Anthropic's Open-Source Disclosure Ledger Shows Where Remediation Slows Down
Anthropic's dashboard now reports 6,157 disclosed open-source vulnerabilities against 516 patches released upstream. The funnel behind those two numbers, and the pacing policy the vendor app
TL;DR
- Anthropic's Frontier Red Team dashboard, last updated on 2 October 2026, reports 6,157 vulnerabilities disclosed across 591 open-source projects, of which 516 are known to have been patched upstream and 5,103 were acknowledged by maintainers.
- The funnel above those numbers is the interesting part. Between 1 November 2025 and 2 October 2026 the programme logged 29,439 discovered findings, routed 6,123 candidates through human triage, had external security research firms confirm 92.7% of them as true positives, and reported 4,824 findings directly to maintainers.
- Anthropic's own policy explains the shape of the curve: a 90-day disclosure deadline with a 14-day extension on request, a compressed 7-day target for actively exploited bugs, a 45-day wait after a patch before technical detail is published, and an explicit commitment to pace submissions to what maintainers can absorb.
- The operational reading is that automated discovery moves the constraint downstream. Patch rate, not finding rate, is the number a team can act on, and it is bounded by the capacity of the projects receiving the reports.
- The method behind those counts matters as much as the totals: the dashboard publishes details only for findings whose disclosure window has closed, keeps hash commitments for the rest, and splits its 584 issued identifiers into 219 CVEs and 365 security advisories.

What the ledger counts, and how it counts it
The dashboard is explicit about its own scope, which is rare enough to be worth quoting. The programme began in February 2026 with an early snapshot of Claude Mythos Preview, uses external firms to reproduce and assess findings, and publishes details only once a finding's disclosure window has closed. Findings still inside the window appear as commitment hashes, so their existence and date are provable while their content stays withheld.
The headline count is a disclosure count and the phrasing around it is careful: as of 2 October 2026 the programme has disclosed 6,157 vulnerabilities across 591 open-source projects, and states that, to its knowledge, 516 of them have been patched. Identifier coverage is 584 records, split between 219 CVEs and 365 GitHub Security Advisories, with the note that a single finding can carry both and that maintainers sometimes ship a fix without publishing an advisory at all.
Six outside firms sit between a finding and a report
The dashboard separates discovery from disclosure, and the separation is the story. Of 29,439 findings discovered in the reporting window, 6,123 became candidates for human triage. External security research firms reviewed 5,674 of those and confirmed 92.7% of the 6,123 as true positives. A further 4,824 findings travelled directly to maintainers without the independent check, at the request of the maintainers themselves.
Anthropic is unusually candid that the true-positive rate is a weak metric. The About page states the number includes real bugs that were already reported elsewhere and real bugs a maintainer decided not to fix, and it warns that a vendor can miscategorise a finding in either direction. The page then names the number it trusts more, and the caveat attached to it: the count of patches created is "a more reliable one", though "patches take a long time to create". The dashboard also concedes that findings confirmed as real have not all been sent yet: some remain unreported "due to capacity limitations" inside the programme itself.

The gap between acknowledged and patched
Read the three numbers in sequence: 6,157 reported, 5,103 acknowledged, 516 patched. Maintainers answer. They release fixes more slowly. That is 8.4% of the disclosed set with a patch published upstream, four months into a programme that started in February 2026, and the dashboard adds the qualifier that a released patch "does not guarantee that those patches have been widely installed."
None of this is evidence of bad faith on anyone's part, and the timeline matters. Disclosure volume at this scale is new; project maintainers are largely volunteers or small teams, and a triaged report still has to be understood, reproduced, fixed, tested and released. Anthropic's policy anticipates exactly that pressure when it commits to "pace our submissions to what maintainers can actually absorb" and states that it does not push large volumes of findings at a single project without agreeing a sustainable pace first.
Where the timelines compress and where they relax
The policy document is a useful read for anyone who has to run disclosure on the receiving side. Standard reports follow a 90-day deadline, with a 14-day extension available when a maintainer is engaged and making progress. Actively exploited critical vulnerabilities get a 7-day target for a patch or mitigation, extendable by another seven days at the maintainer's request. Once a patch exists, full technical detail waits 45 days to give downstream users time to deploy.
Two details show where the leverage sits. Where Anthropic and a maintainer disagree on severity, the vendor generally defers to the maintainer's assessment, with active exploitation as the stated exception. And silence for 30 days escalates a finding to an external coordinator, with public disclosure following at the end of the applicable timeline. The pace of the programme is therefore set in three places: the model that finds bugs, the external firms that triage them, and the maintainers who fix them.

What a remediation queue looks like on a small team
Take a concrete case, marked clearly as a hypothetical. A 25-person software company turns on an AI-assisted review loop over its own repository and gets 40 findings in the first month: 12 high, the rest medium and low. Nobody in the company disagrees with the findings. The queue still takes eleven weeks to clear at one fix per two days, because the two engineers who can act on it are also shipping the roadmap.
That is the same arithmetic as the dashboard, at a scale where it stops being interesting and starts being a hiring decision. The failure mode is not a missed critical bug; it is a queue that fills faster than it drains, with priorities set by whoever shouted last. The remedy is unglamorous and mechanical: a single list, a severity ordering agreed in advance, and a written rule for closing a finding as accepted risk so the count means something.
Measuring your own patch throughput
Two numbers are enough to run the loop honestly. Findings closed per week tells you whether the queue grows or shrinks. The age of the oldest open finding tells you whether the backlog is being managed or merely re-sorted. Add a third if you have the discipline: the share of closed findings that were closed as accepted risk, which is where most teams quietly hide the difference between triage and repair.
A security audit and hardening engagement starts by putting those numbers on the table for the systems you actually run, because the alternative is a vulnerability list that grows every quarter and a fix rate nobody tracks. Anthropic's ledger is worth reading for the same reason: it is a rare case of a vendor publishing both ends of the pipeline, the discoveries and the patches, and letting the distance between them be measured.

Sources
Source: Anthropic's coordinated vulnerability disclosure dashboard — red.anthropic.com/2026/cvd, last updated 2026-10-02 (6,157 vulnerabilities disclosed across 591 open-source projects, 516 patched, 584 identifiers issued, the 29,439 / 6,123 / 5,674 funnel and the 92.7% true-positive rate; all figures read on 2026-10-04). Source: Coordinated vulnerability disclosure for Claude-discovered vulnerabilities — anthropic.com/coordinated-vulnerability-disclosure, last updated 2026-03-06 (90-day deadline, 14-day extension, 7-day target for actively exploited vulnerabilities, 45-day wait before technical detail, 30-day escalation and the pacing commitment). Source: About this dashboard — red.anthropic.com/2026/cvd/about (programme description, external security research firm partners, glossary of acknowledged and patched findings). Internal linkage: Disclosure Doubled and Exploitation Followed. More security engineering analysis on neticslabs.com.
Source: Anthropic's coordinated vulnerability disclosure dashboard — red.anthropic.com, 2026-10-02; Coordinated vulnerability disclosure policy — anthropic.com, 2026-03-06. Captures: official Anthropic dashboard and About pages, retrieved 2026-10-04.