跳到正文
北京时间
原文
Epoch AI:研究、数据与评测· Luke Emberson·· 2026-07-31精选AI 评分68

Epoch AI 数据:2026 年 7 月高危及严重 CVE 数达 Mythos 发布前纪录的约 5 倍

Disclosed CVEs: July Reached 5× the Pre-Mythos Record

AI 导读

Epoch AI 分析 cve.org 数据发现,2026 年 6 月 21 家知名机构披露的高危及严重 CVE 约 1,550 个,7 月达约 2,500 个,约为 Claude Mythos Preview 发布前月度纪录(约 490 个)的 5 倍。

推荐理由

原文用公开 CVE 数据量化前沿模型发布后的漏洞披露激增,并给出数据口径与局限性说明。

正文

Learn more about this graph

In April 2026, Anthropic announced that its latest internal model (Claude Mythos Preview) was capable of autonomous cybersecurity vulnerability discovery and exploitation. Since then, both Anthropic and OpenAI have launched efforts to use frontier models to harden critical software before malicious actors are able to use similarly capable models for harm.

We show that the number of Common Vulnerabilities and Exposures (CVEs) has kept climbing since these announcements. In June, notable organizations published around 1,550 high- and critical-severity CVEs — more than 3× the monthly record prior to the Claude Mythos Preview announcement. July’s total reached around 2,500, about 5× that pre-Mythos record.

These disclosure figures are not the only indication that frontier AI cyber capabilities are now meaningful. In late July, OpenAI reported that GPT-5.6 Sol, working together with a more capable unreleased internal model, autonomously hacked Hugging Face while attempting to cheat on a cybersecurity benchmark — chaining at least three previously unknown security vulnerabilities across OpenAI’s and Hugging Face’s systems (see also this independent analysis of the incident). Anthropic subsequently reported that its own models had compromised external providers’ systems on multiple occasions during evaluations (though the company says the models did not find or exploit any complex vulnerabilities). As our Gradient Update on the OpenAI incident argues, expert assessments and cyber benchmarks had already suggested that frontier models were capable of executing this kind of attack.

Data

Our Cyber Vulnerability Reports hub visualizes data from cve.org, a public repository of CVE reports from software companies and third-party security researchers. We focus our analysis on CVEs reported by 21 notable organizations to avoid capturing noisy submissions from less reputable sources. These notable organizations include:

Microsoft · Google · Apple · Adobe · Oracle · Cisco · IBM · Red Hat · Intel · AMD · NVIDIA · Qualcomm · Samsung · SAP · Amazon (AWS) · VMware (Broadcom) · GitHub (own products) · Linux · Mozilla · Apache · OpenSSL

Assumptions and limitations

Our figures come from publicly disclosed vulnerabilities, which do not include discovered but not publicly disclosed vulnerabilities. Anthropic claims that their Project Glasswing alone has identified over 10,000 high- and critical-severity vulnerabilities.

While some of the increase in observed vulnerability disclosure is almost certainly due to increased feasibility of discovery, the spike may also be caused in part by an increase in the amount of interest in discovering bugs.

Severity ratings and disclosure records are revised over time as CVEs are scored and amended after publication, so historical monthly counts can shift. Our figures for 2025 are now somewhat higher than those shown in our earlier insight on this data, which raises the pre-Mythos monthly record from roughly 440 to roughly 490 high- and critical-severity CVEs. The comparisons above use the revised figures.

Download this data

Monthly high- and critical-severity CVEs from 21 notable organizations

Explore this data

Cyber Vulnerabilities

Explore trends in software and hardware vulnerabilities (CVEs) since 2020 — how counts and severity have changed over time, broken down by the organizations that report them.

来源:Epoch AI:研究、数据与评测 · epoch.ai

相关事件