CyberSecurityBoardThreat Intel · CVEs · Products
Cyber News

OpenAI Unveils GPT-5.6-Cyber: Reduced Safeguards for Exploit Development and Vulnerability Research

August 11, 2026

OpenAI has launched GPT-5.6-Cyber, a specialized cybersecurity model designed for vulnerability research, penetration testing, and incident response. Built on the GPT-5.6 Sol foundation, this model is trained to improve performance on tasks such as finding zero-day vulnerabilities and developing exploit chains, while reducing refusals for higher-risk, dual-use cyber tasks.

The model is available through Daybreak Red, a new access tier that provides other firms with authorized vulnerability research, exploit validation, and security testing capabilities. OpenAI reports that GPT-5.6-Cyber completes 95.0% of advanced cybersecurity requests in internal evaluations, compared to just 1.5% for GPT-5.6 Sol and 2.0% for Daybreak Blue access. It also outperforms its predecessor, GPT-5.5-Cyber, which completed 57.3% of requests.

One notable discovery by the model is CVE-2026-15903, a high-severity out-of-bounds read and write vulnerability in the V8 JavaScript engine (CVSS score: 8.8) that could allow remote code execution via a crafted HTML page. This flaw was patched by Google in mid-July 2026. The model also flagged vulnerabilities in a mobile operating system, a popular database, and over 400 privilege escalation flaws in a kernel.

OpenAI has made GPT-5.6-Cyber available to trusted partners including Accenture, Akamai, Cisco, Cloudflare, CrowdStrike, Fortinet, IBM, Palo Alto Networks, PwC, and Sophos. The company emphasizes that while AI models are improving at finding vulnerabilities, they still require human expertise for effective patching. Research from 1Password shows that LLM-generated patches fully resolve vulnerabilities only 26.0% of the time, and can introduce new issues in 53.9% of cases.

Despite the risks, OpenAI believes democratizing access to frontier intelligence for defenders is crucial to accelerating cyber defense.

CVEs: CVE-2026-15903

Companies: OpenAI, Google, Accenture, Akamai, Cisco, Cloudflare, CrowdStrike, Fortinet, IBM, Palo Alto Networks, PwC, Sophos

Products: GPT-5.6-Cyber, GPT-5.6 Sol, GPT-5.5-Cyber, Daybreak Red, Daybreak Blue