AI-Driven Vulnerability Discovery Surges, Doubling 2025 Totals in 2026

AI-Driven Vulnerability Discovery Surges, Doubling 2025 Totals in 2026

AI-Driven Vulnerability Discovery Surges, Doubling 2025 Totals in 2026

The number of software security flaws detected by artificial intelligence (AI) systems in 2026 is on track to double the count from 2025. The US National Vulnerabilities Database already records 45,207 flaws as of July, nearing last year's total and setting a new all-time high.

Tech Giants Report Record Numbers of Patches

Oracle Corp. patches 1,449 security vulnerabilities in its July update, an all-time record for the company. This figure is nearly five times higher than the 309 fixes reported in the same month last year. Microsoft Corp. also discloses 642 security bugs in July, another all-time high and almost five times the count from the previous year. Alphabet Inc.’s Google addresses 433 such bugs in a recent Chrome browser update, compared to just 11 in the equivalent update one year ago.

AI Enhances Vulnerability Detection

“We have to come to the reckoning that these tools are increasing the ability of people to find vulnerabilities in software,” says Gabriel Bernadett-Shapiro, distinguished AI research scientist at SentinelOne Inc. At Google, the “unprecedented scale and speed” of vulnerability discovery is attributed to advances in AI models and corresponding investments, according to Doug Turner, Chrome’s director of engineering.

No Rise in Exploited Issues Despite Uptick

Despite the surge in discovered vulnerabilities, there has been no rise in the number of exploited issues this year, according to the US government’s Known Exploited Vulnerabilities catalog. Many of the new vulnerabilities are found internally by the tech firms' own cyber-focused AI tools. For instance, out of the 433 vulnerabilities in Chrome in July, 401 were “reported by Google” internally.

Industry Reactions and Future Outlook

“We just aren’t seeing the numbers to back up the doom and gloom prophets,” says Dustin Childs, head of threat awareness at Trend Micro Inc. Frontier AI models, like Anthropic PBC’s Mythos, demonstrate a new level of capability in discovering software vulnerabilities. These models impress officials at the National Security Agency with their ability to find and exploit cybersecurity vulnerabilities. Microsoft releases another AI security tool, MAI-Cyber-1-Flash, aimed at helping with software vulnerability management. Hackers are now turning abstract vulnerabilities into working exploits faster, with the average time dropping from 72 hours last year to just 24 hours in 2026, according to Alexander Leslie, senior advisor at Recorded Future Inc.

References

← Back to all posts

Enjoyed this article? Get more insights!

Subscribe to our newsletter for the latest AI news, tutorials, and expert insights delivered directly to your inbox.

We respect your privacy. Unsubscribe at any time.