Skip to main content
Live
Main content

AI bug hunters push 2026 CVE count past 66,000, doubling last year's pace

Microsoft patched 974 flaws in a single September; Oracle shipped 1,448 in July. AI-assisted discovery is outrunning human remediation.

Jaeden Schafer
Editor in Chief · · 5 min read
Anthropic logo

AI-assisted vulnerability discovery has pushed the number of new software flaws disclosed in 2026 to 66,401 as of September 17, according to cve.icu, the tracking project run by Empirical Security's Jerry Gamblin. That is nearly double the 33,512 CVEs the same project had logged by September 16, 2025, and more than 2.5x the 25,000 recorded in all of 2022, the year OpenAI shipped the first ChatGPT.

The pace of patch releases from major vendors tells the same story. Microsoft issued fixes for 974 CVEs in September 2026 alone, a monthly record. Oracle shipped 1,448 patches in its July 2026 quarterly update, up from 309 in July 2025 — a nearly fivefold year-over-year jump. Google Chrome's two major releases in June 2026 carried 1,072 patches between them, more than every fix shipped in the prior 23 major releases combined.

The proximate cause is that mainstream AI models are now competent bug hunters. Mozilla disclosed in April that a single sprint against Firefox using Anthropic's Mythos model surfaced 271 vulnerabilities. That is roughly what a full-time human security team might turn up over months of manual review, compressed into one push.

Key facts

  • 01cve.icu has recorded 66,401 CVEs as of September 17, 2026, nearly double the 33,512 logged by the same date in 2025.
  • 02Microsoft issued patches for 974 CVEs in September 2026 alone, a monthly record for the company.
  • 03Oracle shipped 1,448 patches in its July 2026 update, up from 309 in July 2025 — a nearly fivefold jump.
  • 04Google Chrome's two major June 2026 releases carried 1,072 patches, more than the prior 23 releases combined.
  • 05Mozilla found 271 Firefox vulnerabilities during a single April sprint using [Anthropic](/claude)'s Mythos model.

The debate inside the security community is whether the surge is a crisis or a catch-up. Gamblin, who also founded the CVE analysis project RogoLabs, argues the raw count is not itself the danger.

The concern is what happens on the other side of disclosure. A CVE is a known flaw, but a known flaw is only fixed once a vendor ships a patch and every customer installs it. Patch adoption already lags across most enterprise environments, and the volumes being disclosed now assume defenders can absorb multiples of last year's workload. Britain's National Cyber Security Center put the concern flatly: "Just finding vulnerabilities does nothing to improve your security."

The same AI tools that help defenders scale are equally available to attackers. Open-weight models can be pointed at the same codebases with the same prompts, and adversaries do not have to respect a responsible-disclosure window. That is the loop security researchers are watching most closely: the interval between when a class of AI-discovered bugs starts appearing in patch notes and when the same class starts appearing in exploit kits.

For now, Cisco Systems' threat intelligence director Matthew Olney says both sides are still finding their footing.

Actors, just like industry, are trying to figure out, 'where do I use AI?'
Matthew Olney, Director of threat intelligence at Cisco Systems

The broader industry backdrop makes the timing awkward. Frontier AI labs are actively discussing whether to slow model releases to buy time on catastrophic-risk questions like autonomous bioweapon design or loss-of-control scenarios — a conversation AI Chat Daily has covered in recent pieces on Anthropic's "pace the frontier" pitch and California's newly ordered kill-switch rules. But the vulnerability-discovery wave is not a frontier-model problem. It is being driven by capabilities that already shipped, in models that are already open-weight, integrated into IDEs, and running inside enterprise pipelines. A pause on GPT-6 or Claude Opus 6 does nothing to reverse it.

Related · from this week
Mustafa Suleyman says AI threats are real and Anthropic is making them worse
Jaeden Schafer · 5 min read →

Gamblin's framing gets at the asymmetry the security industry now has to solve.

That asymmetry is the story worth watching over the next four quarters. Vendors like Microsoft, Oracle, and Google can throw more compute at scanning their own code, and they clearly are — the patch counts prove it. Downstream, the enterprise buyers running that software cannot hire security engineers or DevOps staff at anything close to the rate at which CVEs are being filed. The market opening is for tooling that closes the gap: AI-native patch prioritization, automated remediation, and virtual patching at the runtime and network layers. Expect the next wave of security-startup funding rounds to concentrate there, and expect the incumbents — CrowdStrike, Palo Alto Networks, Wiz — to acquire aggressively into the same category. The vulnerability tsunami is not slowing, and the only scalable answer is more automation on the defensive side.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Microsoft logo
Security

Mustafa Suleyman says AI threats are real and Anthropic is making them worse

Microsoft's AI chief published a 37-page Humanist AI Code of Conduct and a companion essay attacking Anthropic's model-welfare stance.

Jaeden Schafer5 min read
Microsoft logo
Security

Microsoft publishes 37-page 'humanist AI code of conduct'

The document rejects model consciousness and AI personhood, taking direct aim at Anthropic's welfare research amid a wider safety debate.

Jaeden Schafer5 min read
OpenAI logo
Security

Altman testifies Musk demanded long-term OpenAI control before split

On the stand, the OpenAI CEO produced 2017 emails and texts showing Musk wanted control through SpaceX-style supervoting before walking away.

Jaeden Schafer5 min read