A record 974 CVEs were patched by Microsoft alone in a single month last week.
AI doomers have recently swapped one worst-case scenario for another. The focus has shifted from a potential software vulnerability apocalypse to the possibility of rogue artificial intelligence causing mass human death within the next decade. While industry leaders discuss a cooperative slowdown on frontier model development, a different cybersecurity shift has already arrived. This change stems from existing, broadly available capabilities in mainstream AI products, including open weight models.
A tidal wave of vulnerabilities uncovered using AI has accelerated in recent months. This surge piles more pressure on under-resourced IT and security teams and strains volunteers who maintain crucial open source software. Researchers found and disclosed a vast array of vulnerabilities before the rise of AI-enhanced bug hunting, but the recent increase is clear.
Microsoft issued patches for 974 CVEs so far this month, setting a new record. Oracle shipped 1,448 patches in July, a jump from 309 in July 2025. Google Chrome’s two major version releases in June included 1,072 patches, a figure that exceeds all vulnerability fixes shipped in the prior 23 big releases combined. Mozilla found 271 vulnerabilities in Firefox during one bug hunting sprint in April using Anthropic‘s Mythos model.
Across the board, there have been 66,401 CVEs recorded as of Wednesday this week, according to Jerry Gamblin. Gamblin is the head of research at Empirical Security and founder of RogoLabs, which runs the CVE analysis project cve.icu. By September 16 last year, cve.icu had logged a total of 33,512 CVEs, almost half the current total. For all of 2022, the year OpenAI launched its first version of ChatGPT, cve.icu recorded 25,000 CVEs.
Among both security and AI researchers, experts have been divided about whether this spike and other impacts of AI on cybersecurity will be catastrophic or instead magnify existing dynamics and challenges. Some have pointed out that slow patch adoption and lagging investment in cybersecurity broadly already gave attackers many advantages that led to hacking disasters before the rise of AI. But as vulnerability discovery numbers have continued to rise, and the discussion has become less theoretical, the two sides have seemed to move a bit closer.
“I don’t think it’s overblown,” Gamblin says of the apparent explosion in vulnerability findings across the industry. “What I would push back on is the idea that a bigger number is itself the harm. More CVEs is not more vulnerability. It’s more known vulnerability, which is mostly the system working.”
The fear is that vast vulnerability discovery will mean developers getting outpaced on patching, software users who can’t patch fast enough, and an array of escalating cyberattacks fueled by more attackers discovering novel vulnerabilities on their own using AI. As Britain’s National Cyber Security Center puts it, “Just finding vulnerabilities does nothing to improve your security.”
For now, many researchers tell us that there is at least a tenuous balance between AI accelerating bug discovery and AI aiding defenders. “Actors, just like industry, are trying to figure out, ‘where do I use AI?'” says Matthew Olney, director of threat intelligence at Cisco Systems.
As the situation continues to evolve, an AI slowdown of whatever form—be it regulation or an industry accord—could perhaps prevent AI from carrying out a mass human extermination event, but it cannot stop the vulnerability tsunami that has already arrived as a result of existing AI tools.
As RogoLabs Gamblin puts it, “Discovery scales with compute. Remediation scales with people—and people are the part you can’t buy more of in a quarter.”
What it means
For the people making things, the practical change is a race against time. Software updates are arriving faster than teams can apply them. This leaves systems exposed longer, increasing the chance that an attacker will exploit a known flaw before a fix is deployed. The volume of work has outstripped the number of people available to do it.




