More Than 45,000 Software Flaws Reported as AI Reshapes Cybersecurity

More Than 45,000 Software Flaws Reported as AI Reshapes Cybersecurity

More Than 45,000 Software Flaws Reported as AI Reshapes Cybersecurity

Image: Zulfugar Karimov/Unsplash

AI security tools are helping uncover more software flaws, creating new patching demands and potential offensive risks for enterprise IT teams.

Verfasst von
David Curry
David Curry
Jul 28, 2026

The number of software vulnerabilities being uncovered in 2026 is on pace to roughly double the total recorded in 2025, as AI tools become more effective at identifying cyber threats.

The National Vulnerability Database recorded 45,207 vulnerabilities between January and late July, a figure already approaching the total logged during all of 2025. At the current rate, this year is on track to record twice as many uncovered flaws.

The number of vulnerabilities being patched by major technology companies each month is also far higher than in comparable updates last year, according to reporting by Bloomberg. Oracle patched 1,449 vulnerabilities in its July update, up from 309 in the comparable update a year earlier. Microsoft, Google, and other major software providers have reported similar increases in the number of vulnerabilities being patched.

Concerns that AI could hand hackers a roadmap for breaking into vulnerable software have also not yet come to fruition, although many of the most advanced cyber tools remain outside public access. As more operators, including Google and Microsoft, launch their own cyber AI models and services, there is a risk that more bad actors will gain access to them.

Tech companies expand access to AI security models

Anthropic kickstarted the cyber AI market with the launch of Mythos to a select group of partners under its Glasswing initiative. OpenAI launched a similar cyber AI model a few weeks later, which experts believe is comparable to Mythos in sophistication.

Others are jumping on the bandwagon. Microsoft is launching its own security product, while Google has made one available to select partners.

These cyber AI services have been deployed by technology companies, large institutions, and governments to identify vulnerabilities in their own software. Mozilla was one of Mythos’ early partners and said in April that it had rapidly increased its vulnerability detection and patching through the tool.

Must-read security coverage

Advertisement

What security teams should do now

Some organizations, including the National Security Agency, are now using Mythos for offensive cyber planning. This opens the door for US adversaries to conduct similar offensive planning and vulnerability testing, particularly China, which subjected its geopolitical rival Taiwan to 2.6 million cyberattacks in 2025. Security experts warn that AI could increase the scale and speed of future cyber operations.

Cyber agencies linked to the Five Eyes intelligence-sharing alliance, which includes Australia, Canada, New Zealand, the UK, and the US, have said that the proliferation of AI cyber tools could transform the cyber landscape within months rather than years. They have warned that as cyber defense tools become more powerful, offensive cyber capabilities will also grow in sophistication and use, meaning businesses of all sizes will need stronger layers of protection.

Beyond bad actors and adversaries gaining access to offensive cyber tools, rogue AI may also pose a growing threat to businesses. As OpenAI revealed last week, rogue AI systems are becoming increasingly capable of escaping confinement and damaging the open web, with one of its unreleased cyber tools hacking the popular open-source platform Hugging Face. Many industry leaders have called for greater transparency around the cyber tools being developed and the risks they present, leaving businesses with little choice but to strengthen their defenses before these capabilities become more widely available.

For businesses, the rise in vulnerabilities being patched by major tech companies is no reason for complacency. As access to cyber AI models expands, offensive capabilities will grow, and defensive investment will need to keep pace.

Also read: How AI assistants could become the next major cybersecurity risk just by following the wrong instruction.

David Curry

David Curry is a tech journalist and analyst with more than a decade of experience covering the technology sector for established media outlets and research-driven publications. He has reported on the industry since the early 2010s, with a focus on B2B technology, data journalism, mobile apps and app markets, artificial intelligence, digital platforms, and emerging technologies. His work combines journalism, analysis, and industry research to help readers understand how technology trends develop, how digital markets evolve, and how businesses and consumers are affected by new platforms, products, and innovations. David’s coverage often explores the intersection of technology, business strategy, market data, and user behavior. David holds a BA from the University of Lincoln and a master’s degree in International Journalism from the University of Leeds. His academic background and years of reporting experience inform his clear, analytical approach to explaining complex technology topics for professional and general audiences.