Anthropic’s coordinated vulnerability disclosure program using Claude Mythos Preview identified 23,019 candidate vulnerabilities in open-source code. Of 1,596 confirmed valid flaws disclosed to 281 projects, only 97 had been patched by May 22, 2026. That’s a 16:1 discovery-to-fix ratio.
DARPA’s AI Cyber Challenge showed the same constraint: 25 zero-days identified, 12 patched. The problem is structural. While AI discovers flaws at scale, patching requires manual coordination that can’t parallelize. A single researcher finds vulnerabilities faster than a team writes and validates fixes.
Add deployment lag. These 97 patches represent upstream open-source releases, but applications typically run versions years behind. The real operational gap is much wider than 16:1. The bottleneck is patch management infrastructure, which fundamentally can’t operate at the scale vulnerability discovery now reaches.
Sources: Anthropic Coordinated Vulnerability Disclosure Dashboard • SoK: DARPA’s AI Cyber Challenge
Coverage: The vulnerability gap: why discovery is outrunning repair • HackerOne: AI Vulnerability Discovery Is Outpacing Remediation
Related on this blog: [AUTO] AI’s Predictable Hallucinations Become Supply-Chain Weapons • 54 Fake CVEs in Four Days, and Nobody Checked • [AUTO] Poison Claude: Discounted Access, Full Visibility