AI-assisted bug hunting drives record surge in software vulnerabilities
Wired's new Kernel Panic newsletter documents a sharp rise in disclosed CVEs as AI tools accelerate vulnerability discovery across major software vendors.
What to know
- Disclosed CVEs in 2026 have nearly doubled the pace of 2025, reaching 66,401 by mid-September versus 33,512 a year earlier.
- Major vendors — Microsoft, Oracle, Google Chrome, Mozilla — all report record or sharply elevated patch volumes tied to AI-assisted bug hunting.
- Researchers are split on whether the surge signals a genuine security crisis (patch teams outpaced, attackers using AI to find novel flaws) or mainly reflects healthy, more thorough vulnerability disclosure.
- The trend is presented as a near-term, already-occurring AI risk, distinct from the more speculative long-term 'rogue AI' scenarios prompting talk of a development slowdown among AI labs.
Jerry Gamblin Head of research, Empirical Security; founder of RogoLabs (cve.icu)Lily Hay Newman Wired security reporter, co-author of Kernel Panic newsletterMatt Burgess Wired security reporter, co-author of Kernel Panic newsletterMicrosoft Software vendorOracle Software vendorMozilla Software vendor (Firefox)
How it unfolded 2 developments, newest first · click a bar or a number to jump articlesposts
-
2
Story circulates widely via social reposts
The Kernel Panic article was reshared across Mastodon/Flipboard accounts including Top Stories in Tech, Tech Longreads, and PrivacyDigest, spreading the vulnerability-explosion framing further.
“I don't think it's overblown…”
— Jerry Gamblin, Head of research, Empirical Security · source - 1 day quiet
-
1
Wired launches Kernel Panic newsletter framing the vulnerability surge
Wired's Lily Hay Newman and Matt Burgess published the inaugural edition of their security newsletter arguing that an AI-driven vulnerability explosion is already underway, even as AI leaders discuss slowing frontier model development over separate, longer-term risks.
“AI doomers have recently traded one worst-case scenario for another, putting aside a potential software vulnerability apocalypse to focus on the possibility of rogue AI causing mass human death in the next decade.”
— Wired (Kernel Panic newsletter) -
first by wired.com, 4d ago
-
-
background
Total CVEs recorded in 2026 reach 66,401, nearly double 2025's pace — Jerry Gamblin of Empirical Security/RogoLabs, who runs the CVE tracking project cve.icu, reported 66,401 CVEs recorded so far this year, versus 33,512 by the same date in 2025 and 25,000 for all of 2022.
-
background
Microsoft sets monthly record with patches for 974 CVEs — Microsoft said it issued patches for 974 CVEs in the month, described as a new record for the company.
-
background
Oracle's July patch count jumps nearly fivefold year over year — Oracle shipped 1,448 patches in July 2026, compared with 309 in July 2025.
-
background
Chrome releases include more patches than prior 23 combined — Google Chrome's two major version releases in June included 1,072 patches, exceeding the total from the previous 23 major releases combined.
-
background
Mozilla finds 271 Firefox bugs using Anthropic's Mythos model — Mozilla disclosed that it found 271 vulnerabilities in Firefox during a single bug-hunting sprint using Anthropic's Mythos model.