Claude Code Security, an AI-powered vulnerability scanner
Written by Joseph Nordqvist/
2 min read
Anthropic announced Claude Code Security on February 20, 2026, a tool that scans codebases for security vulnerabilities and suggests patches for human review. The feature is available as a limited research preview for Enterprise and Team customers, with free expedited access for open-source maintainers. [1]
What It Is
Claude Code Security is built into Claude Code's web interface. It is designed to go beyond traditional static analysis, which relies on matching code against libraries of known vulnerability patterns.
Instead, Anthropic says the tool reasons about code contextually. It traces how data moves through an application, examines how components interact, and identifies vulnerabilities in areas like business logic and access control that rule-based scanners typically miss.
Each finding goes through a multi-stage verification process. The system re-examines its own results, attempts to disprove them, and filters out false positives before presenting them to an analyst. Findings include severity ratings and a confidence score.
No changes are applied automatically. Developers review findings and suggested patches in a dashboard and decide whether to approve them.
Why This Matters
Software vulnerabilities are a persistent problem. Security teams are routinely outnumbered by the volume of code they need to protect, and traditional scanning tools catch only a subset of issues, primarily those that match known patterns.
If AI models can reliably find the kinds of context-dependent vulnerabilities that currently require skilled human researchers, it could meaningfully shift the economics of software security. The risk, which Anthropic has itself stated, is that attackers gain access to the same capabilities.
Cybersecurity stocks fell on the news. CrowdStrike dropped as much as 6.5%, Cloudflare fell more than 6%, and SailPoint declined 6.8%.
Editorial Transparency
This article was produced with the assistance of AI tools as part of our editorial workflow. All analysis, conclusions, and editorial decisions were made by human editors. Read our Editorial Guidelines
References
- 1.
Making frontier cybersecurity capabilities available to defenders, Anthropic, February 20, 2026
Primary
Was this useful?
More in Industry
View all- OpenAI kills Sora as compute costs force a strategic retreatMarch 25, 2026
- Cursor publishes Composer 2 technical report, formally crediting Kimi K2.5 as base modelMarch 25, 2026
- Cursor's new coding model was built on top of Kimi K2.5, a Chinese open-source baseMarch 23, 2026
- Musk sets March 21 for Tesla's Terafab chip factoryMarch 16, 2026
Related stories
OpenAI shares Pentagon contract language
OpenAI published excerpts of its agreement with the Department of Defense on Saturday morning. The language is more detailed than expected, yet more ambiguous than it first appears.
February 28, 2026
Policy & EthicsOpenAI strikes Pentagon deal hours after Anthropic blacklisted — with seemingly the same terms Anthropic was punished for requesting
OpenAI CEO Sam Altman announced a deal to deploy AI on the Pentagon's classified network just hours after the administration blacklisted Anthropic for requesting the same restrictions OpenAI says it secured.
February 28, 2026
IndustryMeta signs $60 billion AMD chip deal, gaining a 10% stake in NVIDIA's biggest rival
Meta and AMD announced a five-year, approximately $60 billion agreement to deploy up to six gigawatts of AMD Instinct GPUs, with Meta gaining the option to acquire roughly 10% of AMD through performance-based warrants.
February 27, 2026
IndustryMeta signs multiyear deal for NVIDIA GPUs
Meta and NVIDIA announced a multiyear strategic partnership deploying millions of Blackwell and Rubin GPUs, standalone Grace CPUs, and Spectrum-X networking across Meta's hyperscale data centers.
February 18, 2026