Anthropic's Responsible Disclosure Policy: How Glasswing CVD Works in Practice

Retool's new app builder is where AI-generated code ships safely
Building apps with AI is easy. Getting them to production safely is another story.
Project Glasswing has coordinated 1,596 vulnerability disclosures across more than 200 organizations. If your software is in Glasswing's scope, a notification is a matter of when, not if. Understanding how Anthropic's coordinated vulnerability disclosure process works before you receive a notification is the difference between a structured, controlled response and a reactive scramble under deadline pressure.
Anthropic's CVD Policy Overview
Project Glasswing operates under a coordinated vulnerability disclosure model consistent with ISO/IEC 29147 and FIRST.org's CVD guidelines. The core principle is private notification first, public disclosure after remediation. Anthropic notifies affected vendors privately, provides technical details sufficient to reproduce and fix the vulnerability, and gives vendors a defined remediation window before any public disclosure. The model prioritizes giving defenders time to patch before attackers can exploit a published advisory.
Who Gets Notified and When
Notification goes to the security contact registered with CERT/CC, the vendor's published security advisory email (security@, psirt@, or equivalent), or the contact on file with the CVE program if the vendor is a CNA. For open source projects without a dedicated security contact, Glasswing may route through the project's primary maintainers or through a relevant CERT. Notification happens when Glasswing has sufficient confidence in a finding and has completed internal triage. The disclosure clock starts at the date of the initial notification, not at the date of vendor acknowledgment.
Briefings like this, every morning before 9am.
Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.
The Notification Timeline
The standard Glasswing disclosure timeline: Day 0 is initial private notification with technical details. Day 5 is the vendor acknowledgment deadline. Days 5 to 30 are the patch development window for straightforward fixes. Day 90 is the default public disclosure date if no extension has been granted. For critical vulnerabilities with active exploitation evidence, Glasswing may compress the timeline and coordinate with CISA on emergency notification. For complex vulnerabilities requiring multi-vendor coordination (such as protocol-level flaws affecting multiple implementations), the timeline is negotiated with all affected parties.
Vendor Obligations and Response Expectations
When you receive a Glasswing notification, your expected actions are: acknowledge receipt within five business days and assign a named security contact, provide a realistic patch timeline within 30 days of notification, communicate blockers or dependencies that affect the timeline early, test and validate the fix before the disclosure date, and prepare a public advisory or CVE annotation for coordinated release. You are not obligated to patch within any specific window below 90 days, but a vendor that has not responded is not eligible for timeline extensions.
CVE Assignment Process
Anthropic operates as a CVE Numbering Authority (CNA) for Project Glasswing discoveries. As a CNA, Anthropic can reserve CVE IDs directly from the CVE program's block allocation and assign them to confirmed vulnerabilities without waiting for MITRE review. This streamlines the process for straightforward cases. For vulnerabilities requiring multi-vendor coordination or cross-product scope (such as a flaw in a shared library used across dozens of products), Anthropic may work with CERT/CC or CISA as additional coordinating CNAs. CVE IDs are reserved at the time of vendor notification and published at the time of public disclosure.
What Happens If a Vendor Goes Dark
If a vendor does not respond to notification within the acknowledgment window, Glasswing sends a second notification and attempts contact through alternate channels (additional email contacts, CERT/CC coordination, LinkedIn or conference contacts for open source maintainers). If no response is received by day 45, the vulnerability proceeds to public disclosure at day 90 regardless of patch status. Glasswing will note in the public advisory that notification was delivered and unacknowledged. CISA may be involved in parallel for critical infrastructure vendors who are unresponsive.
The Role of CERT/CC and CISA
CERT/CC at Carnegie Mellon serves as a neutral coordinator for cases where direct vendor contact is not possible, where multiple vendors are affected, or where a vendor disputes Glasswing's findings. CISA serves a similar role for US critical infrastructure operators. For vulnerabilities affecting critical infrastructure sectors (energy, water, healthcare, financial services), Glasswing coordinates with CISA in parallel with vendor notification. CISA's involvement does not extend the disclosure deadline but can provide additional remediation support resources to affected organizations.
Past Glasswing Disclosures as Examples
CVE-2026-4747 in FreeBSD illustrates the standard timeline: private notification to the FreeBSD Security Team, acknowledgment within two business days, patch developed and integrated into a security advisory, coordinated public release at 90 days. CVE-2026-5194 in wolfSSL (CVSS 9.1) required additional coordination because the certificate validation flaw affected downstream products built on wolfSSL. The disclosure was extended to allow wolfSSL to notify major downstream integrators before the public advisory was published. Both cases resulted in a published CVE advisory, vendor patch notes, and a Glasswing technical writeup.
