# Claude Mythos Turns N-Day Vulnerabilities Into Weaponized Exploits in Hours—Compressing the Patch Gap Crisis


AI's latest frontier model can create working exploits for known vulnerabilities faster than most organizations patch. Anthropic's testing reveals a fundamental shift in attacker economics that leaves defenders dangerously exposed.


On June 9, 2026, Anthropic disclosed what may be the most consequential demonstration of AI's role in cybersecurity yet: Claude Mythos Preview can weaponize known vulnerabilities into working exploits in hours, not days or weeks. The company's testing—conducted on Firefox, Windows kernel vulnerabilities, and closed-source software—reveals that the traditional notion of a "patch window" is rapidly collapsing under the acceleration of AI-powered exploit development.


The implications are stark. If AI systems can produce production-ready exploits in 12 hours, and Microsoft Windows patches take an average of 11 days to deploy across 90% of enrolled devices, the window for defenders to react has essentially vanished.


## The Threat: AI as an Exploit Factory


Anthropic tested three models—Claude Mythos Preview, Claude Opus 4.8, and Claude Sonnet 4.6—against a total of 39 disclosed security vulnerabilities spanning Firefox's JavaScript engine (SpiderMonkey) and Microsoft Windows kernel code. The results were sobering:


| Test Category | Mythos Preview | Opus 4.8 | Opus 4.7 | Sonnet 4.6 |

|---|---|---|---|---|

| Firefox PoCs created | 14 of 18 | 11 of 18 | N/A | N/A |

| Firefox working exploits | 8 (in ~12 hours) | 2 | N/A | 1 |

| Windows PoCs created | 18 of 21 | 15 of 21 | 13 of 21 | 13 of 21 |

| Windows working exploits | 8 (in ~18 hours) | 0 | 0 | 0 |


Key timeline findings:

  • First Firefox PoC: 8-12 minutes
  • First working Firefox exploit: ~60 minutes (Mythos)
  • First Windows PoC: 31 minutes (Mythos)
  • Complete Windows exploit suite: ~18 hours (Mythos)

  • The velocity is unprecedented. Mythos Preview built its first working Windows kernel exploit—a privilege escalation vulnerability—in under 18 hours, using only compiled binaries and decompiler output without access to source code. This is substantially harder than exploitation with source code, yet the model succeeded where humans would typically require days of reverse engineering and vulnerability analysis.


    ## Background and Context: The N-Day Crisis


    To understand why this matters, it's essential to distinguish between zero-days and N-days:


  • Zero-days: Vulnerabilities unknown to vendors; exploited in the wild before disclosure and patching
  • N-days: Already disclosed vulnerabilities with public patches available, but still vulnerable in unpatched systems

  • Historically, N-days were considered less dangerous than zero-days because defenders had theoretical advance warning. In practice, the months-long patch deployment timeline meant N-days often remained exploitable for weeks or months after disclosure. Attackers would reverse-engineer patches to extract vulnerability details, then build exploits during what Anthropic calls the "patch gap."


    The patch gap is a well-documented problem:

  • Windows critical patches take 7 days to reach 90% of enrolled systems
  • Force reboot policies typically occur on day 11
  • Enterprise environments with custom deployments take 30-60 days to fully patch
  • Legacy systems never fully patch

  • Exploit development has historically been the bottleneck limiting N-day attack speeds. Reverse engineering a patched binary, understanding the vulnerability, and writing functional exploit code requires scarce expertise and significant manual labor. This scarcity limited attack velocity—not because patches were unavailable, but because weaponizing them took time.


    AI fundamentally eliminates that constraint.


    ## Technical Details: How Claude Models Built the Exploits


    Anthropic's testing used two distinct approaches:


    ### Firefox Vulnerability Testing

    The company provided Claude with public patch diffs from Firefox 148 and 149—the exact changes Mozilla made to fix 18 SpiderMonkey vulnerabilities. The model's task: reverse the patch to understand the original bug, then write a proof-of-concept that triggers the vulnerability.


