CWE-Bench
An external benchmark for evaluating whether coding agents can produce correct patches for real-world software vulnerabilities.
Data verified 27 confirmed releases in the last 30 daysSee the free Radar BriefBenchmark score on CWE-Bench — September 2, 2026
We mirror the published score view for CWE-Bench. Gemini 3.8 Flash Cyber leads the public snapshot at 47.2%. We do not use these results to rank models overall.
1 modelAgenticCurrentDisplay onlyUpdated September 2, 2026
Benchmark score table (1 model)
ScoreAbout CWE-Bench
Year
2026
Tasks
Real-world vulnerability patching tasks
Format
Pass@1
Difficulty
Automated vulnerability remediation
CWE-Bench evaluates automated vulnerability patching. BenchLM stores exact provider-reported pass@1 results as display-only cybersecurity evidence until a stable benchmark-owned result artifact is available for the exact model setup.
BenchLM freshness & provenance
Version
CWE-Bench 2026
Refresh cadence
Quarterly
Staleness state
Current
Question availability
Public benchmark set
BenchLM uses freshness metadata to decide whether a benchmark should still be treated as a strong differentiator, a benchmark to watch, or a display-only reference. For the full scoring policy, see the BenchLM methodology page.
FAQ
What does CWE-Bench measure?
An external benchmark for evaluating whether coding agents can produce correct patches for real-world software vulnerabilities.
Which model scores highest on CWE-Bench?
Gemini 3.8 Flash Cyber by Google currently leads with a score of 47.2% on CWE-Bench.
How many models are evaluated on CWE-Bench?
1 AI models have been evaluated on CWE-Bench on BenchLM.
Know when it’s worth switching models
The model to choose, the cheaper alternative, and the release we would wait on.
Read a sample issueJoin 2,000+ readers.
One email each week. Unsubscribe anytime.