Infrastructure

Wired says AI-assisted bug hunting has pushed this year's CVE total to 66,401, up from 33,512 on the same date in 2025

September 19, 2026 at 4:20 AM PT

Wired Kernel Panic newsletter illustration for the story on AI-assisted vulnerability discovery

Image: Wired

Why it mattersDiscovery scales with compute and remediation scales with people, so a team sized against last year's patch load is now sorting a stream that has almost doubled in the same nine months.

Wired's Matt Burgess and Lily Hay Newman opened their new Kernel Panic newsletter on 19 September with a set of numbers on 2026 vulnerability disclosures. Jerry Gamblin, head of research at Empirical Security and founder of the CVE analysis project cve.icu, told them there were 66,401 CVEs recorded as of 17 September. By the same day in 2025, cve.icu had logged 33,512. The full year 2022, the year ChatGPT launched, ran to 25,000.

What each big vendor patched

Microsoft said last week it has issued patches for 974 CVEs so far this month, a new record for the company. Oracle shipped 1,448 patches in its July update, against 309 in July 2025. Google Chrome's two major version releases in June included 1,072 patches together, more than the vulnerability fixes across the prior 23 big releases combined. Mozilla said in April it found 271 Firefox vulnerabilities during one bug hunting sprint that used Anthropic's Mythos model.

What the researchers say the number does and does not mean

Gamblin told Wired the spike is real but not itself the harm: "More CVEs is not more vulnerability. It's more known vulnerability, which is mostly the system working." Britain's National Cyber Security Centre, which Wired quotes for the counterpoint, puts the risk plainly: "Just finding vulnerabilities does nothing to improve your security." Matthew Olney, director of threat intelligence at Cisco Systems, told the reporters that attackers and defenders are both working out where AI helps them, and it is not yet clear which side gains more.

The line the piece ends on comes from Gamblin: "Discovery scales with compute. Remediation scales with people, and people are the part you can't buy more of in a quarter." If a security team was sized against last year's disclosure rate, this year's queue is 66,401 against 33,512 at the same date, so the same weekly triage cadence is now processing a stream 98 percent larger than the one it sized against nine months ago. Every dependency in a service inherits that queue, so a triage step that assumed a stable weekly patch load now has to sort a stream that grows with whatever bug hunting model the ecosystem's researchers have pointed at it this quarter. Anthropic's Mythos found 271 Firefox flaws in one sprint. The same tool run against your own codebase will report faster than a human team can read the reports, and the fix work still has to be done by that team.

Source

Reported by: Wired

This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.

More from AI News

Anthropic says most malicious Claude use it caught this year ran with the AI in direct control of the attack

Anthropic's September 2026 threat report says a majority of the malicious Claude operations it disrupted this year ran with AI in direct control, and it names Russian, Chinese and criminal groups it detected between December 2025 and August 2026.

Source: Hacker NewsInfrastructure

Proofpoint says four groups are sharing one Chrome exploit kit, and the patches were released in the last 24 hours

Proofpoint says four hacking groups have been using the same three-bug exploit kit against Chromium browsers and Windows, and links the pace to AI-assisted exploit development.

Source: PressInfrastructure

Microsoft patches a record 972 vulnerabilities in September, and one of them is triggered by SQL Copilot

Microsoft's September patch release fixes a record 972 vulnerabilities, 112 of them critical, including a SQL Server bug reached through SQL Copilot and two Windows zero days.

Source: PressInfrastructure