Data Insight
Jul. 31, 2026

Serious cyber vulnerability disclosures kept climbing in July

Disclosures of serious cybersecurity vulnerabilities (CVEs rated high or critical) have continued to surge. In July, notable organizations published around 2,500 high- and critical-severity CVEs — about 5× the monthly record prior to the Claude Mythos Preview announcement, and 60% above June’s record-breaking total.

Recent real-world incidents have shown that frontier models can autonomously hack into production systems, sometimes without the knowledge of the companies that build and evaluate them. OpenAI reported that one of its models hacked Hugging Face’s servers to obtain the solution to a cybersecurity benchmark, and Anthropic subsequently found that its models had gained unauthorized access to the systems of three external organizations during evaluations.

Epoch's work is free to use, distribute, and reproduce provided the source and authors are credited under the Creative Commons BY license.

Learn more about this graph

In April 2026, Anthropic announced that its latest internal model (Claude Mythos Preview) was capable of autonomous cybersecurity vulnerability discovery and exploitation. Since then, both Anthropic and OpenAI have launched efforts to use frontier models to harden critical software before malicious actors are able to use similarly capable models for harm.

We show that the number of Common Vulnerabilities and Exposures (CVEs) has kept climbing since these announcements. In June, notable organizations published around 1,550 high- and critical-severity CVEs — more than 3× the monthly record prior to the Claude Mythos Preview announcement. July’s total reached around 2,500, about 5× that pre-Mythos record.

These disclosure figures are not the only indication that frontier AI cyber capabilities are now meaningful. In late July, OpenAI reported that GPT-5.6 Sol, working together with a more capable unreleased internal model, autonomously hacked Hugging Face while attempting to cheat on a cybersecurity benchmark — chaining at least three previously unknown security vulnerabilities across OpenAI’s and Hugging Face’s systems (see also this independent analysis of the incident). Anthropic subsequently reported that its own models had compromised external providers’ systems on multiple occasions during evaluations (though the company says the models did not find or exploit any complex vulnerabilities). As our Gradient Update on the OpenAI incident argues, expert assessments and cyber benchmarks had already suggested that frontier models were capable of executing this kind of attack.

Data

Assumptions and limitations

Download this data

Explore this data