Loading...
Loading...
Vulnerability remediation, the work of patching, changing code or configuration, or retiring a flawed component and then proving the fix holds, is now the bottleneck in security. As of August 26, 2026, Anthropic had disclosed 2,300 open-source vulnerabilities found by Claude Mythos Preview, its restricted cybersecurity model, and other Claude models, and knew of 421 that maintainers had patched.
On September 22, 2026, Palo Alto Networks launched Unit 42 Continuous Frontier AI Defense and put two numbers side by side. In its internal deployment, Unit 42's frontier-model harness produced "over a year's worth of traditional penetration testing results in just three weeks." The same harness "helped engineering teams cut mean time to remediate by 51%," according to Unit 42.
The second number decides whether the first one matters.
Fernando Montenegro of the analyst firm The Futurum Group flagged the catch. The 51% came from Palo Alto's internal deployment. Customer data, where security does not control engineering, is "the real test," Montenegro wrote. In Futurum's 1H 2026 Cybersecurity Decision Maker Survey, friction routing patch work from security back to IT operations and DevOps was the most-cited operational hurdle, named in the top three by half of respondents. He proposed "exposures closed rather than exposures found" as the measure Unit 42 should report to customers.
That measure points one step past the patch. The fix ships, the ticket closes, and someone still has to show the attack path is gone in the environment where it was found.
Vulnerability remediation is now the bottleneck, by Anthropic's own account. Project Glasswing launched with about 50 partners using Claude Mythos Preview, and Anthropic wrote in its May 22, 2026 Glasswing update: "Progress on software security used to be limited by how quickly we could find new vulnerabilities. Now it's limited by how quickly we can verify, disclose, and patch the large numbers of vulnerabilities found by AI."
Its disclosure dashboard shows where the work piles up. Between November 2025 and August 26, 2026, Anthropic's models produced 26,153 candidate findings in open-source code. External security firms reviewed 5,008 of them and confirmed 91.4% as real. Anthropic disclosed 2,300 vulnerabilities across 392 projects, and to its knowledge 421 had been patched. The disclosures are themselves a subset of what the models found, because, in the page's words, "the process of independent human triage and review is the rate limiting step."
In its May update, Anthropic said it was likely undercounting patches shipped without a public advisory, and that many disclosures were still inside the 90-day disclosure window. It still called the low patch count "a genuine problem," and noted that enterprises fixing their own code move faster than volunteer maintainers.
Enterprises were losing ground before any of this. Verizon's 2026 Data Breach Investigations Report found that only 26% of vulnerabilities in CISA's Known Exploited Vulnerabilities catalog were fully remediated in 2025, down from 38% the year before. Verizon found the median time to fully resolve them rose from 32 days to 43. In the median case, organizations had 50% more critical vulnerabilities to patch than the year before.
Verizon's data ends in November 2025. Anthropic didn't start scanning open source with an early Claude Mythos Preview snapshot until February 2026, so none of the new volume is in those numbers.
Every model you add brings findings. None of them brings an engineer, a change window, or a regression suite.
No. Palo Alto Networks' Unit 42 reported in September 2026 that "no single AI model catches more than 40% of vulnerabilities in a complex environment," and that Anthropic's Claude Mythos 5 (the June 2026 update to Mythos Preview) and OpenAI's GPT-5.6-Cyber "have less than 10% overlap in the exposures they identify" in its testing.
Google said much the same at its AI Threat Defense launch in May 2026: "No single model finds the superset of vulnerabilities that other models find." The large vendors selling frontier-model testing pair it with human experts and with help acting on the findings. Unit 42 delivers fix guidance and points customers to Frontier Virtual Patching, and CrowdStrike's Frontier AI Readiness and Resilience page promises: "Most vulnerability programs end with a PDF. This one doesn't." Google routes fixes through CodeMender and says its platform "automatically generates tests to verify every fix" before a patch goes live.
If two leading models overlap on under a tenth of what they find, a clean report from one model covers only what that model could see on the day it ran. Treat it as one sample when you report it upward. That holds for any single AI pentest, ours included, which is why the measures at the end of this piece count fixes verified rather than findings.
