Digital security vulnerabilities recorded between January and Jul 27 stand at 45,207, nearing 2025’s total
[WASHINGTON] The number of software security flaws discovered in popular technology products in 2026 is on pace to roughly double the tally of vulnerabilities that surfaced in 2025, an explosion driven by increasingly capable artificial intelligence systems.
The US National Vulnerabilities Database, a repository of digital security holes, recorded 45,207 flaws between January and Monday (Jul 27), a count approaching the total number found in all of 2025.
2025 saw an all-time record for recorded vulnerabilities in that database.
Security vulnerabilities are flaws in software that can be exploited by a hacker, including to break into computer systems to commit crimes or carry out espionage.
Oracle said it patched 1,449 security vulnerabilities in its monthly July software update, an all-time record for the 49-year-old tech giant, while the same update in 2025 contained 309 fixes.
Microsoft disclosed 642 security bugs in July, another all-time high and nearly five times the count in July 2025.
Alphabet’s Google found and fixed 433 such bugs in a recent update to the Chrome browser versus 11 in an equivalent update in 2025.
“We have to come to the reckoning that these tools are increasing the ability of people to find vulnerabilities in software,” said Gabriel Bernadett-Shapiro, distinguished AI research scientist at the cybersecurity firm SentinelOne.
At Google, the “unprecedented scale and speed” of vulnerability discovery is a result of advances in AI models and a corresponding investment, Doug Turner, Chrome’s director of engineering, told Bloomberg.
Microsoft declined to comment. Oracle did not respond to a request for comment.
The surge in discovered vulnerabilities lends credence to the warnings governments and security firms have been issuing about the threat posed by hackers armed with powerful, new AI models.
A deeper look at the figures also reveals the limits of these worries.
There has been no rise in the number of exploited issues so far in 2026, despite the uptick in discovered flaws, according to the US government’s Known Exploited Vulnerabilities catalogue.
Internal security personnel at the technology firms are finding many of the new vulnerabilities with their own cyber-focused AI tools, according to their disclosures.
Of the 433 vulnerabilities in Chrome in July, 401 were “reported by Google” internally, according to the company.
“We just aren’t seeing the numbers to back up the doom and gloom prophets,” said Dustin Childs, head of threat awareness at the cybersecurity firm Trend Micro.
Frontier AI models accelerated their ability to discover software vulnerabilities in recent months, prompting anxiety about a surge in hackers exploiting those flaws.
Anthropic’s Mythos tool found thousands of software vulnerabilities in early testing, showcasing a new level of capability for cutting-edge AI models.
OpenAI has developed comparable tools. Officials at the National Security Agency have been impressed by the Anthropic model’s ability to find and exploit cybersecurity vulnerabilities, Bloomberg reported.
Microsoft on Monday released another AI security tool, known as MAI-Cyber-1-Flash, that it said will help software vulnerability management.
Hackers are also able to turn abstract vulnerabilities into working exploits, which can actually be used to breach a computer system, faster than ever.
The average time it took attackers to exploit vulnerabilities dropped from 72 hours in 2025 to just 24 hours in 2026, said Alexander Leslie, senior advisor at the cybersecurity firm Recorded Future.
OpenAI disclosed on Jul 21 its autonomous agents had breached another company, Hugging Face, in an incident that Bloomberg reported took hours, compared to the weeks it likely would have taken a human. BLOOMBERG
Decoding Asia newsletter: your guide to navigating Asia in a new global order. Sign up here to get Decoding Asia newsletter. Delivered to your inbox. Free.
Share with us your feedback on BT's products and services