// AI threat desk · 7 Oct 2026
Home/CVE · Vulns & Patches
Vulns & PatchesMediumCVPCVSS not assigned

Anthropic expands Cyber Verification Program into three access tiers

Anthropic expanded its Cyber Verification Program on Oct 6, 2026, giving qualifying security professionals advanced cyber capabilities and reduced blocking classifiers.

AI-generated image of security analysts reviewing blurred cyber-defense dashboards in a monitoring centre.
AI-generated image, not a photo of the event.
Key takeaways
  • The Cyber Verification Program now has three access tiers, and each includes Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1 and future models.
  • Defense Access covers defensive security work, while Red Team Access adds authorized penetration testing and red teaming.
  • Specialized Access has the fewest cyber blocks and is limited to verified organizations testing safety systems that could affect people’s lives or disrupt markets.

Anthropic expanded its Cyber Verification Program on Oct 6, 2026, creating three access tiers for qualifying cybersecurity professionals. The program provides advanced cyber capabilities and reduced blocking classifiers, the company said.

Defense Access covers security operations, incident response, malware reverse engineering, and vulnerability analysis and validation, and Red Team Access adds authorized penetration testing and red-teaming. Specialized Access is reserved for verified organizations authorized to test safety systems that could impact people’s lives or disrupt markets.

Anthropic said organizations enrolled in the program must retain data so it can monitor for cyber misuse. The Cyber Verification Program is available on the Claude Platform, Google Cloud’s Vertex AI and Microsoft Foundry.

On this page

Anthropic measured different blocking levels across the tiers

Anthropic’s CyScenarioBench testing showed that every task was blocked on its first prompt without Cyber Verification Program access. Defense Access blocked 46 of 50 trials at some point, while four tasks succeeded.

Red Team Access produced no blocks in the test, and Claude Opus 5.5 completed 34 of 50 CyScenarioBench tasks.

Project Glasswing partners found 129,000 verified vulnerabilities

Anthropic said Project Glasswing partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026. More than 33,000 of those vulnerabilities had been rated critical or high severity.

The company said its own open-source scanning found another 5,500 verified software vulnerabilities between April and October 2026. Anthropic said its vulnerability total is likely an undercount and it expects the true impact to be at least five times higher.

Anthropic requires data retention for enrolled organizations

Data retention is required for organizations enrolled in the program so Anthropic can monitor for cyber misuse. The company said Enterprise Frontier Safeguards will later offer eligible organizations a way to store data in cloud infrastructure they control.

The company said Enterprise Frontier Safeguards combines the privacy of zero data retention with safeguards and will be available later this fall.

Organizations can apply to the program, but Anthropic said applicants will be verified and must provide proof of the security controls required for the relevant access tier.

FAQ

What did Anthropic change in its Cyber Verification Program?

Anthropic expanded the program into three access tiers that provide qualifying security professionals with advanced cyber capabilities and reduced blocking classifiers.

What are Anthropic’s three Cyber Verification Program tiers?

The tiers are Defense Access, Red Team Access and Specialized Access. Defense Access supports defensive work, Red Team Access adds authorized penetration testing and red teaming, and Specialized Access is reserved for verified organizations testing high-impact safety systems.

Which models are included in Anthropic’s cyber access tiers?

Each tier includes Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1 and new models moving forward.

How does Anthropic control cyber misuse in the program?

Anthropic requires data retention for organizations enrolled in the program so it can monitor for cyber misuse. Applicants must also provide proof of the security controls required for their access tier.

Where is Anthropic’s Cyber Verification Program available?

The program is available on the Claude Platform, Google Cloud’s Vertex AI and Microsoft Foundry.

How many vulnerabilities did Project Glasswing uncover?

Anthropic said Project Glasswing partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026, while its own open-source scanning found another 5,500 between April and October 2026.

