MikhbarMIKHBAR
Cybersecurity

AI-Driven Vulnerability Discovery Surges to Record Highs

While industry leaders debate a cooperative slowdown in AI development, a massive wave of AI-accelerated vulnerability discovery is already straining global IT and security infrastructure.

AI-Driven Vulnerability Discovery Surges to Record Highs

A Cybersecurity Sea Change

The ongoing conversation surrounding artificial intelligence often focuses on theoretical, long-term risks. However, a significant shift in the cybersecurity landscape has already taken hold. While AI labs toy with the possibility of industry-wide agreements to slow the development of frontier models, the widespread availability of mainstream AI products and open-weight models is currently fueling an unprecedented spike in software vulnerability discovery.

This trend has created a clear divide in the industry. While researchers previously identified vulnerabilities through manual efforts, the integration of AI tools has significantly accelerated the pace of bug hunting. This 'vulnerability tsunami' is now placing immense strain on under-resourced IT departments and the global community of volunteers tasked with maintaining vital open-source software.

Record-Breaking CVE Data

The scale of the current surge is evidenced by the rising number of Common Vulnerabilities and Exposures (CVEs) recorded by researchers. According to data from cve.icu, a project founded by Empirical Security’s Jerry Gamblin, there have been 66,401 CVEs recorded as of September 2026. This figure marks a stark increase from the 33,512 vulnerabilities logged by the same date last year. To put this into perspective, the total number of CVEs for all of 2022—the year ChatGPT was launched—was approximately 25,000.

Major technology companies are reflecting this trend in their monthly patch cycles. Microsoft recently reported a new record, having issued patches for 974 CVEs in a single month. Oracle’s patch count reached 1,448 in July, compared to 309 during the same period in 2025. Furthermore, Google Chrome’s two major releases in June addressed 1,072 vulnerabilities, exceeding the total number of fixes provided in the prior 23 major releases combined. Mozilla also noted that a single bug-hunting sprint using Anthropic’s Mythos model uncovered 271 vulnerabilities in Firefox.

The Gap Between Discovery and Remediation

While the sheer volume of discovered vulnerabilities is unprecedented, experts offer differing perspectives on the nature of the risk. Jerry Gamblin notes that an increase in CVEs does not necessarily equate to more vulnerability, but rather more visibility into existing flaws. From this perspective, the current wave indicates that the reporting system is functioning.

However, the primary concern remains the disparity between the speed of discovery and the capacity for remediation. As Britain’s National Cyber Security Center has observed, simply identifying vulnerabilities does not enhance security if they remain unpatched. The core challenge is that while vulnerability discovery can scale with compute power, the remediation process requires human personnel—a resource that remains difficult to scale in the short term.

Industry Balancing Act

Despite the surge in discoveries, some security experts maintain that the current landscape is finding a tenuous balance. Researchers are increasingly exploring how defenders can leverage the same AI tools that attackers are using to uncover weaknesses. Matthew Olney, director of threat intelligence at Cisco Systems, suggests that both industry players and malicious actors are currently in a phase of experimentation, attempting to determine the most effective ways to integrate AI into their respective operations.

While slow patch adoption and lagging investment in cybersecurity were issues long before the rise of AI, the current acceleration has made these challenges less theoretical and more immediate. The industry is now grappling with the reality that even if regulatory frameworks or accords successfully curtail the development of advanced AI in the future, the infrastructure for AI-powered vulnerability discovery is already deeply integrated into the digital ecosystem.

Sources

  • WIREDForget the AI Slowdown—the Vulnerability Explosion Is Already Happening