploitation for GhostAnything about the 224 others beyond no evidence yet
CISA SSVC Exploitation0 active, 29 PoC, 182 nonePublic proof-of-concept exists for 29Current state; entries are stamped when assessed and rarely revisited
EPSS, 21 Sep17 at 1% or more; 1 above 50%A modelled 30-day probability of exploitation activityCertainty; it ranks likelihood, not impact
CVSS 7.0 or above138Severity if exploitedLikelihood of exploitation at all

Three details stand out. First, Ghost's CISA-ADP SSVC entry still reads "Exploitation: none", because it was stamped on 20 February and never revisited, months after the exploitation campaign. SSVC is a snapshot, not a feed.

Second, EPSS already agrees with VulnCheck on the one that matters: Ghost scores 70.2 per cent, the 99th percentile. The median EPSS across the 218 scored entries is 0.39 per cent. Eight score 5 per cent or more, and four score 10 per cent or more: Ghost, the Codex-credited Apache HTTP Server bug (34.3 per cent), an NGINX WebDAV flaw credited to Calif.io with Claude (25.1 per cent) and a junrar bug (12.0 per cent).

Third, the EPSS probabilities sum to about 2.74. FIRST defines each score as the probability of observing exploitation activity in the next 30 days, so, as an inference that assumes the model is well calibrated for this set, you would expect two or three of these entries to show some exploitation activity in the coming month. Activity is not the same as a KEV-grade campaign, but it is not zero either.

The one that was exploited, and what it looked like

Timeline, not to scale, of Ghost CVE-2026-26980: fix 6.19.1 on 16 February, advisory 18 February, CVE 20 February with CISA SSVC recording exploitation as none; XLab saw page poisoning on 7 May (day 76), 156 domains by 10 May, over 700 and a second group by 17 May; VulnCheck KEV on 21 May (day 90); on 21 September not in CISA KEV, EPSS 70.2 per cent.
Drawn from the Ghost GitHub advisory and release, the CVE.org and NVD records, Qianxin XLab's report and the tracker's VulnCheck KEV date.

Ghost's advisory describes a SQL injection in the Content API that "allowed unauthenticated attackers to read arbitrary data from the database", affecting versions 3.24.0 to 6.19.0. The credit reads: "We thank Nicholas Carlini using Claude, Anthropic". The fix, 6.19.1, shipped on 16 February, two days before the advisory. Ghost told users to review staff accounts and rotate keys, because the flaw exposed API keys.

Qianxin's XLab team first saw exploitation on 7 May, 76 days after the CVE record appeared. Attackers used the injection to obtain Admin API keys, rewrote articles in bulk to plant JavaScript loaders in page footers, and used the sites' reputations to push fake CAPTCHA pages of the ClickFix type, ending in information-stealing malware. XLab counted 156 affected domains by 10 May and more than 700 by 17 May, including university sites, and found a second attacker group competing for the same victims. VulnCheck added the CVE to its KEV list on 21 May, day 90. The CISA catalogue has never listed it.

This is the pattern the base rates predict. The one exploited entry is an unauthenticated, internet-facing flaw in a content management system, the category that dominates exploitation data, with a patch that many site owners had not applied. Who found it, and with what tool, made no visible difference to how it was used.

Why "attackers mostly shrug" is the wrong reading

Most CVEs are never exploited. Garrity puts the historical range at just under 1 per cent to 2 per cent. VulnCheck's first-half report puts its KEV-to-CVE ratio at 1.4 per cent and notes that CVE volume grew 45 per cent against the previous six months while KEV additions grew 10 per cent. A low rate for any 225 CVEs is the default, not a verdict on who found them. VulnCheck's own wider cut, 1,061 vulnerabilities attributed to AI-assisted discovery, found 14 exploited, 1.3 per cent, which it describes as roughly matching the overall rate.

Exploitation lags, and this set is young. VulnCheck reports a median of 80 days from CVE publication to KEV in the first half of 2026. Of the 218 dated entries, 83 were published fewer than 80 days before 21 September, and the median entry is 98 days old. Ghost itself took 76 days to be seen exploited. Much of the tracker has not yet been exposed for as long as the typical exploited CVE needed.

The targets skew away from what attackers use. Over a third of the set is Firefox, Bouncy Castle and wolfSSL. Library flaws tend to be exploited, if at all, through the products that embed them, and a browser bug usually needs to be chained with others. Our inference, which the data does not test, is that flaws like these are more likely to be used by a small number of capable actors, quietly, than to show up in the mass-exploitation telemetry that feeds KEV lists. "No KEV entry" is weaker evidence for a browser bug than for a CMS plugin.

Counting can undercount in both directions. The tracker includes entries that are not Anthropic finds, and misses Anthropic finds whose credit text never mentions Anthropic. Anthropic's own ledger reports 177 CVE records and 285 GitHub advisories across its disclosed findings, a different population from the tracker's 225, only 81 of which link to that ledger.

Method, not accusation: who has a stake

Both main sources have commercial interests, and neither disqualifies them.

Anthropic benefits from Mythos being seen as unusually capable: it restricted the model to vetted partners, committed up to 100 million US dollars in usage credits, and framed the launch around danger. It has also been candid about the bottleneck. Its ledger says the number disclosed is a subset of what its models found, "since the process of independent human triage and review is the rate limiting step". VulnCheck's analysis argues the ledger's own figures do not reconcile: 421 patched on the dashboard against 202 fixed findings in the ledger table. Anthropic had not responded to The Register's questions when it published.

VulnCheck sells exploit and vulnerability intelligence and runs VulnCheck KEV, so a story in which KEV-style evidence beats CVE counts is also a story about its product. Garrity's tracker is transparent: the code, the keyword list and every record are public, which is why we could recount it. The analysis is sound as far as it goes. The headline built on it goes further than the data.

