The cybersecurity landscape is experiencing a significant surge in reported software vulnerabilities, a phenomenon that experts attribute to the increasing use of artificial intelligence in bug discovery. This "vulnerability explosion" is already underway, driven by broadly available AI tools, even as discussions continue about a potential slowdown in AI development.
Recent data highlights this trend. Microsoft confirmed last week that it released patches for 974 Common Vulnerabilities and Exposures (CVEs) in the current month, setting a new record for the company. Oracle's July patch release included 1,448 fixes, a substantial increase compared to 309 in July 2025. Google Chrome's two major version releases in June collectively contained 1,072 patches, surpassing the total number of vulnerability fixes in the preceding 23 major releases combined. Mozilla also reported in April that a single bug-hunting sprint using Anthropic’s Mythos AI model identified 271 vulnerabilities in Firefox.
Overall, the number of recorded CVEs has seen a dramatic increase. As of Wednesday this week, 66,401 CVEs have been logged. This figure is nearly double the 33,512 CVEs recorded by September 16 of the previous year. For the entirety of 2022, the year OpenAI launched its initial version of ChatGPT, approximately 25,000 CVEs were recorded.
While some experts initially debated whether AI's impact on cybersecurity would be catastrophic or merely amplify existing challenges, the escalating numbers suggest a growing consensus on the significance of this trend. The head of research at Empirical Security and founder of RogoLabs, which operates the CVE analysis project cve.icu, stated that the apparent explosion in vulnerability findings is not overblown. He emphasized that an increased number of CVEs indicates more known vulnerabilities, which can be seen as the system working to identify flaws.
However, concerns persist that the rapid pace of vulnerability discovery could outstrip the ability of developers to issue patches and software users to implement them promptly. This imbalance could potentially lead to an increase in cyberattacks, as more attackers leverage AI to discover novel vulnerabilities. The British National Cyber Security Center has noted that simply finding vulnerabilities does not inherently improve security.
For the time being, many researchers observe a delicate balance between AI accelerating bug discovery and AI aiding defensive measures. Threat intelligence directors note that both malicious actors and the cybersecurity industry are actively exploring how to best utilize AI.
Despite any potential future AI slowdowns, whether through regulation or industry agreements, the current wave of vulnerability discoveries driven by existing AI tools is already here. The challenge lies in the disparity between the scalability of discovery, which can be enhanced with computational power, and the scalability of remediation, which relies on human resources that cannot be easily expanded.