The Public Disclosure Format
At the time of coordinated public disclosure, Glasswing publishes a technical advisory that includes the CVE identifier, affected versions, vulnerability description, proof-of-concept (where appropriate), CVSS score and vector, remediation guidance, and a timeline of the disclosure process. The advisory is published on Anthropic's security portal and submitted to the NVD for inclusion in the CVE database. Vendors are encouraged to publish their own advisory in parallel and to reference the CVE identifier in patch notes.
Vendor Response Playbook and Escalation Guide
The complete vendor response playbook, including response templates for Glasswing notifications, internal escalation paths, legal and communications considerations for public disclosure, and the contact escalation guide for cases where Glasswing coordination stalls, is available in the Mythos Brief.
Subscribe to unlock Remediation & Mitigation steps
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
The bottom line
Receiving a Glasswing notification is increasingly likely for any organization maintaining widely deployed software. The organizations that handle it well are those that have already registered a security contact, documented an internal response process, and prepared for coordinated public disclosure before the notification arrives. For the complete vendor response playbook and contact escalation guide, access the Mythos Brief at decryptiondigest.com/mythos-brief.
Frequently asked questions
What do I do if I receive a notification from Anthropic about a vulnerability?
Respond to the notification within five business days to acknowledge receipt and assign a security contact. Failure to respond does not pause the disclosure clock. Provide a realistic patch timeline and communicate any dependencies or blockers early. Anthropic will work with you on timeline coordination for complex fixes, but the default disclosure deadline remains in place unless formally extended.
How long do vendors have to patch before Anthropic goes public?
The standard Glasswing disclosure window is 90 days from initial private notification. Extensions are available for vulnerabilities requiring significant remediation work, hardware fixes, or multi-party coordination. Vendors must request an extension before the deadline and provide a credible remediation timeline to receive one.
How does Anthropic assign CVE IDs?
Anthropic operates as a CVE Numbering Authority (CNA) for vulnerabilities discovered through Project Glasswing. This means Anthropic can reserve and assign CVE IDs directly without routing through MITRE. For vulnerabilities that span multiple vendors or require cross-organization coordination, Anthropic may work with CERT/CC or CISA as additional coordinating bodies.
What is the difference between Anthropic's disclosure and a bug bounty?
Project Glasswing is a proactive AI-driven vulnerability research program, not a bug bounty. Bug bounties pay external researchers to find bugs in your software. Glasswing discovers vulnerabilities autonomously using Claude Mythos, then notifies vendors through coordinated disclosure. There is no submission portal, and vendors do not pay Anthropic for notifications.
Can I request an extension to the disclosure deadline?
Yes. Extension requests must be submitted to the Glasswing security contact before the original deadline. Requests should include a specific extended timeline and the reason for the delay (patch complexity, supply chain dependency, hardware fix requirement, etc.). Extensions are evaluated case by case. A vendor that has not responded to the initial notification is not eligible for an automatic extension.
What happens if a vendor disputes Anthropic's vulnerability finding?
Vendors who believe a Glasswing finding is not a valid vulnerability should raise the dispute in writing to the Glasswing security contact with a technical explanation of why the reported behavior is intended or not exploitable. Anthropic will evaluate the dispute with internal review. If disagreement persists, CERT/CC or another neutral coordinating body can be engaged as a technical arbitrator. The disclosure deadline is not automatically paused during a dispute; vendors should raise disagreements early in the remediation window rather than near the deadline.
Sources & references
- Anthropic Project Glasswing
- FIRST.org: Guidelines for Coordinated Vulnerability Disclosure
- CERT/CC Vulnerability Disclosure Policy
- CISA Vulnerability Disclosure Policy
- CVE Program: CNA Rules
- ISO/IEC 29147: Vulnerability Disclosure Standard
Free resources
Critical CVE Reference Card 2025–2026
25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.
Ransomware Incident Response Playbook
Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.
Get threat intel before your inbox does.
50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.
Unsubscribe anytime. We never sell your data.

Founder & Cybersecurity Evangelist, Decryption Digest
Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.
Win a $2,495 Black Hat pass.
Full-access to Black Hat USA 2026 in Las Vegas. Subscribe free to enter.
