cd /news/artificial-intelligence/ai-finding-twice-as-many-cyber-flaws… · home topics artificial-intelligence article
[ARTICLE · art-76227] src=businesstimes.com.sg ↗ pub= topic=artificial-intelligence verified=true sentiment=· neutral

AI finding twice as many cyber flaws in 2026 as it did in 2025

The number of software security flaws discovered in 2026 is on pace to roughly double the 2025 total, with 45,207 vulnerabilities recorded in the US National Vulnerabilities Database between January and July 27, approaching last year's all-time record. Oracle, Microsoft, and Google reported record-high patches in July, driven by increasingly capable AI systems, though exploited vulnerabilities have not risen, according to the US government's Known Exploited Vulnerabilities catalogue.

read3 min views1 publishedJul 28, 2026
AI finding twice as many cyber flaws in 2026 as it did in 2025
Image: Businesstimes (auto-discovered)

Digital security vulnerabilities recorded between January and Jul 27 stand at 45,207, nearing 2025’s total

[WASHINGTON] The number of software security flaws discovered in popular technology products in 2026 is on pace to roughly double the tally of vulnerabilities that surfaced in 2025, an explosion driven by increasingly capable artificial intelligence systems.

The US National Vulnerabilities Database, a repository of digital security holes, recorded 45,207 flaws between January and Monday (Jul 27), a count approaching the total number found in all of 2025.

2025 saw an all-time record for recorded vulnerabilities in that database.

Security vulnerabilities are flaws in software that can be exploited by a hacker, including to break into computer systems to commit crimes or carry out espionage.

Oracle said it patched 1,449 security vulnerabilities in its monthly July software update, an all-time record for the 49-year-old tech giant, while the same update in 2025 contained 309 fixes.

Microsoft disclosed 642 security bugs in July, another all-time high and nearly five times the count in July 2025.

Alphabet’s Google found and fixed 433 such bugs in a recent update to the Chrome browser versus 11 in an equivalent update in 2025.

“We have to come to the reckoning that these tools are increasing the ability of people to find vulnerabilities in software,” said Gabriel Bernadett-Shapiro, distinguished AI research scientist at the cybersecurity firm SentinelOne.

At Google, the “unprecedented scale and speed” of vulnerability discovery is a result of advances in AI models and a corresponding investment, Doug Turner, Chrome’s director of engineering, told Bloomberg.

Microsoft declined to comment. Oracle did not respond to a request for comment.

The surge in discovered vulnerabilities lends credence to the warnings governments and security firms have been issuing about the threat posed by hackers armed with powerful, new AI models.

A deeper look at the figures also reveals the limits of these worries.

There has been no rise in the number of exploited issues so far in 2026, despite the uptick in discovered flaws, according to the US government’s Known Exploited Vulnerabilities catalogue.

Internal security personnel at the technology firms are finding many of the new vulnerabilities with their own cyber-focused AI tools, according to their disclosures.

Of the 433 vulnerabilities in Chrome in July, 401 were “reported by Google” internally, according to the company.

“We just aren’t seeing the numbers to back up the doom and gloom prophets,” said Dustin Childs, head of threat awareness at the cybersecurity firm Trend Micro.

Frontier AI models accelerated their ability to discover software vulnerabilities in recent months, prompting anxiety about a surge in hackers exploiting those flaws.

Anthropic’s Mythos tool found thousands of software vulnerabilities in early testing, showcasing a new level of capability for cutting-edge AI models.

OpenAI has developed comparable tools. Officials at the National Security Agency have been impressed by the Anthropic model’s ability to find and exploit cybersecurity vulnerabilities, Bloomberg reported.

Microsoft on Monday released another AI security tool, known as MAI-Cyber-1-Flash, that it said will help software vulnerability management.

Hackers are also able to turn abstract vulnerabilities into working exploits, which can actually be used to breach a computer system, faster than ever.

The average time it took attackers to exploit vulnerabilities dropped from 72 hours in 2025 to just 24 hours in 2026, said Alexander Leslie, senior advisor at the cybersecurity firm Recorded Future.

OpenAI disclosed on Jul 21 its autonomous agents had breached another company, Hugging Face, in an incident that Bloomberg reported took hours, compared to the weeks it likely would have taken a human. BLOOMBERG

Decoding Asia newsletter: your guide to navigating Asia in a new global order. Sign up here to get Decoding Asia newsletter. Delivered to your inbox. Free.

Share with us your feedback on BT's products and services

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @us national vulnerabilities database 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/ai-finding-twice-as-…] indexed:0 read:3min 2026-07-28 ·