AI vulnerability discovery grows the backlog because every finding costs human time to reproduce, report, and fix, and models are built to produce findings. Cloudflare, a Glasswing participant, wrote in May 2026: "Ask a model to find bugs, and it will find them, whether the code has any or not." The team called that bias reasonable for an exploratory tool and "a ruinous one for a triage queue," because every speculative finding spends human attention.
Mythos Preview raised the quality bar. Cloudflare said its output arrived with fewer hedged findings and clearer reproduction steps, and Anthropic's 91.4% confirmation rate points the same way. Real findings still need a person to confirm, report, and patch each one, and models now produce far more of them than any team produced before.
The open-source tool curl shows the review that sits between a model's report and a real vulnerability. When a Claude Mythos report on curl, delivered in May 2026, listed five "confirmed security vulnerabilities," curl lead developer Daniel Stenberg and his security team spent hours on the list. One survived as a vulnerability. Of the other four, three were false positives and one was "just a bug."
Stenberg still calls AI analyzers "significantly better at finding security flaws" than the older tools, and earlier AI tools had already prompted two to three hundred curl bug fixes over roughly eight to ten months.
Severity is the second cost. Anthropic's disclosure dashboard, as of August 26, 2026, shows Claude's severity ratings matched the external security research firms' ratings exactly 85.2% of the time. They fell within one band 97.1% of the time. The firms' ratings tend to run lower, Anthropic says, because they account for "project-specific severity rules that Claude does not have access to at run time." A model's high rating shouldn't set your fix order on its own.
Fix first the vulnerabilities your own team has already judged dangerous. CVSS, EPSS, and a model's severity label all score a flaw without knowing your environment. Your SOC spent last month deciding which hosts were under attack and which apps barely matter, and those calls should reorder the list.
When Simbian's AI SOC Agent and AI Pentest Agent share context, that judgment carries into the pentest in three ways:
Your analysts made each of those calls while working alerts, and the pentest reuses them instead of guessing. Their past decisions record which hosts were actually attacked and which ones your team already ruled low. If your SOC and AppSec teams report to different leaders, this is a direct way to get one team's knowledge into the other's queue.
Vulnerability remediation ends when a retest shows the patch closed the attack path the original finding demonstrated. Many programs treat a closed ticket as the last step of the vulnerability remediation process, and that is where exposure hides.
Asked about the most common mistake companies make after a pentest, one practitioner on r/Pentesting answered: "Getting a report, fixing issues and then...not checking again. Are the issues really fixed? Was the workaround really enough?"
Frontier models raise the stakes. Cloudflare let a model write its own patches and watched "a few go out that fixed the original bug while quietly breaking something else the code depended on," the team wrote. It also said more than one team it has spoken with now runs a two-hour SLA from CVE release to patch in production. Cloudflare's warning: "if regression testing takes a day, you cannot get to a two-hour SLA without skipping it."
The window of exposure runs from the moment a flaw ships to the moment its fix is verified. Discovery sits in the middle of that window, and a retest closes it. The retest is also the step teams have historically skipped. In Simbian's conversations with pentest buyers this year, they put a human retest at 25 to 50 percent of the original engagement's cost, and at that price, many told us, they shipped the fix unverified.
Pre-release tests help, and Google's AI Threat Defense now generates one for every fix. A retest adds a different check: it replays the original attack path in the environment where the finding was made.
Simbian's AI Pentest Agent treats a Retest as a new run scoped to the findings you select, typically the ones your team has fixed, and it retests the same path the original finding proved. Every finding already carries reproduction steps a developer can run by hand, and a Thought Trace: the Agent's record of how it reached the exploit. Up to five Retests are included with each engagement. When one of your pentesters, or a partner's, corrects a finding, the edit becomes a new version with a note explaining why. The Agent reads that note on the next Retest.
