Palo Alto finds 75 flaws with frontier AI

Palo Alto Networks says it used Anthropic’s Claude Mythos, Claude Opus 4.7 and OpenAI’s GPT-5.5-Cyber against its own codebase for a month starting April 7. The result was 26 CVEs covering 75 concrete vulnerabilities across more than 130 products, roughly seven times its usual monthly CVE volume.

The notable part is that this was a defensive use of frontier cyber models. Palo Alto accessed the systems through Anthropic’s Project Glasswing and OpenAI’s Trusted Access for Cyber, then embedded them in an internal scanning harness rather than simply asking a chatbot to review code.

The models wrote working exploits

CPO Lee Klarich said the models were far better at writing working exploits than earlier systems, with internal tests showing exploit success rates above 70%. But he also stressed that the models were not magic: Palo Alto spent substantial engineering time building the harness that connected model output to its security workflow.

All 26 CVEs were patched before public disclosure, and the advisory said none were exploited in the wild. The bigger warning is timing. Palo Alto estimates attackers may gain comparable frontier-model capability in three to five months, so defenders have a short window to scan code, reduce exposed attack surface and automate detection and response.

Sources: CocoLoop, CNBC, Axios, Palo Alto Networks Blog; checked model names, CVE count, 75 flaws, exploit rate, patch status and three-to-five-month warning.