Epoch's work is free to use, distribute, and reproduce provided the source and authors are credited under the Creative Commons BY license.
Learn more about this graph
In April 2026, Anthropic announced that its latest internal model (Claude Mythos Preview) was capable of autonomous cybersecurity vulnerability discovery and exploitation. Since then, both Anthropic and OpenAI have launched efforts to use frontier models to harden critical software before malicious actors are able to use similarly capable models for harm.
We show that the number of Common Vulnerabilities and Exposures (CVEs) has kept climbing since these announcements. In June, notable organizations published around 1,550 high- and critical-severity CVEs — more than 3× the monthly record prior to the Claude Mythos Preview announcement. July’s total reached around 2,500, about 5× that pre-Mythos record.
These disclosure figures are not the only indication that frontier AI cyber capabilities are now meaningful. In late July, OpenAI reported that GPT-5.6 Sol, working together with a more capable unreleased internal model, autonomously hacked Hugging Face while attempting to cheat on a cybersecurity benchmark — chaining at least three previously unknown security vulnerabilities across OpenAI’s and Hugging Face’s systems (see also this independent analysis of the incident). Anthropic subsequently reported that its own models had compromised external providers’ systems on multiple occasions during evaluations (though the company says the models did not find or exploit any complex vulnerabilities). As our Gradient Update on the OpenAI incident argues, expert assessments and cyber benchmarks had already suggested that frontier models were capable of executing this kind of attack.
Data
Assumptions and limitations
Download this data
Explore this data
Explore trends in software and hardware vulnerabilities (CVEs) since 2020 — how counts and severity have changed over time, broken down by the organizations that report them.

