Z.ai released GLM-5.3 on August 14, 2026, a 743-billion-parameter model built on GLM-5.2's base with all gains from post-training alone. The model delivers 66.9% on DeepSWE coding (+20 points from predecessor) and a headline 84.5% on CyberGym vulnerability discovery, slightly edging Anthropic's Mythos 5 (83.8%) and OpenAI's GPT-5.6 Sol (83.6%), per multiple sources.
Notably, Z.ai delayed open-weight release, departing from GLM-5.2's fast rollout pattern. The model found 2,436 vulnerabilities across 269 open-source projects— 1,097 rated critical or high severity— surfaced through coordinated disclosure. Z.ai attributes the surge to emergent exploit-chain reasoning the company says it did not explicitly train for, citing the need for safety evaluation before public weights.
The move carries policy significance: it is the first time a Chinese frontier lab cited emergent capability concerns (rather than export rules or platform policy) for withholding weights. For architects evaluating open models, GLM-5.3 marks the inflection where vulnerability discovery (defensive) scales faster than open-source deployment guardrails. The two-week hold and future weight release, expected end-August, will be when independent verification begins on the company's benchmark claims.