It's time to turn from CVSS-backed patching to choke-point patching focused on breaking chains to critical assets.

August 10, 2026

On April 7, 2026, Anthropic announced Project Glasswing, which changed how every security team operates. Claude Mythos, an AI-frontier model that found thousands of high-severity vulnerabilities, including flaws in major operating systems and Web browsers, many of which survived for decades of human review and automated security tests. Of which, less than 1% was fully patched. This is a patch physics problem rather than a patch management problem. You cannot match machine-speed discovery with a remediation cycle that runs on human time.

Before Mythos, in 2025, 46,407 CVEs were published, up from 40,009 in 2024, a 16% year-over-year increase. The National Institute of Standards and Technology enriched nearly 42,000 CVEs in 2025, 45% more than any prior year but still couldn't keep pace with the growing volume of submissions.

Now, imagine Mythos vulnerability discovery on top of this baseline; the vulnerabilities identified will flow downstream to every enterprise. When a critical zero-day is found in a kernel or widely used open source library, CVEs get published, scanner signatures get updated, and suddenly every organization running that software has a new critical finding to address.