Chinese AI lab Z.ai released GLM-5.3 on August 14, a model the company says reuses the exact same 743-billion-parameter base as GLM-5.2 — with every gain coming from post-training rather than a fresh pre-training run.
The update makes GLM-5.3 'the most capable open-weights model for coding,' Z.ai says, citing a 50% improvement over GLM-5.2 on its in-house Z.ai Code Bench and open-weights state-of-the-art results on public benchmarks including Terminal-Bench 3.0 (28.3 vs. 4.6), DeepSWE v1.1 (66.9) and Agents' Last Exam (28.5). The gains come from scaling reinforcement learning across long-horizon 'work environments' — tasks that can represent several days of a senior engineer's work, with the model expected to diagnose bottlenecks, run experiments and deliver measurable end-to-end speedups.
The most surprising finding is what Z.ai calls an emergent cyber capability. As post-training scaled, vulnerability discovery improved faster than expected: GLM-5.3 scores 84.5% on CyberGym, the best result on the benchmark and ahead of Anthropic's Mythos 5 (83.8%) and OpenAI's GPT-5.6 Sol (83.6%). On ExploitBench it more than doubles GLM-5.2 (54.4 vs. 24.4), and on ExploitGym it completes 105 tasks in two hours versus 29 before.
The pattern holds in the real world. Working with security teams in China, the model identified 2,436 vulnerabilities across 269 projects — 1,097 of medium-to-high severity — with the oldest flaw dating back to 1981. On average, a vulnerability had lived 26.6 years in the code before discovery. Z.ai is tracking the disclosures in a public Security Disclosure Ledger.
Weights will be released openly in about two weeks, after safety evaluation and hardening, the company said. For API users, thinking is now always enabled with three effort levels (low, high, max) — a migration that breaks calls still sending thinking.type: 'disabled'. GLM Coding Plan subscribers also move to a points-based quota with 50% off-peak pricing.
Sources
- z.aiGLM-5.3: Frontier Coding with Emergent Cyber Capabilities — Z.ai
- unite.aiZ.ai Launches GLM-5.3 With Frontier Coding and a Cyber Capability That Outgrew Its Training — Unite.AI
- marktechpost.comZ.ai Ships GLM-5.3 Without Retraining the Base Model — MarkTechPost
- techtimes.comGLM-5.3: Post-Training Produced Exploit Chains Z.ai Never Planned — TechTimes




