AIToday
AI Coding AssistantsAI Safety & AlignmentWIRED AIPublished: Sep 19, 2026, 22:00 JST

AI bug hunting drives 66,401 CVEs as slowdown talks stall

AI bug hunting drives 66,401 CVEs as slowdown talks stall

3 Key Points

  1. What happened

    A wave of AI-assisted vulnerability discovery has hit the software industry. Microsoft issued patches for 974 CVEs in one month, a new record, while cve.icu has logged 66,401 CVEs so far this year.

  2. Why it matters

    AI is surfacing more known flaws, not necessarily more total flaws, which is putting pressure on under-resourced IT and security teams and open source volunteers to keep pace with patching.

  3. What to watch

    The balance hinges on whether defenders can use AI as effectively as attackers, says Cisco's Matthew Olney. Watch whether patch adoption keeps up with discovery.

WHO IT HITSEnterprise IT and security teams are being pushed to patch faster than ever, while the volunteers maintaining critical open source software face a growing backlog of fixes.

Not sure about something? Ask the AI

Summaries like this, in your inbox every morning.

Context & Analysis

The newsletter Kernel Panic debuts with a focus on how AI is reshaping digital security. For years, AI doomers worried about a software vulnerability apocalypse, but the article notes that concern has shifted toward rogue AI causing mass human death. Meanwhile, the vulnerability wave from existing AI tools has already arrived.

The numbers back this up. Microsoft's 974 CVE patches in one month set a record. Oracle shipped 1,448 patches in July, compared to 309 in July 2025. Google Chrome's two major June releases included 1,072 patches, more than all fixes in the prior 23 big releases combined. Mozilla found 271 vulnerabilities in Firefox in one sprint using Anthropic's Mythos model. Overall, cve.icu has logged 66,401 CVEs this year, nearly double the 33,512 recorded by September 16 last year.

Experts are divided on whether this is catastrophic or just magnifying existing dynamics. Jerry Gamblin of Empirical Security argues more CVEs means more known vulnerabilities, which is mostly the system working. But the fear is that patching cannot keep up. As Gamblin puts it, discovery scales with compute, while remediation scales with people. The stakes hinge on whether defenders can use AI as effectively as attackers, and whether under-resourced security teams can close the gap.

FAQ
What is a CVE?
A CVE, or common vulnerability and exposure, is a confirmed software flaw that has been catalogued and disclosed.
How does the 2026 CVE count compare to previous years?
By September 16 last year, cve.icu had logged 33,512 CVEs, almost half the 66,401 recorded as of this week. For all of 2022, the year ChatGPT launched, cve.icu recorded 25,000 CVEs.
Are AI companies planning to slow down development?
AI leaders are considering a cooperative slowdown on frontier model development, and the article notes that any slowdown could not stop the vulnerability surge already under way.

Get the latest AI Coding Assistants news every morning

For example, today's edition would include:

  • Oracle's Clay Magouyrk: AI coding rollout outpaced our processesTop Companies AI · 17h ago
  • HarnessRouter standardizes agent runs via one protocolDaily Dose of Data Science · 20h ago
  • Anthropic: 26 percent of dev work at AL4, a quarter of researchTHE DECODER · 23h ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleVals raises $40 million to fix AI benchmarking, revenue up 8x