ANTHROPIC has expanded its Cyber Verification Program (CVP) to allow more vetted cybersecurity professionals to test Claude models with fewer safeguards and blocking classifiers. The move follows Project Glasswing, which Anthropic says uncovered at least 129,000 verified software vulnerabilities between April and July 2026, with a further 5,500 verified flaws found from April to October 2026 via open-source scanning.
The company notes that more than 33,000 of the verified vulnerabilities are rated as critical or high severity, though it acknowledges this is likely an undercount, based on data from only a subset of Glasswing partners. Anthropic suggests the true impact could be at least five times higher.
The CVP introduces three access tiers to align with defenders’ needs: Defense Access (incident response, malware reverse engineering, vulnerability analysis and validation), Red Team Access (adds authorised penetration testing and red-teaming), and Specialized Access (fewest safeguards for a limited group authorised to test safety systems). Access includes use of Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and upcoming models.
In CyScenarioBench evaluations cited by Anthropic, Defense Access blocked 46 of 50 tasks on Claude Opus 5.5, while Red Team Access completed 34 of 50 tasks—identical to results with no safeguards; without CVP access, every task was blocked on the first prompt. The company emphasises that AI-driven verification aims to balance defensive benefits with the dual-use risk of abuse.
Notably, two widely cited exploited vulnerabilities linked to other products remain CVEs of interest in related analyses: CVE-2026-26980 and CVE-2026-61500.