Powered Vulnerability Discovery Explodes: Global Software Flaws Double in a Year to Record High
Add preferred source
AI tools are rewriting the cybersecurity landscape at unprecedented speed. The total number of registered CVE vulnerabilities globally surged from 33,512 to 66,401 over the past year—a 100% increase. Microsoft patched a record 974 vulnerabilities this month alone; Oracle released 1,448 patches in July, nearly quadruple the 309 from July 2025; Google Chrome fixed 1,072 flaws in June, exceeding the combined total of its previous 23 major releases. RogoLabs founder Jerry Gamblin argues the surge doesn’t mean software is less secure—rather, AI is exposing flaws that were always there. But the core tension is stark: AI-driven vulnerability discovery scales with compute power and can accelerate indefinitely, while patching depends on human labor that cannot be scaled quickly. Even if discussions about slowing AI development materialize into policy, they cannot reverse the vulnerability tsunami already underway.
Key Elements
Artificial intelligence is rewriting the offensive-defensive dynamics of cybersecurity at an unprecedented pace. According to a report by Wired magazine, the number of software security vulnerabilities discovered with the help of AI tools has surged like a tsunami over the past year, with the total number of registered CVE vulnerabilities worldwide doubling in a single year to a record high of 66,401. This shift is pushing already understaffed enterprise security teams and open-source software maintainers to their limits.
Microsoft disclosed last week that it has already patched 974 CVE vulnerabilities this month alone, setting a company record for the most fixes in a single month. CVE, or Common Vulnerabilities and Exposures, is the industry-standard identifier for software security flaws.
The numbers from other tech giants are equally striking. Oracle released a staggering 1,448 vulnerability patches in July of this year, compared to just 309 in July 2025—a nearly fourfold increase. Google’s Chrome browser fixed a cumulative 1,072 vulnerabilities across two major version updates in June, exceeding the combined total of its previous 23 major releases. Mozilla announced in April that it had conducted a concentrated vulnerability sweep using Anthropic’s Mythos AI model, uncovering 271 Firefox browser flaws in a single pass.
Jerry Gamblin, founder of industry research firm RogoLabs, operates the CVE tracking project cve.icu. According to his latest tally, as of this Wednesday, the total number of registered security vulnerabilities across the web has reached 66,401. That compares to 33,512 in the same period of September 2025—a doubling in one year. By contrast, when ChatGPT first launched in 2022, the full-year total of new vulnerabilities was just 25,000.
The dramatic acceleration in vulnerability discovery has sparked fierce debate within both the security and AI research communities. One camp views this as a catastrophic development that will upend the cybersecurity order; the other argues that AI is merely amplifying structural deficiencies that predate the AI boom—lagging patch cycles, under<a href="https://bitcomme.com/warren-buffett-has-endorsed-the-same-investment-for-decades-history-backs-him-up/” title=”Warren Buffett Has Endorsed the Same Investment for Decades. History Backs Him Up.”>investment in security, and the fact that hackers were already exploiting these flaws to cause widespread incidents long before AI arrived. But as the vulnerability count keeps climbing and the discussion shifts from theoretical to practical pressure, the two camps are gradually converging.
Gamblin’s assessment of the current situation is relatively measured. He points out that the surge in total vulnerabilities does not equate to software becoming less secure. “More CVEs doesn’t mean more vulnerabilities—it means more discovered vulnerabilities, which broadly indicates that the security scanning ecosystem is working,” he said. In his view, flaws that were previously hidden in the shadows are now being exposed one by one by AI, which is fundamentally an upgrade in security capability.
However, the risk does not automatically dissipate simply because “discovery equals progress.” The core tension is this: AI can discover vulnerabilities far faster than humans can fix them. Attackers can also leverage AI to autonomously find brand-new vulnerabilities, enabling more frequent and more sophisticated cyberattacks. The UK’s National Cyber Security Centre (NCSC) put it bluntly: “Simply finding vulnerabilities does nothing to improve your security.”
For now, AI maintains a fragile equilibrium between offense and defense. Matthew Olney, director of threat intelligence at Cisco Systems, said that whether it’s legitimate enterprises or attackers, “everyone is trying to figure out the same question: where should I be using AI?”
Discussions about slowing the development of frontier AI models continue both within and outside the industry, whether through regulatory policy or voluntary industry agreements. But even if such measures are implemented, they can only address the future. For the vulnerability tsunami already at hand, no form of “AI deceleration” can reverse it. As Gamblin put it: “The scale of vulnerability discovery depends on compute—throw money at it and it accelerates without limit. But the scale of vulnerability remediation depends on people, and people are precisely what you cannot buy within a single quarter.”
| Organization | Timeframe | Vulnerabilities Fixed/Found | Comparison Baseline |
|---|---|---|---|
| Microsoft | This month to date | 974 CVEs | Highest single-month total in company history |
| Oracle | July 2026 | 1,448 patches | 309 in July 2025 |
| Google Chrome | June 2026 | 1,072 patches | More than previous 23 major releases combined |
| Mozilla Firefox | April 2026 | 271 vulnerabilities | Single AI-assisted sweep |
| Global CVE total | As of this Wednesday | 66,401 | 33,512 in the same period of 2025 |
Note: Data sourced from RogoLabs’ cve.icu tracking project and public company disclosures.
For enterprise security teams and open-source maintainers, the pressure from this trend is multidimensional. On one hand, the surge in vulnerability counts means the workload for triage and remediation has multiplied; on the other, attackers’ ability to leverage AI tools is improving in lockstep, dramatically compressing the response window available to human defenders. Open-source projects that rely on volunteers maintaining core components in their spare time face an especially dire situation.
From a broader perspective, the AI-driven vulnerability discovery boom is forcing the entire industry to reexamine structural issues in security investment. Historically, security budgets have skewed toward purchasing protective products and compliance audits, while underinvesting in foundational patch management and vulnerability response processes. Now that AI has drastically lowered the cost of finding vulnerabilities, what’s been exposed is the human bottleneck on the remediation side—a bottleneck that will not disappear simply because compute power increases.
Once added, BigGo Finance appears first in Google Search Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.
