An AI model just found a serious security flaw in the software that developers use to write AI-assisted code.

Z.ai released GLM-5.3 on August 14, 2026, and the model’s headline moment came quickly: it identified a significant vulnerability in Cursor, the AI-powered code editor. The discovery was flagged by security researcher Joshua Saxe.

The benchmark numbers tell a story

On the CyberGym vulnerability discovery benchmark, the model scored 84.5%, edging out Mythos 5 at 83.8% and GPT-5.6 Sol at 83.6%.

The ExploitBench results are where things get genuinely striking. GLM-5.3 scored 54.4% on that benchmark, which measures a model’s ability to reason through and execute exploits. Its predecessor, GLM-5.2, scored roughly half that.