AI Fuels Record Surge in Software Vulnerabilities, Straining Security Teams

27 minutes ago
AI Fuels Record Surge in Software Vulnerabilities, Straining Security Teams

The cybersecurity world is grappling with an unprecedented surge in software vulnerabilities, largely driven by the accelerating capabilities of artificial intelligence, even as discussions about AI's future risks dominate headlines. This AI-driven "vulnerability explosion" is placing immense pressure on already stretched IT and security teams, as well as the volunteers maintaining open-source software.



While researchers have always found vulnerabilities, the recent spike is undeniable. Microsoft has already issued patches for 974 confirmed software flaws (CVEs) this month, setting a new record. In July, Oracle released a staggering 1,448 patches, a massive jump from 309 in July 2025. Google Chrome's two major June releases included 1,072 patches, surpassing the total from its previous 23 major releases combined.



The numbers are stark: as of this week, a total of 66,401 CVEs have been recorded, according to Jerry Gamblin, head of research at Empirical Security. This nearly doubles the 33,512 CVEs logged by the same date last year and significantly outpaces the 25,000 CVEs recorded throughout 2022, the year ChatGPT launched.



Experts are divided on whether this trend will be catastrophic or simply amplify existing cybersecurity challenges. Some argue that slow patch adoption and underinvestment in security already gave attackers an edge. However, as vulnerability discovery rates climb, the debate is becoming less theoretical.



"I don’t think it’s overblown," Gamblin states, emphasizing that "more CVEs is not more vulnerability. It's more known vulnerability, which is mostly the system working." The real concern lies in the potential for developers and users to fall behind on patching, coupled with an escalation of cyberattacks as more threat actors leverage AI to discover novel exploits.



The core issue, as highlighted by Britain's National Cyber Security Centre, is that "Just finding vulnerabilities does nothing to improve your security." The challenge now is to effectively manage and remediate this deluge of discovered flaws before they can be exploited.


AI Fuels Record Surge in Software Vulnerabilities, Straining Security Teams
Previous
AI Fuels Record Surge in Software Vulnerabilities, Straining Security Teams
Next
Flock Safety Offers Buyouts Amid Customer Exodus and Privacy Backlash
Flock Safety Offers Buyouts Amid Customer Exodus and Privacy Backlash