Last seen September 4, 2026

Claude Security Vulnerability

Anthropic's Claude Opus 4.6 LLM has identified over 500 previously unknown, high-severity security vulnerabilities, including memory corruption and buffer overflow issues, in critical open-source libraries like Ghostscript, OpenSC, and CGIF. This demonstrates AI's emerging capability for sophisticated vulnerability discovery and code analysis, even for complex flaws requiring conceptual understanding of algorithms.

Technical Severity
Low severity
Lifecycle Status

STABLE

What Happened

Anthropic's Claude Opus 4.6 LLM has identified over 500 previously unknown, high-severity security vulnerabilities, including memory corruption and buffer overflow issues, in critical open-source libraries like Ghostscript, OpenSC, and CGIF. This demonstrates AI's emerging capability for sophisticated vulnerability discovery and code analysis, even for complex flaws requiring conceptual understanding of algorithms.

Why This Matters

Publisher reporting describes a concrete security event. BugSkan could not yet bind it to a CVE or affected version, so treat the source details as the current record.

Recommended Action

Confirm whether opus is present in your environment and review vendor guidance for this report. Apply available patches or mitigations if your deployment matches the described conditions.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

Sep 04, 2026 12:17

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: UNKNOWN

Primary entities:

Amazon AWSAnthropicGitHubGoogleMicrosoftOpenAI

Timeline

  • Incident first seen
    Feb 06, 2026 05:30

    BugSkan first recorded this incident.

  • Claude Opus 4.6 Finds 500+ High-Severity Flaws Across Major Open-Source Libraries - The Hacker News
    Feb 06, 2026 05:30

    thehackernews.com ยท Research

  • Anthropic published the prompt injection failure rates that enterprise security teams have been asking every vendor for - VentureBeat
    Feb 10, 2026 05:30

    venturebeat.com ยท Vulnerability

  • Anthropic Finds 22 Firefox Vulnerabilities Using Claude Opus 4.6 AI Model - The Hacker News
    Mar 07, 2026 05:30

    thehackernews.com ยท Vulnerability

  • Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis
    Sep 01, 2026 13:56

    thehackernews.com ยท News

  • GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests
    Sep 04, 2026 12:17

    thehackernews.com ยท Jailbreak

  • Latest observed development
    Sep 04, 2026 12:17

    Most recent source or update associated with this incident.

Sources

Claude Opus 4.6 Finds 500+ High-Severity Flaws Across Major Open-Source Libraries - The Hacker News

thehackernews.com ยท Feb 06, 2026 05:30

Anthropic's Claude Opus 4.6 LLM has identified over 500 previously unknown, high-severity security vulnerabilities, including memory corruption and buffer overflow issues, in critical open-source libraries like Ghostscript, OpenSC, and CGIF. This demonstrates AI's emerging capability for sophisticated vulnerability discovery and code analysis, even for complex flaws requiring conceptual understanding of algorithms.

Open publisher source
Anthropic published the prompt injection failure rates that enterprise security teams have been asking every vendor for - VentureBeat

venturebeat.com ยท Feb 10, 2026 05:30

Anthropic's Claude Opus 4.6 exhibits prompt injection success rates up to 78.6% in less constrained environments, quantitatively validating a previously theoretical risk for AI agents. This vulnerability was demonstrated by a PromptArmor attack on Claude Cowork, enabling data exfiltration of confidential files via hidden prompt injections bypassing sandbox restrictions and monitoring.

Open publisher source
Anthropic Finds 22 Firefox Vulnerabilities Using Claude Opus 4.6 AI Model - The Hacker News

thehackernews.com ยท Mar 07, 2026 05:30

Anthropic's Claude Opus 4.6 AI model discovered 22 new vulnerabilities in the Firefox browser, including high-severity issues like a use-after-free bug and a critical just-in-time miscompilation. The AI also demonstrated the concerning ability to develop crude exploits for identified flaws, specifically one for CVE-2026-2796 with a CVSS score of 9.8.

Open publisher source
Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis

thehackernews.com ยท Sep 01, 2026 13:56

Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that's been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligence (AI)-assisted analysis. The idea, ESET said in a series of posts on X, is to deliberately trip a large language model's (LLM) safety mechanisms and prevent its

Open publisher source
GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests

thehackernews.com ยท Sep 04, 2026 12:17

OpenAI on Thursday officially unveiled GPTโ€‘6 Astra, which it described as the "world's most intelligent and aligned model." The development comes days after the artificial intelligence (AI) company said the model had reached the "Critical" cybersecurity capability threshold under its Preparedness Framework. "Astra is state-of-the-art on computer use, browsing, software engineering,

Open publisher source

Other BugSkan incidents that share identifiers, products, or vendors with this report.

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

โ† Back to incident intelligence