ExploitGym: leaderboard
Real-world cybersecurity agent benchmark measuring whether AI agents can turn known software vulnerabilities into working, intended exploits across userspace, V8, and Linux kernel targets.
Metric: Successful Intended Exploits (#). Source: www.cybergym.io. Status: years away from saturation. 14 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | GPT-5.6 Sol | 293 |
| 2 | Claude Mythos 5 | 247 |
| 3 | Claude Opus 5 | 191 |
| 4 | GLM-5.3 | 130 |
| 5 | GPT-5.5 | 129 |
| 6 | Claude Opus 4.8 | 120 |
| 7 | GLM-5.2 | 79 |
| 8 | GPT-5.4 | 61 |
| 9 | Gemini 3.1 Pro (Preview) | 12 |
| 10 | Claude Opus 4.7 | 12 |
| 11 | Muse Spark 1.1 | 7 |
| 12 | GLM-5.1 | 4 |
Interactive version: theaggregate.ai/benchmark?slug=exploitgym · How It Works · Data refreshed daily, snapshot 2026-09-05.