AI-assisted scanning pushes 2026 software vulnerability discoveries to roughly double 2025's record total
The US Vulnerabilities Database logged over 45,000 software flaws by late July, nearly matching all of 2025, as AI scanning speeds discovery. Oracle patched 1,449 vulnerabilities in July, up from 309 a year earlier. Microsoft logged 642, nearly 5x its year-ago total, per The Star
Software vulnerability discoveries are on pace to roughly double in 2026 compared with 2025, driven largely by AI-assisted scanning tools that let researchers and security teams find flaws faster and at greater scale. The US National Vulnerabilities Database had already logged more than 45,000 vulnerabilities by late July, nearly matching the total for all of 2025, which was itself a record year. Major technology companies are seeing the effect directly: Oracle patched a record 1,449 vulnerabilities in its July update, up from 309 during the same period last year, while Microsoft reported 642 security bugs in July, nearly five times its total from a year earlier. Google said 401 of the 433 flaws it disclosed were found internally through its own AI-assisted security operations. The surge cuts both ways. The same AI tools that help defenders find and patch flaws faster are also available to attackers, and researchers say the average time needed to build a working exploit from a disclosed vulnerability has fallen from 72 hours to just 24, narrowing the window security teams have to patch before an exploit appears in the wild.