Get a free audit

Field Notes / AI Security

GLM-5.3 Is Free to Download. An Exploit Chain for a Patched CVE Cost $20.40.

Anthropic’s Frontier Red Team put an open-weight Chinese model within 1.5 points of its own strongest exploit-development system. The number that should move your patch schedule is $20.40: the API bill for a working exploit chain against a hardened ARM64 target, after 20 minutes of human attention.

Author
Red Team Partners
Read
12 MIN READ
Filed
30 Sep 2026
A developer working alone with a downloaded model, the shape of an attacker who no longer needs a lab behind them.

01 What Anthropic measured, and against whom

Five months ago Anthropic announced Claude Mythos Preview and described it as the first model able to build sophisticated exploits from beginning to end without a human directing each step. The expectation they stated then was that the capability would spread. The GLM-5.3 evaluation is the company checking its own forecast, and finding it arrived early.

Two benchmarks carry the argument. Both compare GLM-5.3 against Anthropic’s own models and against the other open-weight systems an attacker could download today Anthropic 2026 .

Model ExploitBench (V8) Binary exploitation, full control-flow hijack
Claude Mythos Preview56 of 410 · 13.7%6%
GLM-5.3 (open weights)50 of 410 · 12.2%4%
Claude Opus 4.6~0%0%
GLM-5.2~0%0%
Kimi K3~0%0%
DeepSeek V4.1-Flash~0%0%

Read the bottom four rows before the top two. One generation ago, every openly available model sat at zero on both tests. GLM-5.3 did not narrow a gap. It crossed a line that nothing downloadable had crossed before, and it did so while its immediate predecessor was still on the wrong side of it.

Anthropic then took the capability off the benchmark and pointed it at real software. Over the course of one day, researchers used GLM-5.3 to find previously unknown vulnerabilities in the JavaScript engine of a popular web browser and chained them into a working exploit: a web page that reads arbitrary files off the computer of anyone who visits it.

02 $20.40, and what it does to your patch window

The zero-day work is the headline. The n-day result is the one that should reach your change-advisory board.

Anthropic used GLM-5.3-Flash, the cheaper model in the family, to build an exploit chain for CVE-2026-11645 against ARM64 targets with PAC hardening. Pointer authentication is a mitigation specifically designed to make this class of exploit difficult. The run took 20 minutes of human attention plus eight hours of machine work, and cost $20.40 at Zhipu’s published API prices Anthropic 2026 .

$20.40 API cost of a working exploit chain for CVE-2026-11645 on ARM64 with PAC hardening, using GLM-5.3-Flash
20 min of human attention required, alongside eight hours of machine work
1 day to find unknown vulnerabilities in a browser JavaScript engine and chain them into a working exploit

Nothing here requires an attacker with a research team. It requires a downloaded model, a cloud bill smaller than lunch, and the patience to leave a job running overnight.

03 The safety training comes off for about $1,200

GLM-5.3 ships with refusal behaviour. It declines a direct request to attack something. Anthropic tested how much that behaviour is worth, at 50 samples per condition, by measuring how often the model engaged with an order to carry out a malicious cyber attack Anthropic 2026 .

ConditionGLM-5.3 engagedClaude Opus 4.8 / Opus 5 / Mythos 5
Bare order, no framing0%0%
False cover story64%0%
Prefilled reasoning92%0%
Abliterated copy100%not possible

A cover story is a sentence. Prefilled reasoning is a formatting trick. Those two rows need no budget and no expertise, and between them they move the model from refusing everything to complying with nine requests in ten.

The last row needs a little money and no permission. Abliteration edits the weights to remove the refusal direction outright. Anthropic’s team had never done it before and spent roughly 2,200 GPU hours, about $4,400. They estimate an experienced team would need around 600 GPU hours, about $1,200, which is also what the Flash variant took them. Refusal rates on JailbreakBench and HarmBench fell from 95% to roughly 3%, and on StrongREJECT to roughly 12%.

The Claude column stays at zero for one structural reason. Those weights are not published, so the refusal behaviour is not something a downloader can edit. Safety training holds when the model is a service. It is a suggestion when the model is a file.

04 Four months is now your planning horizon

On 17 September 2026, twelve days before Anthropic published, the NIST Center for AI Standards and Innovation assessed GLM-5.3 as the most cyber-capable open-weight model released to date, and put it about four months behind the US frontier on an aggregate of CAISI’s cyber benchmarks CAISI, via Anthropic .

Four months is a useful number because it converts a vague worry into a schedule. Whatever the closed frontier demonstrates this quarter, plan for a downloadable version of it next quarter, in the hands of anyone, with the refusals removable for the price of a laptop. That is not a forecast about 2030. It is the observed lag, measured twice by two organisations that do not share an incentive to agree.

Anthropic’s recommendations run the other way: governments should safety-test capable models including whatever follows GLM-5.3, developers of open-weight models should safeguard them, and access to advanced models should widen for defenders. All three are sound. None of them are things you control, and none of them will land inside your next patch cycle.

05 What changes in your testing this quarter

Five things follow directly from the numbers above. Each one is something you can start this month, and none of them wait on a regulator.

Before the next patch cycle
  • Measure your actual time from vendor disclosure to deployed patch on internet-facing systems. If it is longer than a week, the $20.40 figure is aimed at you.
  • Treat n-days as live, not pending. The assumption that no exploit exists yet because none has been published is the assumption this research retires.
  • Test whether your detection recognises machine-paced activity. Eight hours of unattended work does not look like a person at a keyboard, and rules tuned to human rhythms miss it.
  • Inventory every AI system you expose to users or to untrusted input, then test it adversarially. Your own deployment is part of the attack surface the same research describes.
  • Ask your suppliers the patch-latency question you just asked yourselves. Their unpatched week is your unpatched week, and their answer belongs in the contract rather than in a questionnaire nobody reads.

References

Sources

  1. Anthropic Frontier Red Team. “GLM-5.3 and the spread of advanced cyber capabilities.” Andrew Fasano, Marius Fleischer, Cole McFaul, Robert Xiao, Tripp Gallagher. 29 September 2026. anthropic.com
  2. Anthropic. Frontier Red Team research index. anthropic.com
  3. NIST Center for AI Standards and Innovation (CAISI). Assessment of 17 September 2026, as reported by Anthropic: GLM-5.3 is the most cyber-capable open-weight model released to date and lags the US frontier by about four months. nist.gov
  4. Z.ai (Zhipu AI). The GLM model family, published as downloadable open weights. z.ai