AI-written patches aren't ready to ship unreviewed on systems that matter. In a recent r/cybersecurity thread about responding to Mythos, one commenter wrote that a mission-critical system still needs a human "to sign off the actual patch," at least for now. The same logic applies to automated security remediation in the SOC, where an action needs human approval whenever the blast radius of a wrong call outweighs the system's confidence in its verdict.
A passing Retest shows the path you tested is closed. It says nothing about the next variant of that bug, or about what the first run missed, which is the job of the next full run and of detection.
Remediation removes a vulnerability by patching, changing code or configuration, or retiring the component. Mitigation reduces the chance or impact of exploitation while the vulnerability stays in place, through a virtual patch, a WAF rule, network segmentation, or detection. Most programs need both, because exploitation often begins before a patch exists.
Right now you need the time mitigation buys. Mandiant's M-Trends 2026 estimated the mean time to exploit at minus seven days, meaning exploitation routinely happens before a patch is released. Unit 42's launch post says automated adversary scanners weaponize newly disclosed CVEs within 15 minutes. Verizon's median time to full resolution for KEV-listed vulnerabilities is 43 days.
Anthropic's own advice to network defenders in the Glasswing update points to critical controls such as "keeping comprehensive logs for detection and response," which improve security "without depending on any single patch landing in time."
Detection is also the one mitigation a pentest can test directly. A pentest that proves an exploit path is the most realistic test of whether your detections cover it. Simbian routes AI Pentest Agent findings to the AI SOC Agent, which checks detection coverage for the affected asset and investigates the alerts the pentest's own exploit attempts set off. That's the idea behind adversarial exposure validation, which asks whether prevention stopped the exploit and whether detection saw it, and behind continuous security validation more broadly.
Measure vulnerability remediation by exposures closed and verified, using four numbers:
Continuous pentesting that runs the loop from finding to fix to retest to detection is built to move all four.
Go back to the two numbers Palo Alto put side by side. A year of findings in three weeks is the number every new model will beat. The 51% cut in mean time to remediate is the one worth copying. Montenegro wants Unit 42 to report exposures closed, and stopping your own clock at a passing retest is how you count them. The AI Pentest Buyer's Scorecard covers remediation and continuous testing among the eight dimensions it uses to evaluate AI pentest vendors.
Q: What is vulnerability remediation? Vulnerability remediation is the process of removing a security flaw, by patching, changing code or configuration, or retiring the affected component, and then verifying the flaw can no longer be exploited. It differs from mitigation, which reduces the chance or impact of exploitation while the flaw stays in place.
Q: What is mean time to remediate? Mean time to remediate is the average time between discovering a vulnerability and fixing it. Many programs stop the clock when the ticket closes, which records when someone said the flaw was fixed. A stricter measure stops it at a passing retest of the original exploit path, so the number tracks exposure actually closed.
Q: What are the 5 steps of the vulnerability remediation process? A common five-step model is discover, prioritize, fix, verify, and monitor. Discover the flaw; prioritize it against business context; fix it with a patch, a code or configuration change, or by retiring the component; verify the fix by retesting the original exploit path; and monitor for new attempts and variants. Programs that skip verification close tickets without knowing whether the exposure ended.
Q: What are examples of vulnerability remediation? Applying a vendor patch, upgrading a vulnerable library, changing a misconfigured access policy, rewriting unsafe input handling, and decommissioning an unsupported server are all remediation. Each counts as complete only once a retest shows the original exploit no longer works.
Q: Can AI models like Claude Mythos find and fix vulnerabilities? Partly. Claude Mythos Preview and other Claude models find real vulnerabilities at scale, and external security firms confirmed 91.4% of the candidate findings they reviewed through August 2026. Models can also propose patches, but Cloudflare reported that a few model-written patches fixed the original bug while quietly breaking something else, so each fix still needs human review, regression testing, and a retest.
Q: What are the best practices for vulnerability remediation? Vulnerability remediation best practices start with the findings your own team has already judged dangerous, ahead of raw CVSS order. Have a human approve patches on critical systems, run regression tests before release, and retest the original exploit path before the ticket closes. Track time to verified fix and retest pass rate, and confirm your detections would catch an attempt while a fix is pending.