AI/TLDR

Gemini 3.8 Flash Cyber

Security-specialised twin of Gemini 3.8 Flash for vulnerability discovery and automated patching, released September 2026 to vetted defenders through Google's Fairwind Program.

Gemini CyberAPI onlyLimited access — offered to vetted defenders through Google's Fairwind Program, on its own or combined with the CodeMender agent. Not on the public Gemini API.
Released
2 Sep 2026
Parameters
Undisclosed
License
Proprietary

Overview

Gemini 3.8 Flash Cyber is the security model Google released on 2 September 2026 alongside Gemini 3.8 Flash. Google calls it "our most capable cybersecurity model, with frontier-level performance in vulnerability detection and automated patching", and it shares the same foundational intelligence as the mainline 3.8 Flash model rather than being a separate pretraining run.

It is not generally available. Access runs through the Fairwind Program, a vetted-access programme Google DeepMind launched with this model to give high-priority defenders early access before new threats arrive. Google prioritises governments and national cyber authorities, critical infrastructure operators in healthcare, telecommunications, energy and financial services, and maintainers of core technology platforms; applicants are vetted for a proven track record of ethical operations and research. Participants can use the model on its own or combined with CodeMender, Google's code-security agent for automating vulnerability fixes.

On the results Google published at launch, 3.8 Flash Cyber reaches frontier-level performance on CyberGym for autonomous vulnerability discovery, surpassing both its predecessor 3.5 Flash Cyber and significantly larger frontier models. Google reports a success rate above 70% at finding real vulnerabilities across 20 programming languages, and 47.2% pass@1 on CWE-Bench for automated patching against a leading frontier model's 47.8% — at significantly lower cost. Google's Chrome Security team found it produced 2.6 times more correct patches to Chrome vulnerabilities than the best commercial models.

Released2026-09-02
LicenseProprietary
WeightsAPI only
ParametersUndisclosed
ArchitectureShares the same foundational intelligence as Gemini 3.8 Flash, specialised for security applications — autonomous vulnerability discovery and automated patch generation. Google says the cybersecurity training behind the Cyber variant also drove part of the mainline model's coding and reasoning gains.
ModalitiesText
StatusLimited access — offered to vetted defenders through Google's Fairwind Program, on its own or combined with the CodeMender agent. Not on the public Gemini API.

Benchmarks

CWE-Bench automated patching, as reported by Google at launch. Google did not name the comparison model.

BenchmarkGemini 3.8 Flash CyberLeading frontier model (unnamed)
CWE-Bench (pass@1)47.2%47.8%

Comparison source ↗

This model's scores

  1. CWE-Bench (automated patching, pass@1)47.2%

Scores on a 0–100 scale (25-point gridlines); higher is better. Each benchmark links to its published source.

Strengths

  • 47.2% pass@1 on CWE-Bench automated patching, within a point of a leading frontier model at far lower cost
  • Frontier-level CyberGym performance on autonomous vulnerability discovery, ahead of 3.5 Flash Cyber and much larger models
  • Success rate above 70% finding real vulnerabilities across codebases in 20 programming languages
  • 2.6× more correct Chrome patches than the best commercial models, per Google's Chrome Security team
  • Runs on its own or inside CodeMender, so patch generation can be automated end to end

Best for

  • Reach for it for autonomous vulnerability discovery across large codebases in authorised defensive security programmes
  • Reach for it for automated patch generation, on its own or driven by Google's CodeMender agent
  • Reach for it if you operate critical infrastructure or maintain widely-used software and qualify for the Fairwind Program
  • Not a general-purpose model: use Gemini 3.8 Flash for everything outside security workflows

Gemini Cyber — every version

The full lineage of the Gemini Cyber line, newest first. Every version has its own page — click any to compare specs, benchmarks and pricing.

VersionReleasedContextLicense
Gemini 3.8 Flash Cybercurrent2026-09-02Proprietary
Gemini 3.5 Flash Cyber2026-07-21Proprietary

FAQ

What is Gemini 3.8 Flash Cyber?

Gemini 3.8 Flash Cyber is the cybersecurity model Google released on 2 September 2026 alongside Gemini 3.8 Flash. It shares the same foundational intelligence as the mainline model but is specialised for security work — autonomous vulnerability discovery and automated patch generation — and Google describes it as its most capable cybersecurity model.

Who can use Gemini 3.8 Flash Cyber?

It is not on the public Gemini API. Access is granted through Google DeepMind's Fairwind Program to vetted defenders: governments and national cyber authorities, critical infrastructure operators in healthcare, telecommunications, energy and financial services, and maintainers of core technology platforms. Applicants are vetted for a proven track record of ethical operations and research.

How well does Gemini 3.8 Flash Cyber patch vulnerabilities?

Google reports 47.2% pass@1 on CWE-Bench for automated patching, against 47.8% for a leading frontier model it did not name, at significantly lower cost. Google's Chrome Security team found the model produced 2.6 times more correct patches to Chrome vulnerabilities than the best commercial models.

How does it compare with Gemini 3.5 Flash Cyber?

Google says 3.8 Flash Cyber surpasses both 3.5 Flash Cyber and significantly larger frontier models on CyberGym, the benchmark for autonomous vulnerability discovery. It also reports a success rate above 70% at finding real vulnerabilities across codebases in 20 programming languages.

What does it cost?

Google has not published token pricing for Gemini 3.8 Flash Cyber. It is a restricted-access model distributed through the Fairwind Program rather than a listed Gemini API model, though Google states its patching performance comes at significantly lower cost than the leading frontier model it compared against.