cd /news/artificial-intelligence/microsoft-races-to-patch-hundreds-of… · home topics artificial-intelligence article
[ARTICLE · art-80040] src=mlq.ai ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

Microsoft Races to Patch Hundreds of Security Bugs Found by Anthropic’s Mythos

Microsoft engineers are racing to patch hundreds of security flaws found by Anthropic's Claude Mythos Preview, an unreleased AI model that identified 90 critical and 141 important SharePoint vulnerabilities in April alone, according to internal records reviewed by ProPublica. Microsoft received Mythos access as a launch partner in Project Glasswing, Anthropic's defensive-security program, and internal slides said roughly 50 Microsoft employees received access. The company planned to address critical and important SharePoint findings first, followed by roughly 300 moderate bugs, with a goal of clearing April findings before May 31.

read6 min views1 publishedJul 30, 2026
Microsoft Races to Patch Hundreds of Security Bugs Found by Anthropic’s Mythos
Image: Mlq (auto-discovered)
  • Claude Mythos Preview found 90 critical and 141 important SharePoint vulnerabilities in April, with more arriving during the first half of May, according to internal Microsoft materials reviewed by ProPublica. [1] - Microsoft was a launch partner in Project Glasswing, Anthropic’s restricted defensive-security program, and internal slides said roughly 50 Microsoft employees received access to Mythos. [1][2] - Microsoft planned to address critical and important SharePoint findings first, followed by roughly 300 moderate bugs. The internal materials did not describe plans for low-severity findings. [1] - The Zero Day Initiative counted 621 new Microsoft CVEs in July, but Microsoft has not disclosed how many originated with Mythos.

[5] Microsoft engineers are racing through hundreds of security flaws found by Anthropic’s Claude Mythos Preview, an unreleased AI model that was producing vulnerability reports faster than the company could patch them, according to internal records and a meeting recording reviewed by ProPublica.[1]

In SharePoint alone, Mythos identified 90 vulnerabilities Microsoft classified as critical and 141 classified as important during April. The model found additional flaws in the first half of May. Internal documents also described hundreds of critical or important findings across Microsoft 365, Teams and Copilot, most of which remained unpatched as of mid-May.[1]

A restricted defensive program produced a patching backlog #

Microsoft received Mythos access as a launch partner in Project Glasswing, Anthropic’s defensive-security initiative announced on April 7. The initial group also included Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, Nvidia, Palo Alto Networks and the Linux Foundation. Anthropic said it extended access to more than 40 additional organizations that build or maintain critical software infrastructure.[2]

The program allowed partners to use Mythos for defensive work on first-party and open-source systems, including source-code analysis, binary testing, endpoint security and penetration testing. Anthropic committed up to $100 million in model-usage credits to the effort and $4 million to open-source security organizations. [2] Its disclosure policy says research on closed-source software is covered only where Anthropic has obtained appropriate authorization.

[3]Internal Microsoft slides said roughly 50 full-time employees received access, with the goal of hardening critical services before publicly available models caught up. During a mid-May meeting, an engineering manager described the response as a “mad dash” and pressed teams to clear April findings before May 31, which the presentation treated as the point when outside capabilities might close the gap. [1] That date was an internal forecast, not an independently established deadline.

Anthropic declined to comment to ProPublica. In a May 22 public update, the company said it and approximately 50 Glasswing partners had collectively found more than 10,000 high- or critical-severity vulnerabilities. Anthropic did not provide a partner-by-partner breakdown or enough detail to independently assess that aggregate count.[4]

Microsoft is treating the highest-risk findings first #

The Microsoft materials show engineers following the company’s existing severity system: critical findings first, followed by important vulnerabilities. The SharePoint group expected to remain occupied for months, with important bugs scheduled for work in August before engineers moved to roughly 300 moderate findings. The records did not mention low-severity SharePoint bugs.[1]

