Cisco released Antares on July 21, 2026, a pair of open-weight AI models built to identify which files in a codebase are likely to contain a known vulnerability. The models, Antares-350M and Antares-1B, are live now on Hugging Face, and Cisco says benchmark tests on its own 500-task Vulnerability Localization Benchmark show both models outperforming several larger closed- and open-weight rivals at a fraction of the estimated runtime cost, with a third, larger model, Antares-3B, still in development.
Rather than flag generic coding issues, Antares works through a repository the way a human security analyst might: starting from a vulnerability description, it searches for matching code patterns, opens candidate files, weighs new evidence, and narrows toward the files most likely to be affected before handing a reviewer a ranked list. That iterative-search approach, adapted from earlier research by Cisco's Foundation AI team, is built on the premise that useful retrieval behavior can come from how a model searches, not just how large it is.
The bigger selling point may be where the models run. Because Antares is compact enough for local or on-premises deployment, security teams can scan proprietary code without sending it to a third-party API, an appeal Cisco is aiming squarely at universities, public-sector agencies, and smaller security teams that have lacked the budget for token-intensive AI tools. Antares is not meant to replace static analysis, secret scanning, or dynamic testing; Cisco frames it as a way to speed up the initial triage step that usually falls to a human analyst.
Antares arrives alongside two other recent Cisco security-AI projects, Foundry Security Spec and the CodeGuard secure-coding rules corpus, and lands at a moment when rivals including Google and OpenAI are applying much larger frontier models to the same vulnerability-triage problem. Whether a model with fewer than a billion parameters can hold up against that competition at production scale, across codebases far messier than a 500-task benchmark, is still an open question.