  • Mythos Preview created 14 functional PoCs in minutes, and 8 complete working exploits within 12 hours
  • Opus 4.8 created 11 PoCs, with 2 converted to working exploits
  • Timeline to first exploit: ~60 minutes for Mythos

  • ### Windows Kernel Testing

    This was substantially harder. Anthropic selected 21 Windows kernel vulnerabilities patched between January and February 2026 and provided Claude with:

  • Decompiled code (not source)
  • Stripped symbols (variable names, types, and structure removed)
  • No patch diffs (closed-source binary only)

  • Mythos Preview successfully created:

  • 18 crash PoCs (triggering blue screens of death) from 21 test vulnerabilities
  • 8 working privilege escalation exploits within 18 hours
  • First functional exploit in under 18 hours

  • The working exploits weren't theoretical—they delivered code execution and privilege escalation on Windows systems. This was not brute-force fuzzing; Claude was performing actual reverse engineering, understanding kernel data structures, and crafting functional exploit code.


    ## Implications: The Collapse of the Patch Window


    Under traditional timelines, a vulnerability disclosed on Friday might be exploited in the wild by the following Wednesday or Thursday—a 4-7 day window. Organizations with rapid patching could theoretically close the gap before widespread exploitation.


    Claude Mythos Preview collapses that window to hours.


    The math is now against defenders:

  • Vulnerability disclosed → public patch available
  • Security researcher feeds patch to Claude Mythos
  • Working exploit created within 12-18 hours
  • Organizations still at 7+ days into their patch deployment cycle
  • Attackers can now exploit the gap with high-fidelity, reliable exploits

  • This is particularly dangerous because:


    1. Exploit commodification: Exploit development is no longer a scarce skill. Any attacker with API access can instantly weaponize disclosed vulnerabilities.


    2. Scaling attacks: Where a typical threat actor could create 2-3 exploits per month due to engineering constraints, Claude enables creation of dozens per day.


    3. Privilege escalation automation: Building reliable privilege escalation exploits typically requires deep kernel knowledge. Claude achieved this with decompiled binaries—a task previously reserved for advanced threat actors.


    4. Supply chain implications: Third-party library vulnerabilities disclosed to the public now have weaponized exploits within hours, exposing downstream users immediately.


    ## HackWire Analysis: When the Patch Gap Becomes a Patch Chasm


    This is not a story about AI capabilities in the abstract. It's about the fundamental economic shift in how attacks work.


    For thirty years, exploit development was a bottleneck that slowed attackers. Organizations invested in fast patching, assuming they'd get a week or two to respond before widespread exploitation. That assumption is now obsolete.


    What Anthropic has demonstrated is the democratization of a previously scarce skill. When reverse engineering and exploit development could be automated by a capable AI model, suddenly attackers don't need elite knowledge—they need API access. The economics have flipped entirely in the attacker's favor.


    The most consequential detail Anthropic buried in their report: Claude models with safeguards disabled can perform these exploits. This isn't speculative—it's confirmed. Any organization or attacker with sufficient resources can replicate these results today. The capability exists now. It's deployed.


    The second detail: Windows kernel exploitation is *harder* than user-mode exploitation, yet Claude succeeded. This proves that no software category—not kernel code, not closed-source systems, not stripped binaries—is immune to this acceleration.


    For defenders, this means three immediate actions:


    1. Assume the patch window is now 24 hours, not 7 days. Organizations need to restructure patching workflows to treat critical disclosures as emergency events requiring deployment within one business day, not one week.


    2. Prioritize compensating controls for unpatched systems. If patching can't be instant, network segmentation, EDR capabilities, and behavioral detection become the actual perimeter.


    3. Audit your N-day exposure now. Run vulnerability scans against production. Every disclosed CVE without a patch is now a weaponized threat, not a theoretical one.


    The patch gap didn't close—it became a chasm. And Claude Mythos just handed attackers a bridge.


    — HackWire Editorial


    ## Recommendations for Organizations


    Given the accelerated threat timeline, defenders should implement:


  • Zero-trust network architecture: Assume internal systems can be compromised; enforce authentication and authorization for every resource
  • Emergency patching playbooks: Establish procedures to deploy critical patches within 24 hours, not 7 days
  • Enhanced EDR/XDR deployment: Deploy endpoint and extended detection and response across all systems to catch exploitation attempts in real-time
  • Vulnerability prioritization: Focus patching efforts on internet-facing systems and software with public exploits first
  • Supply chain audits: Verify third-party dependencies for unpatched N-day vulnerabilities weekly, not monthly
  • Threat modeling updates: Assume all disclosed CVEs are weaponized threats, not potential risks

  • Organizations should also review their incident response plans to account for much faster exploitation timelines and ensure detection capabilities can identify compromise within hours of exploit deployment.


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)