What this means for patch prioritisation in UK organisations

The practical lesson is not about Anthropic. AI-assisted discovery is raising CVE volume faster than exploitation, and every vendor patch drop now carries more of these credits. Ordering work by CVE count, by CVSS alone or by who found the bug will waste effort. Ordering by exploitation evidence will not.

There is a UK constraint to respect. Cyber Essentials v3.3 (April 2026) requires updates that fix vulnerabilities rated critical or high, or with a CVSS v3 base score of 7 or above, to be installed within 14 days of release. By the tracker's recorded scores, 138 of these 225 would qualify. EPSS and KEV can tell you what to do on day one; they do not let a certified organisation skip day fourteen. The NCSC's vulnerability management guidance makes the same split: apply updates as soon as possible, with a separate principle for responding to active exploitation.

A working priority order for UK teams, built from the signals above. Our recommendation, not a regulatory text

TierTriggerTarget
1In CISA KEV or VulnCheck KEV, and present in your estatePatch or mitigate within days; hunt for compromise
2EPSS at or above about 10%, or internet-facing and unauthenticatedPatch this week
3CVSS 7.0 or above, or vendor critical or highWithin 14 days (Cyber Essentials floor)
4Everything elseNormal patch cycle; re-score weekly
# Which of your CVEs are in CISA KEV? (cves.txt: one CVE ID per line)
curl -s https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json \
  | jq -r '.vulnerabilities[].cveID' | sort > kev.txt
sort cves.txt | comm -12 - kev.txt

# EPSS scores for up to 100 CVEs at a time
curl -s 'https://api.first.org/data/v1/epss?cve=CVE-2026-26980,CVE-2026-27654' \
  | jq -r '.data[] | [.cve, .epss, .percentile] | @tsv'

Take this with you

Actions in the order worth doing

  • If you run Ghost, confirm every instance is on 6.19.1 or later, then review staff users and rotate Admin and Content API keys as Ghost advised, and check article footers and code injection settings for unfamiliar script tags.
  • Add VulnCheck KEV alongside CISA KEV as a tier one trigger; this case shows CISA's list can miss a real campaign for months.
  • Pull EPSS scores daily for every open CVE in your estate and sort the queue by KEV status first, EPSS second, exposure third.
  • Keep the Cyber Essentials 14-day clock for CVSS 7.0 and above running in parallel; use EPSS to order work inside it, not to defer it.
  • Treat SSVC Exploitation values in CVE records as dated snapshots and check the assessment timestamp before relying on them.
  • Stop reporting CVE volume or AI-found counts as a risk metric to leadership; report exploited-and-present and time to remediate instead.
  • Watch browser and cryptographic library updates on their own merits, since absence from KEV is weak evidence for that class.

The question that exposes the gap

The Anthropic numbers will keep moving: 83 of these entries are younger than the median time to exploitation, and the tracker adds new ones every few days. Neither "AI will flood us with exploits" nor "attackers shrug" is a plan. The question for any UK security lead is simpler and harder: if the 226th entry, or any of the existing 225, were added to a KEV list tomorrow, how many hours would pass before your team knew it was in your estate, and who would own the fix?

Key facts

Sources

  1. PrimaryAnthropic CVE tracker: the 225-entry dataset, keyword list, VulnCheck KEV markers; cloned and recountedPatrick Garrity (GitHub)accessed 2026-09-22
  2. PrimaryKnown Exploited Vulnerabilities catalogue JSON, version 2026.09.21; cross-checked against all 225 entriesCISAaccessed 2026-09-22
  3. PrimaryEPSS API: scores dated 21 September 2026 for the 218 published entriesFIRSTaccessed 2026-09-22
  4. PrimaryEPSS explainer defining the score as the probability of exploitation activity in the next 30 daysFIRSTaccessed 2026-09-22
  5. PrimaryCVE records for all 225 entries via the CVE Services API, used for CISA-ADP SSVC exploitation values and record statesCVE Programaccessed 2026-09-22
  6. PrimaryNVD record for the Ghost CVE: CWE-89, NVD score 7.5 and GitHub CNA score 9.4NIST NVDaccessed 2026-09-22
  7. PrimaryGhost security advisory for the Content API SQL injection, affected versions, fix and creditGhost Foundationaccessed 2026-09-22
  8. PrimaryGhost 6.19.1 release, published 16 February 2026Ghost Foundationaccessed 2026-09-22
  9. PrimaryReport of in-the-wild exploitation of CVE-2026-26980: dates, domain counts and attack chainQianxin XLabaccessed 2026-09-22
  10. Primary1H 2026 State of Exploitation: 495 KEVs, 80-day median, 1.4% KEV-to-CVE ratio, AI-assisted discovery figuresVulnCheckaccessed 2026-09-22
  11. PrimaryGarrity's September review of Anthropic's disclosure ledger, including the severity comparisonVulnCheckaccessed 2026-09-22
  12. PrimaryGarrity's April method post and caveat on inconsistent CVE creditsVulnCheckaccessed 2026-09-22
  13. PrimaryAnthropic coordinated vulnerability disclosure dashboard, figures as of 26 August 2026Anthropicaccessed 2026-09-22
  14. PrimaryProject Glasswing announcement, 7 April 2026Anthropicaccessed 2026-09-22
  15. PrimaryCyber Essentials Requirements for IT Infrastructure v3.3: 14-day rule for CVSS 7 and aboveNCSCaccessed 2026-09-22
  16. PrimaryNCSC vulnerability management guidance and its five principlesNCSCaccessed 2026-09-22
  17. Reported byNews report that prompted this briefing; source of Garrity's quotes and the 225 and one-exploited framingThe Registeraccessed 2026-09-22

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.