Anthropic Debuts Claude Code Security – AI Now Scan Vulnerabilities in Your Entire Codebase
On Tue, Feb 20, 2026, Anthropic introduced Claude Code Security , a new feature integrated into Claude Code. This capability enables the automatic scanning of entire repositories for vulnerabilities and provides patch suggestions for review.
On Tue, Feb 20, 2026, Anthropic introduced Claude Code Security , a new feature integrated into Claude Code. This capability enables the automatic scanning of entire repositories for vulnerabilities and provides patch suggestions for review.
Unlike traditional static application security testing (SAST) tools, Claude Code Security utilizes advanced reasoning through Claude Opus 4.6. It analyzes data flows and architectural contexts to identify issues that may not be visible with conventional methods.
The system operates by mapping data movement across modules and simulating attack paths. It identifies business logic flaws, authentication bypasses, complex injection vectors, and memory-safety issues, which are often undetected by traditional scanners.
Potential issues undergo a multi-stage self-assessment to reduce false positives. Validated vulnerabilities are presented in a dashboard with explanations, reproduction steps, severity ratings, and suggested patches.
Fixes require human approval to maintain a "human in the loop" safeguard. Internal testing revealed over 500 previously unknown high-severity vulnerabilities in popular open-source projects. Disclosure to maintainers is in progress.
On Tue, Feb 20, 2026, Anthropic introduced Claude Code Security , a new feature integrated into Claude Code.
According to Anthropic, Claude Code Security aims to provide advanced defensive capabilities for broader use. This integration allows teams to review findings and implement fixes within their existing tools.
The introduction of Claude Code Security affected the stock market, with shares of established cybersecurity firms experiencing a decline:
CrowdStrike (CRWD) — down approximately 8% Cloudflare (NET) — down approximately 8.1% Okta (OKTA) — down approximately 9.2% Palo Alto Networks, Zscaler, and smaller SAST vendors faced similar declines.
The Global X Cybersecurity ETF decreased by nearly 5%. Analysts noted this development as a significant deployment of autonomous vulnerability research, impacting traditional tools financially.
Availability: The feature is available in a limited research preview for Enterprise and Team plan customers. Open-source maintainers can request access via Anthropic’s security contact form. Feedback from this preview will inform a broader rollout later in 2026.
Anthropic emphasizes that this tool will enhance code scanning capabilities, providing defenders with advanced resources before potential misuse by attackers.
Based on reporting by GBHackers.