Microsoft defines critical vulnerabilities as flaws that could allow code execution without user interaction, including self-propagating malware or common-use scenarios with no warnings. Important vulnerabilities can compromise the confidentiality, integrity or availability of data or processing resources. Microsoft separately cautions that severity measures the worst theoretical outcome, not the likelihood of exploitation.[6]

A Microsoft spokesperson told ProPublica that triage decisions consider exploitability and customer impact, and that exploit chains have long been part of its risk assessments. The company declined to say how many Mythos findings had been patched since May. Microsoft said security remained its most important priority and that teams were using AI to discover and remediate vulnerabilities as quickly as possible.[1]

Anthropic’s disclosure policy normally targets public disclosure after 90 days or when a patch is released, whichever comes first. It permits a 14-day extension for vendors making progress and sets a seven-day target for a patch or mitigation when a critical vulnerability is under active exploitation. Full technical details generally remain private for 45 days after a patch to give users time to deploy it.[3]

Patch volumes show the scale, but not Mythos’ contribution #

Microsoft’s public patch volume has expanded sharply. The Zero Day Initiative counted 208 Microsoft CVEs in June and 621 new CVEs in July. The July total included 63 critical, six moderate and one low vulnerability, with the remainder rated important. Two were listed as under active exploitation, including a remotely reachable SharePoint flaw with a CVSS score of 5.3.[5][7]

The July release covered Windows, Office, Azure, GitHub Copilot, Defender, Exchange Server, Hyper-V and other products. Microsoft has not identified which of those patches, if any, originated with Mythos. Its own MDASH vulnerability-hunting system is also operating across Windows, Azure and identity products, and Microsoft credited that system with discoveries affecting Hyper-V, the Windows kernel, Active Directory, Remote Desktop and other components.[8]

The difficult issue is whether conventional triage fully captures the risk from AI systems capable of combining modest flaws into more serious exploit chains. Vinh Nguyen, a former National Security Agency chief AI officer who is now a senior technical adviser to Anthropic, told ProPublica that several low-level flaws can combine into a high-severity attack. His affiliation means his assessment is not independent of Anthropic, although Microsoft separately acknowledged that AI systems could force the industry to reconsider how low and moderate findings are classified.[1]

Independent indicators point to a broader capacity problem. Dustin Childs of the Zero Day Initiative described July’s release as record-breaking, while vulnerability-management specialist Ben Edwards told ProPublica that the industry was already handling intense report volumes before AI accelerated discovery.[1] [5] Five Eyes cybersecurity agencies warned on June 22 that AI was shrinking the period between vulnerability discovery and exploitation and urged organizations to accelerate patching.

[9]Faster scanning does not remove the human work after discovery. Engineers still have to reproduce findings, determine reachability and severity, build fixes, test them against deployed systems and distribute updates. Microsoft has not disclosed the size of its remaining Mythos backlog or how many of the model’s findings have reached customers as patches.

Companies mentioned #

Further sources #

[[1] ProPublica, “Anthropic’s New AI Model Can Identify More Software Bugs Than Ever… ↗](https://www.propublica.org/article/anthropic-mythos-microsoft-software-vulnerabilities)

[[2] Anthropic, “Project Glasswing: Securing critical software for the AI era,” Apri… ↗](https://www.anthropic.com/glasswing)

[[3] Anthropic, “Coordinated vulnerability disclosure for Claude-discovered vulnerab… ↗](https://www.anthropic.com/coordinated-vulnerability-disclosure)

[[4] Anthropic, “Project Glasswing: An initial update,” May 22, 2026. ↗](https://www.anthropic.com/research/glasswing-initial-update)

[[5] Zero Day Initiative, “The July 2026 Security Update Review,” July 14, 2026. ↗](https://www.zerodayinitiative.com/blog/2026/7/14/the-july-2026-security-update-review)

[[6] Microsoft Security Response Center, “Security Update Severity Rating System.” ↗](https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system)+3 more

The stories that matter, in one email. Free — unsubscribe anytime.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @microsoft 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/microsoft-races-to-p…] indexed:0 read:6min 2026-07-30 ·