Glasswing’s security team identified 225 software flaws tied to Anthropic’s AI services, with VulnCheck monitoring each issue. Only a single vulnerability has been confirmed in active attacks, according to the latest analysis released on September 21, 2026. The findings highlight a growing attack surface around AI platforms, even as most discovered bugs remain unexploited.
The bulk of the vulnerabilities stem from misconfigurations, outdated libraries, and insufficient input validation in Anthropic’s APIs and supporting infrastructure. Researchers say the flaws were uncovered through automated scanning and manual code review, then reported to Anthropic for remediation. While the company patched most issues promptly, the sheer volume underscores the challenges of securing rapidly evolving AI ecosystems. The lone exploited flaw involved a remote code execution path in a third‑party component that was inadvertently exposed to the internet.
Security analysts note that AI providers like Anthropic attract attention because their services power countless downstream applications. „When a single API call can influence business decisions, attackers are motivated to find any foothold,” said Maya Patel, a senior threat analyst at SecureFuture. The research team found that many of the CVEs (Common Vulnerabilities and Exposures) were low‑severity, but their cumulative effect could enable chained attacks. For example, a series of privilege‑escalation bugs could allow an adversary to move laterally across cloud environments that host Anthropic’s models. The report also points to supply‑chain risks, as several vulnerabilities originated in open‑source libraries that Anthropic incorporates without thorough vetting.
Despite the high count of reported issues, real‑world exploitation remains limited. The only confirmed case involved a misconfigured container that exposed a debug endpoint, which hackers used to execute arbitrary commands. „The low exploitation rate suggests that most researchers are still in the discovery phase, and attackers may be waiting for a more lucrative vector,” Patel added. Nonetheless, the presence of unpatched bugs creates a tempting landscape for opportunistic threat actors, especially as AI adoption accelerates across sectors like finance, healthcare, and government.
The implications are clear: organizations that integrate Anthropic’s models must adopt rigorous security hygiene, including regular dependency audits and strict network segmentation. Anthropic has pledged to strengthen its vulnerability‑management program, promising faster disclosure timelines and deeper collaboration with the security community. As AI continues to embed itself in critical workflows, the pressure to close these gaps will intensify, prompting both vendors and users to prioritize resilient design.
What types of vulnerabilities were most common in the report? Most findings involved configuration errors, outdated third‑party components, and insufficient input sanitization, which can lead to denial‑of‑service or privilege escalation.
Has Anthropic disclosed all the identified flaws publicly? Anthropic has acknowledged the majority of the CVEs and issued patches, but a few low‑severity issues remain under coordinated disclosure with researchers.
Should businesses stop using Anthropic’s AI services until the issues are fully resolved? No. While the vulnerabilities highlight risks, Anthropic’s rapid patching and ongoing security improvements mean the services remain usable, provided clients follow recommended security best practices.