tech
AI Bug Hunting Drives Record Surge in Software Vulnerabilities

Software vulnerability disclosures are on pace to roughly double in 2026 compared with last year, and researchers tracking the numbers say AI-assisted bug hunting is the main driver. Microsoft said last week it had issued patches for 974 CVEs so far in September, a company record, according to figures reported by WIRED on September 19, 2026. A CVE, short for common vulnerabilities and exposures, is the standard industry label for a confirmed software flaw.
How much has vulnerability disclosure grown in 2026?
As of September 16, 2026, cve.icu — the tracking project run by Jerry Gamblin, head of research at Empirical Security — had logged 66,401 CVEs for the year, per Wired's report. On the same date in 2025, the total stood at 33,512, meaning this year's count had already reached roughly double last year's pace with more than three months still to go. For comparison, all of 2022 — the year OpenAI launched the first public version of ChatGPT — produced about 25,000 CVEs, according to the same dataset. The trend line does not prove AI caused every additional disclosure, but the timing lines up with the wider availability of AI coding and analysis tools capable of scanning source code for flaws.
Which companies are shipping the most AI-found patches?
Oracle's patch volume offers the sharpest year-over-year jump in the data cited by Wired: the company shipped 1,448 patches in July 2026, compared with 309 in July 2025, a nearly fivefold increase. Google's Chrome browser saw a similar pattern at the code level rather than the calendar level. Its two major version releases in June 2026 carried 1,072 combined fixes, more than the total number of vulnerability patches shipped across Chrome's prior 23 major releases put together, according to Wired's review of Chrome's release notes. Mozilla reported a narrower but pointed example in April 2026, disclosing 271 vulnerabilities found in Firefox during a single bug-hunting sprint that used Anthropic's Mythos model, per the same Wired account.
Does a higher CVE count mean software is less secure?
Gamblin, whose cve.icu project supplies much of the year-over-year comparison, told Wired he does not view the spike as alarming on its own. "I don't think it's overblown," he said, adding: "What I would push back on is the idea that a bigger number is itself the harm. More CVEs is not more vulnerability. It's more known vulnerability, which is mostly the system working." That framing puts Gamblin closer to researchers who see AI-driven discovery as accelerating a disclosure process that already existed, rather than creating new categories of risk. The counterargument, also present in Wired's reporting, is that discovery is now outpacing an industry's ability to patch, distribute, and verify fixes — a gap that existed before AI tools arrived and that a faster flow of findings could widen rather than close.
What does the flood of AI-found bugs mean for open-source projects?
Mozilla's Firefox sprint illustrates the pressure point for smaller or volunteer-run projects: 271 vulnerabilities surfaced in one testing cycle is a substantial triage workload for any team, let alone one without Oracle- or Microsoft-scale security staffing. Wired's reporting frames this as the practical cost of AI-assisted bug hunting — the tools are broadly available, including in open-weight models, so the discovery capability is not confined to large vendors with big patch teams. The open question the industry has not resolved is whether AI tools that find bugs faster will also be paired with AI tools that triage and patch them at a matching speed, or whether human review will remain the bottleneck regardless of how many flaws are found.
What to watch
- Whether cve.icu's year-end total for 2026 lands near double the 2025 figure, confirming the trend Gamblin has tracked through mid-September.
- Whether Microsoft, Oracle, or Google report slower patch-release cadence even as discovery volume climbs, which would signal the predicted bottleneck materializing.
- Whether more open-source maintainers publicly describe being overwhelmed by AI-surfaced bug reports, following Mozilla's April Firefox sprint.
- Whether AI labs' discussions of a voluntary slowdown on frontier model development extend to restricting bug-hunting tool releases, or remain focused solely on model capability.
Wired's Kernel Panic newsletter, written by Lily Hay Newman and Matt Burgess, is tracking the story on an ongoing basis at the original report.
Questions
How many CVEs have been recorded so far in 2026?
As of September 16, 2026, cve.icu had logged 66,401 CVEs for the year, compared with 33,512 on the same date in 2025, according to Wired's report citing researcher Jerry Gamblin.
How much did Oracle's patch volume increase year over year?
Oracle shipped 1,448 patches in July 2026 versus 309 in July 2025, according to figures reported by Wired.