The Rise of AI-Driven Vulnerability Discovery
As the world grapples with the implications of artificial intelligence, one area that has quietly but dramatically transformed is cybersecurity. The narrative around AI often focuses on its potential for catastrophic outcomes—whether through rogue systems or existential risks. But what's become increasingly clear is that AI's impact on digital security is already unfolding in a more immediate and tangible way: a massive spike in vulnerability discovery.
"What I would push back on is the idea that a bigger number is itself the harm. More CVEs is not more vulnerability. It's more known vulnerability, which is mostly the system working." — Jerry Gamblin, Empirical Security
This shift isn't just about AI making things faster—it's about how AI tools are now enabling both professionals and amateur hackers to identify flaws in systems previously hidden from view. In the past, security researchers might have spent weeks or months hunting down a single vulnerability through manual code reviews or reverse engineering. Today, that same effort can be completed in minutes with an AI assistant.
A Tidal Wave of CVEs
According to data from cve.icu, the number of reported Common Vulnerabilities and Exposures (CVEs) has skyrocketed. In just over a year—from September 16, 2024, to today—more than 33,000 new CVEs have been logged. That's nearly double what was recorded in all of 2022 when OpenAI launched ChatGPT.
- Microsoft patched 974 CVEs in one month, a record high.
- Oracle released 1,448 patches in July 2026 compared to only 309 in the same period last year.
- Google Chrome shipped 1,072 patches in two major updates in June alone—more than all previous releases combined.
- Mozilla found 271 vulnerabilities in Firefox during a single bug-hunting sprint using Anthropic's Mythos model.
The sheer volume of findings is staggering and not just an academic curiosity. It signals a fundamental change in how software flaws are discovered, and it places immense pressure on the teams responsible for fixing them.
Why This Matters Now
While some may see these numbers as alarming, there's a critical distinction to be made: more CVEs do not necessarily mean more vulnerabilities. They indicate that systems are becoming more transparent. In fact, as Jerry Gamblin, head of research at Empirical Security and founder of RogoLabs, puts it, “Discovery scales with compute. Remediation scales with people—and people are the part you can't buy more of in a quarter.”
This is where the real concern lies. If AI tools can find flaws faster than ever before, but the human resources needed to fix them remain static or even shrinking, we're left with a dangerous gap between detection and response.
The Human Cost Behind the Numbers
IT and security teams are already stretched thin. With the recent surge in vulnerability disclosures, they're facing an ever-growing backlog of issues that must be prioritized and remediated. Open-source maintainers—who often work voluntarily—are especially hard-hit, as they lack the financial backing or staffing to keep up with the pace of discovery.
This is not a theoretical scenario anymore. Real-world impacts are already being felt across industries. Financial institutions, healthcare providers, and even government agencies are seeing their systems compromised due to previously unknown vulnerabilities that were exposed only after AI-assisted research revealed them.
Can an AI Slowdown Help?
With many AI labs proposing a voluntary slowdown in frontier model development, the hope is that such measures might mitigate existential risks. However, this approach has limitations when it comes to addressing the current vulnerability explosion.
AI-powered bug discovery is already here and largely decentralized. Anyone with access to an open-source model or chatbot can start hunting for vulnerabilities today—no approvals needed. A slowdown in research may prevent some future disasters, but it won't reverse the damage already done by existing AI tools.
The Role of AI in Defense
Despite the growing risks, there's also a silver lining. AI isn't just a threat—it's becoming a powerful ally in cybersecurity defense. Many organizations are using AI to streamline patch management, automate incident response, and proactively identify potential threats before they're exploited.
But here's the catch: those same tools that help defenders also empower attackers. As Matthew Olney, director of threat intelligence at Cisco Systems, explains, “Actors, just like industry, are trying to figure out, 'where do I use AI?'” The key is in understanding when and how to deploy these technologies responsibly.
Looking Ahead: What's Next?
The next few years will be crucial for cybersecurity. As we continue to see more vulnerabilities being discovered, the focus must shift from simply detecting flaws to rapidly patching them. The industry needs better processes for vulnerability triage, more efficient remediation workflows, and improved collaboration between vendors and security teams.
More importantly, there's a growing consensus that AI should be part of the solution—not just another problem. That means investing in tools that enhance human decision-making rather than replacing it, building robust training pipelines for security personnel, and ensuring that AI systems themselves are secure from the inside out.
The age of AI-driven vulnerability discovery has arrived—and we must prepare for a future where the speed of discovery will outpace our ability to respond. It's no longer a question of if but when—and how well we adapt.
Key Facts
- CVEs logged since September 16, 2024: More than 33,000 new CVEs
- Microsoft patches in one month: 974 CVEs
- Oracle patches in July 2026: 1,448 patches
- Google Chrome patches in June 2026: 1,072 patches
- Mozilla vulnerabilities found using AI: 271 vulnerabilities in Firefox
- Total CVEs recorded as of recent count: 66,401 CVEs
- CVEs logged in 2022: 25,000 CVEs
- CVEs logged by September 16, 2024: 33,512 CVEs
Background
The article discusses how artificial intelligence is transforming cybersecurity by dramatically increasing the number of discovered vulnerabilities. AI tools are enabling both professionals and amateur hackers to identify flaws in systems that were previously hidden from view, leading to a massive spike in vulnerability discovery. This trend has created pressure on security teams responsible for fixing these issues, especially as open-source maintainers face challenges due to limited resources.
Quick Answers
- What is the CVE explosion?
- The CVE explosion refers to the dramatic increase in Common Vulnerabilities and Exposures (CVEs) being discovered, largely accelerated by AI-assisted vulnerability hunting tools.
- How many CVEs were logged since September 16, 2024?
- More than 33,000 new CVEs have been logged since September 16, 2024.
- Who is Jerry Gamblin?
- Jerry Gamblin is the head of research at Empirical Security and founder of RogoLabs, which runs the CVE analysis project cve.icu.
- What did Jerry Gamblin say about CVEs?
- Jerry Gamblin said that more CVEs is not more vulnerability. It's more known vulnerability, which is mostly the system working.
- When was the article published?
- The article was published on September 19, 2026.
- Who are the authors of the article?
- The article was authored by Matt Burgess and Lily Hay Newman.
- What is the impact of AI on vulnerability discovery?
- AI has enabled faster identification of system flaws, significantly increasing the number of vulnerabilities discovered compared to previous manual methods.
- How many patches did Oracle release in July 2026?
- Oracle released 1,448 patches in July 2026.
Frequently Asked Questions
What does CVE stand for?
CVE stands for Common Vulnerabilities and Exposures, which is cybersecurity jargon for confirmed software flaws.
Why are more CVEs being reported now?
More CVEs are being reported because AI tools have made vulnerability discovery faster and more accessible to both professionals and amateur hackers.
What is the relationship between AI and cybersecurity according to experts?
Experts say that while AI can accelerate bug discovery, it also aids defenders. However, the rapid pace of discovery outpaces the ability to remediate issues quickly.
Source reference: https://www.wired.com/story/kernel-panic-ai-vulnerability-explosion/



Comments
Sign in to leave a comment
Sign InLoading comments...