Skip to content
GLM-5.3 Model Enhances Cyber Exploitation Risks

GLM-5.3 Model Enhances Cyber Exploitation Risks

First seen 29 Sep 2026, 20:17 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 21:05 UTC
  • •Z.ai's GLM-5.3 model has been released with minimal safeguards, increasing exploitation risks.
  • •NIST's CAISI assessment ranks GLM-5.3 as the most capable open-weight model to date.
  • •Attackers can bypass GLM-5.3's protections with alarming ease, raising concerns for defenders.

The release of Z.ai's GLM-5.3 AI model on August 14, 2026, has raised significant cybersecurity concerns due to its advanced capabilities for developing cyber exploits. NIST's CAISI assessment indicates that GLM-5.3 is the most cyber-capable open-weight model available, but it lacks effective safeguards, allowing attackers to bypass them easily. Simulated tests showed that attackers could circumvent GLM-5.3's protections between 64% and 100% of the time. This model can autonomously create exploits targeting known vulnerabilities, including those in widely used software like Google Chrome's V8 engine. The model's public availability increases the risk of malicious use, particularly as it lags U.S. frontier models by four months in cyber capabilities. The situation is compounded by the active exploitation of CVE-2026-11645, which was added to CISA's KEV list shortly after its publication. Overall, the combination of GLM-5.3's capabilities and the ongoing exploitation of vulnerabilities poses a serious threat to cybersecurity.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-08
CVE-2026-11645 published
A vulnerability affecting critical software was disclosed, leading to active exploitation.
NIST
2026-06-09
CVE-2026-11645 added to CISA KEV
CISA listed CVE-2026-11645 as actively exploited, prompting heightened awareness.
NIST
2026-08-14
GLM-5.3 model released
Z.ai launched the GLM-5.3 AI model, which can autonomously create cyber exploits.
Anthropic
2026-09-17
CAISI assessment published
NIST's CAISI released findings on GLM-5.3, highlighting its advanced cyber capabilities.
NIST

More articles in this cluster (5)

Following this threat?

Track CVE-2026-11645 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed