AI is uncovering software security flaws at a record pace
Vendors and AI tools found most flaws internally, while only 1.3% of AI-assisted discoveries were confirmed exploited, VulnCheck said.
- The U.S. National Vulnerabilities Database recorded 45,207 software flaws through late July, a volume largely driven by AI-powered tools enabling researchers to find and patch defects at accelerated scale.
- Despite fears that AI-assisted vulnerability discovery would empower attackers, a VulnCheck report Tuesday found that AI-discovered flaws are no more likely to be exploited than vulnerabilities found through traditional methods.
- Only 14 vulnerabilities, or 1.3%, have been confirmed as exploited in the wild, while Anthropic's Project Glasswing has seen little movement since April with few findings becoming published CVEs.
- Cybersecurity experts warn that attackers are accelerating their efforts, with the median time from vulnerability publication to exploitation dropping from 120 days in 2025 to 80 days during this year's first half.
- Attackers are increasingly targeting the expanding AI software stack, with AI products accounting for almost 6% of exploited vulnerabilities alongside network edge devices and content management systems.
13 Articles
13 Articles
AI-discovered vulnerabilities are barely being exploited
AI-discovered vulnerabilities are arriving at roughly twice last year’s rate. Almost none of them are being exploited. The US National Vulnerabilities Database recorded 45,207 software flaws between January and 27 July, already approaching the whole of 2025, which was itself a record. On that trajectory the year ends at roughly double the 2025 total, Bloomberg […] This story continues at The Next Web
AI-found bugs aren't proving any easier to exploit despite the hype
Anthropic's Project Glasswing may have uncovered tens of thousands of potential security flaws, but new research suggests AI-assisted vulnerability discovery has yet to produce the wave of real-world attacks many expected. In research shared with The Register, VulnCheck analyzed 1,061 publicly attributed AI-assisted vulnerability discoveries from Anthropic's Project Glasswing and the Berkeley Vulnerability Research Initiative, then cross-referen…
AI-assisted security tools are finding more bugs, but the threat level has not changed
AI systems like Anthropic’s Project Glasswing and Microsoft’s MDASH are aiding in the discovery of vulnerabilities, filling the ever-growing pool of defects that defenders have to address before exploitation occurs. Yet, through the first half of 2026, these vulnerabilities were no more or less likely to be exploited than all vulnerabilities disclosed during that period, VulnCheck said in a report Tuesday. Concerns remain high about AI-discover…
AI is uncovering software security flaws at a record pace
The number of software security vulnerabilities discovered in 2026 is on pace to roughly double the total reported in 2025, largely because AI has made it much faster to identify software flaws, Bloomberg reports. By late July, the U.S. National Vulnerabilities Database had already recorded more than 45,000 vulnerabilities, nearly matching the total for all of 2025, which was itself a record year. Major technology companies, including Oracle, M…
Vulnerabilities discovered using artificial intelligence have not yet led to a significant increase in real-world attacks, according to the company VulnCheck, which studied over a thousand cases in which AI helped identify potential software issues.
Coverage Details
Bias Distribution
- 60% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium








