Approximately 1,596 vulnerabilities had been disclosed to open-source maintainers as of May 2026 under the programme filed at 26-0404. Around 97 had been patched, with 65 published security advisories. That is a remediation rate of roughly six per cent.
The finding that matters here is not about any project’s diligence. It is that discovery scaled and remediation did not, and the two are performed by entirely different parties.
The Asymmetry Is Structural
Discovery is now a capital expenditure. An organisation with compute and a model can generate findings continuously, and the cost per finding falls as the process improves.
Remediation is a human activity performed largely by volunteers. Someone must read the report, reproduce it, understand the surrounding code, design a fix that does not break dependents, test it, release it, and handle the fallout. None of that scales with compute.
The Recipients Did Not Agree To This Workload
A maintainer of a widely used library is frequently one person doing unpaid work in their own time. A report arriving from a well-resourced coalition is not a collaboration between equals; it is an obligation transferred from an organisation with a security budget to an individual without one.
The libraries named in this programme — FFmpeg, the Linux kernel — sit under almost everything, which is precisely why they were chosen and precisely why their maintainers are already the most heavily loaded people in the ecosystem.
What A Six Per Cent Rate Means For Defenders
Practically: roughly fifteen hundred known, disclosed, unfixed vulnerabilities in software that is deployed nearly everywhere, with no patch to apply.
For an organisation, that is not a patching problem. It is the argument this desk made at 26-0506 arriving from a different direction — the controls that matter are the ones that work while the defect is still present, because for most of these there will be no fix in any useful timeframe.
Compiled from published coalition material and independent analysis, listed below. Figures are as reported by the disclosing organisation, which has a commercial interest in the discovery capability; the patching figures are correspondingly the more conservative of the two claims it makes. Corrections: corrections@forensicpost.com.
- Project Glasswing and the AI vulnerability disclosure velocity crisisCloud Security Alliance
- Project Glasswing proved AI can find the bugs. Who’s going to fix them?The Hacker News
- Project Glasswing: an initial updateAnthropic