Overview
Gemini 3.8 Flash Cyber is the security model Google released on 2 September 2026 alongside Gemini 3.8 Flash. Google calls it "our most capable cybersecurity model, with frontier-level performance in vulnerability detection and automated patching", and it shares the same foundational intelligence as the mainline 3.8 Flash model rather than being a separate pretraining run.
It is not generally available. Access runs through the Fairwind Program, a vetted-access programme Google DeepMind launched with this model to give high-priority defenders early access before new threats arrive. Google prioritises governments and national cyber authorities, critical infrastructure operators in healthcare, telecommunications, energy and financial services, and maintainers of core technology platforms; applicants are vetted for a proven track record of ethical operations and research. Participants can use the model on its own or combined with CodeMender, Google's code-security agent for automating vulnerability fixes.
On the results Google published at launch, 3.8 Flash Cyber reaches frontier-level performance on CyberGym for autonomous vulnerability discovery, surpassing both its predecessor 3.5 Flash Cyber and significantly larger frontier models. Google reports a success rate above 70% at finding real vulnerabilities across 20 programming languages, and 47.2% pass@1 on CWE-Bench for automated patching against a leading frontier model's 47.8% — at significantly lower cost. Google's Chrome Security team found it produced 2.6 times more correct patches to Chrome vulnerabilities than the best commercial models.
| Released | 2026-09-02 |
|---|---|
| License | Proprietary |
| Weights | API only |
| Parameters | Undisclosed |
| Architecture | Shares the same foundational intelligence as Gemini 3.8 Flash, specialised for security applications — autonomous vulnerability discovery and automated patch generation. Google says the cybersecurity training behind the Cyber variant also drove part of the mainline model's coding and reasoning gains. |
| Modalities | Text |
| Status | Limited access — offered to vetted defenders through Google's Fairwind Program, on its own or combined with the CodeMender agent. Not on the public Gemini API. |
Benchmarks
CWE-Bench automated patching, as reported by Google at launch. Google did not name the comparison model.
| Benchmark | Gemini 3.8 Flash Cyber | Leading frontier model (unnamed) |
|---|---|---|
| CWE-Bench (pass@1) | 47.2% | 47.8% |
This model's scores
Scores on a 0–100 scale (25-point gridlines); higher is better. Each benchmark links to its published source.
Strengths
- 47.2% pass@1 on CWE-Bench automated patching, within a point of a leading frontier model at far lower cost
- Frontier-level CyberGym performance on autonomous vulnerability discovery, ahead of 3.5 Flash Cyber and much larger models
- Success rate above 70% finding real vulnerabilities across codebases in 20 programming languages
- 2.6× more correct Chrome patches than the best commercial models, per Google's Chrome Security team
- Runs on its own or inside CodeMender, so patch generation can be automated end to end
Best for
- Reach for it for autonomous vulnerability discovery across large codebases in authorised defensive security programmes
- Reach for it for automated patch generation, on its own or driven by Google's CodeMender agent
- Reach for it if you operate critical infrastructure or maintain widely-used software and qualify for the Fairwind Program
- Not a general-purpose model: use Gemini 3.8 Flash for everything outside security workflows
Gemini Cyber — every version
The full lineage of the Gemini Cyber line, newest first. Every version has its own page — click any to compare specs, benchmarks and pricing.
| Version | Released | Context | License |
|---|---|---|---|
| Gemini 3.8 Flash Cybercurrent | 2026-09-02 | — | Proprietary |
| Gemini 3.5 Flash Cyber | 2026-07-21 | — | Proprietary |
FAQ
What is Gemini 3.8 Flash Cyber?
Gemini 3.8 Flash Cyber is the cybersecurity model Google released on 2 September 2026 alongside Gemini 3.8 Flash. It shares the same foundational intelligence as the mainline model but is specialised for security work — autonomous vulnerability discovery and automated patch generation — and Google describes it as its most capable cybersecurity model.
Who can use Gemini 3.8 Flash Cyber?
It is not on the public Gemini API. Access is granted through Google DeepMind's Fairwind Program to vetted defenders: governments and national cyber authorities, critical infrastructure operators in healthcare, telecommunications, energy and financial services, and maintainers of core technology platforms. Applicants are vetted for a proven track record of ethical operations and research.
How well does Gemini 3.8 Flash Cyber patch vulnerabilities?
Google reports 47.2% pass@1 on CWE-Bench for automated patching, against 47.8% for a leading frontier model it did not name, at significantly lower cost. Google's Chrome Security team found the model produced 2.6 times more correct patches to Chrome vulnerabilities than the best commercial models.
How does it compare with Gemini 3.5 Flash Cyber?
Google says 3.8 Flash Cyber surpasses both 3.5 Flash Cyber and significantly larger frontier models on CyberGym, the benchmark for autonomous vulnerability discovery. It also reports a success rate above 70% at finding real vulnerabilities across codebases in 20 programming languages.
What does it cost?
Google has not published token pricing for Gemini 3.8 Flash Cyber. It is a restricted-access model distributed through the Fairwind Program rather than a listed Gemini API model, though Google states its patching performance comes at significantly lower cost than the leading frontier model it compared against.