The number of software vulnerabilities being uncovered in 2026 is on pace to roughly double the total recorded in 2025, as AI tools become more effective at identifying cyber threats.
The National Vulnerability Database recorded 45,207 vulnerabilities between January and late July, a figure already approaching the total logged during all of 2025. At the current rate, this year is on track to record twice as many uncovered flaws.
The number of vulnerabilities being patched by major technology companies each month is also far higher than in comparable updates last year, according to reporting by Bloomberg. Oracle patched 1,449 vulnerabilities in its July update, up from 309 in the comparable update a year earlier. Microsoft, Google, and other major software providers have reported similar increases in the number of vulnerabilities being patched.
Concerns that AI could hand hackers a roadmap for breaking into vulnerable software have also not yet come to fruition, although many of the most advanced cyber tools remain outside public access. As more operators, including Google and Microsoft, launch their own cyber AI models and services, there is a risk that more bad actors will gain access to them.
Tech companies expand access to AI security models
Anthropic kickstarted the cyber AI market with the launch of Mythos to a select group of partners under its Glasswing initiative. OpenAI launched a similar cyber AI model a few weeks later, which experts believe is comparable to Mythos in sophistication.
Others are jumping on the bandwagon. Microsoft is launching its own security product, while Google has made one available to select partners.
These cyber AI services have been deployed by technology companies, large institutions, and governments to identify vulnerabilities in their own software. Mozilla was one of Mythos’ early partners and said in April that it had rapidly increased its vulnerability detection and patching through the tool.
Must-read security coverage
- UK Police Convicts Pair in £5.5 Billion Bitcoin Launder Case
- Blackpoint Cyber vs. Arctic Wolf: Which MDR Solution is Right for You?
- How GitHub Is Securing the Software Supply Chain
- 8 Best Enterprise Password Managers
What security teams should do now
Some organizations, including the National Security Agency, are now using Mythos for offensive cyber planning. This opens the door for US adversaries to conduct similar offensive planning and vulnerability testing, particularly China, which subjected its geopolitical rival Taiwan to 2.6 million cyberattacks in 2025. Security experts warn that AI could increase the scale and speed of future cyber operations.
Cyber agencies linked to the Five Eyes intelligence-sharing alliance, which includes Australia, Canada, New Zealand, the UK, and the US, have said that the proliferation of AI cyber tools could transform the cyber landscape within months rather than years. They have warned that as cyber defense tools become more powerful, offensive cyber capabilities will also grow in sophistication and use, meaning businesses of all sizes will need stronger layers of protection.
Beyond bad actors and adversaries gaining access to offensive cyber tools, rogue AI may also pose a growing threat to businesses. As OpenAI revealed last week, rogue AI systems are becoming increasingly capable of escaping confinement and damaging the open web, with one of its unreleased cyber tools hacking the popular open-source platform Hugging Face. Many industry leaders have called for greater transparency around the cyber tools being developed and the risks they present, leaving businesses with little choice but to strengthen their defenses before these capabilities become more widely available.
For businesses, the rise in vulnerabilities being patched by major tech companies is no reason for complacency. As access to cyber AI models expands, offensive capabilities will grow, and defensive investment will need to keep pace.
Also read: How AI assistants could become the next major cybersecurity risk just by following the wrong instruction.