Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes—Anthropic reports that GLM-5.3 built working exploits in controlled tests. It succeeded in 50 of 410 ExploitBench attempts, compared with 56 of 410 for Anthropic’s Claude Mythos Preview. The results show a demonstrated capability under evaluation conditions, not evidence that GLM-5.3 has been used in a real-world attack.

What Anthropic tested—and what it found

In a report published September 29, 2026, Anthropic evaluated GLM-5.3, a model developed by Zhipu AI, also known outside China as Z.ai. On Anthropic’s ExploitBench evaluation—focused on exploiting known vulnerabilities in Chrome’s V8 engine—GLM-5.3 produced end-to-end exploits in 50 of 410 attempts. Claude Mythos Preview did so in 56 of 410 attempts. Anthropic’s report says the models ran in isolated, sandboxed environments.

That 50-of-410 result is an attempt count from Anthropic’s evaluation. It is not a claim that the model succeeded on 50 of 410 unique vulnerabilities, nor should it be read as a general success rate for all exploit development.

A different Anthropic benchmark measured a different outcome

On a separate internal binary-exploitation benchmark, Anthropic reported full control-flow hijacks in 4% of GLM-5.3 trials and 6% of Claude Mythos Preview trials. Those percentages use a different task and outcome from ExploitBench, so they should not be combined with the 50-of-410 counts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Anthropic’s controlled exploit demonstrations

Anthropic also described researcher-led demonstrations beyond its benchmark totals. In one sandboxed Linux browser session, GLM-5.3 found and chained previously unknown vulnerabilities into a browser exploit that could read arbitrary files. Anthropic said it disclosed the vulnerabilities it described to the maintainer; the report did not establish their later patch or disclosure status. The demonstration targeted the Linux browser build in Anthropic’s sandbox. The company said the issues might affect other platforms, where exploitation could be more complex.

In a separate session, GLM-5.3-Flash worked on a known Chrome flaw and another known flaw, eventually producing an ARM64 exploit chain. Anthropic reported eight hours of model work and 20 minutes of human attention; it estimated the run would have cost $20.40 at Zhipu API prices. These are details of Anthropic’s controlled demonstrations, not evidence of an attack against a live victim.

How NIST CAISI’s results compare

The U.S. National Institute of Standards and Technology’s Center for AI Standards and Innovation (CAISI) published a separate assessment on September 17, 2026. CAISI described GLM-5.3 as “the most cyber-capable open-weight model released to date” among the models it had evaluated. It also estimated that GLM-5.3 trailed the U.S. frontier by about four months on its aggregate cyber-capability measure. That is a dated comparison of evaluated models—not a claim that GLM-5.3 is the most capable model overall, or that every cyber task has a four-month gap. CAISI’s assessment notes that its comparison reflects models released and evaluated at the time, and excludes unreleased systems that might be more capable.

CAISI’s benchmark results use its own tasks, denominators, and scoring methods. Its ExploitBench figure, for example, is based on the best of three attempts per task, unlike Anthropic’s 50 successful attempts out of 410 in its evaluation.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
CAISI evaluation GLM-5.3 result How to interpret it
SEC-Bench Pro 40.4% (74/183) CAISI’s reported result for this benchmark family.
ExploitBench 61.1% (9.8/16) CAISI’s score; it reflects the best of three attempts per task, not Anthropic’s 50-of-410 attempt count.
ExploitGym (Userspace) 9.4% (47/498) CAISI’s reported result for the Userspace tasks.
CAISI OSS-Fuzz 7.7% (23/297) CAISI’s reported result for this benchmark family.

CAISI says its aggregate cyber capability index uses item-response theory; a 400-point increase corresponds to a tenfold increase in statistical odds of solving tasks on its evaluations. Its four-month estimate comes from that aggregate measure, not a literal model release schedule. CAISI’s comparison includes both trusted-access and publicly released U.S. models; it tested U.S. models with cyber safeguards disabled when applicable.

What the safeguard tests do—and do not—show

Anthropic reported that GLM-5.3 refused every request in its direct malicious-request condition. In simulated malicious-request tests, however, it engaged with 64% of trials when given a deceptive red-team cover story and 92% when given prefilled reasoning. An abliterated copy—a modified version intended to remove refusals—engaged in 100% of those simulated trials.

These figures describe Anthropic’s simulations, not real-world attack rates. The test environment did not execute generated code or connect to external systems; a separate language model approximated command results. Anthropic cautioned that its simulations are imperfect portrayals of real-world conditions.

In a separate test using three harmful-request benchmarks, Anthropic found that abliteration reduced refusal rates while leaving measured general-science capability unchanged and tested CyberGym capability only a few percentage points lower. That is a result for Anthropic’s evaluation of its modified model, not a guarantee about every altered copy or deployment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why the open weights matter

NIST says Z.ai released GLM-5.3 on August 14, 2026, and publicly released its weights two weeks later. Open weights allow users to run and modify the model; Anthropic says this can include modifying it to remove refusals. The safeguard results therefore should not be assumed to describe every GLM-5.3 deployment: users may encounter different access arrangements and modified versions.

What readers can conclude

  • Anthropic demonstrated that GLM-5.3 could produce working exploits in benchmark attempts and controlled sandbox sessions.
  • CAISI’s independent assessment also found strong cyber capability for an open-weight model, while placing it behind the U.S. frontier on CAISI’s aggregate measure at that time.
  • The benchmark numbers are not directly interchangeable: the organizations used different evaluations, denominators, and scoring approaches.
  • Neither the benchmark results nor the sandbox demonstrations establish that GLM-5.3 was used in a real-world attack.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.