Sources

  1. We Asked 100+ AI Models to Write Code. Here’s How Many Failed Security Tests. | Veracode, VeracodePrimary
  2. GitHub - patrickmgarrity/Anthropic-Credited-CVEs: Tracking Vulnerabilities That Appear to be Credited to the Anthropic Research Team, GitHubPrimary
  3. Expanding the Cyber Verification Program, AnthropicPrimary
  4. Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws, The Hacker News
  5. Anthropic loosens Claude’s cyber restrictions for verified defenders, Help Net Security
How we checked this story
ClaimSourceStatus
Anthropic said its expanded Cyber Verification Program makes advanced cyber capabilities and reduced blocking classifiers available to qualifying security professionals.AnthropicConfirmed
Anthropic’s program has three access tiers, each including access to Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and future models.AnthropicConfirmed
Defense Access covers security operations, incident response, malware reverse engineering, and vulnerability analysis and validation.AnthropicConfirmed
Red Team Access adds authorized penetration testing and red-teaming to defensive uses.AnthropicConfirmed
Specialized Access has the fewest cyber blocks and is reserved for verified organizations authorized to test high-impact safety systems.AnthropicConfirmed
Anthropic requires data retention for organizations enrolled in the program to monitor for cyber misuse.AnthropicConfirmed
Anthropic said Enterprise Frontier Safeguards will later let eligible organizations store data in cloud infrastructure they control.AnthropicConfirmed
Without CVP access, every CyScenarioBench task was blocked on the first prompt.AnthropicConfirmed
Defense Access blocked 46 of 50 CyScenarioBench trials, while four tasks succeeded.AnthropicConfirmed
Red Team Access had no blocks and Claude Opus 5.5 completed 34 of 50 CyScenarioBench tasks.AnthropicConfirmed
Project Glasswing partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026.AnthropicConfirmed
Anthropic found an additional 5,500 verified software vulnerabilities through open-source scanning between April and October 2026.AnthropicConfirmed
More than 33,000 of the verified vulnerabilities had been rated critical or high severity.AnthropicConfirmed
Anthropic said its vulnerability total is likely an undercount and expects the true impact to be at least five times higher.AnthropicConfirmed
Anthropic said organizations can apply to the Cyber Verification Program and that applicants must provide proof of required security controls.AnthropicConfirmed
The Cyber Verification Program is available on the Claude Platform, Google Cloud’s Vertex AI, and Microsoft Foundry.AnthropicConfirmed
Help Net Security reported that Anthropic expanded its Cyber Verification Program with three access tiers for security teams.Help Net SecurityAttributed
The Hacker News reported that Anthropic said it was expanding a program allowing vetted cybersecurity professionals to test advanced models with reduced safeguards and blocking classifiers.Anthropic, via The Hacker NewsAttributed
The Hacker News reported that Anthropic claimed Project Glasswing uncovered at least 129,000 verified software vulnerabilities between April and July 2026.The Hacker NewsAttributed
VulnCheck researcher Patrick Garrity reported that two of 300 vulnerabilities discovered by Anthropic or Project Glasswing had been exploited in the wild.Patrick Garrity, via The Hacker NewsAttributed
The Hacker News said the two vulnerabilities with active exploitation efforts were CVE-2026-26980 in Ghost CMS and CVE-2026-61500 in Rejetto HTTP File Server.The Hacker NewsAttributed
Veracode’s 2025 report tested more than 100 large language models across Java, Python, C#, and JavaScript.VeracodeConfirmed
Veracode reported that 45% of code samples failed security tests and introduced OWASP Top 10 vulnerabilities.VeracodeConfirmed
Patrick Garrity said a GitHub tracker lists 128 fixed Anthropic findings without CVEs and 243 findings withdrawn by Anthropic.Patrick Garrity, via GitHubAttributed
veracode.com published its report on Jul 30, 2025.veracode.comConfirmed
Anthropic published its report on Oct 6, 2026.AnthropicConfirmed

Could not verify

  • Whether the 129,000 reported vulnerabilities were independently validated is not established.
  • Whether the vulnerabilities discovered through Project Glasswing were exploited beyond the two reported cases is not established.
  • How many organizations or people have received CVP access is not established.
  • Whether CVP access caused any real-world security improvement is not established.
Explore with AI