A surge in software vulnerabilities found with the help of artificial intelligence is straining the information technology and security teams that must address them, according to newly compiled industry figures. Empirical Security research chief Jerry Gamblin, who founded the CVE analysis project cve.icu, recorded 66,401 CVEs as of Wednesday of this week, a category of confirmed software flaws. By September 16 of last year the project had logged 33,512, roughly half the current count, and for all of 2022, the year OpenAI released its first ChatGPT, it recorded 25,000.

Vendors are reporting record patch volumes. Microsoft said last week it had issued fixes for 974 CVEs so far this month, a new high. Oracle shipped 1,448 patches in July, compared with 309 in July 2025, and Google's two major Chrome releases in June carried 1,072 patches, more than the total shipped across the prior 23 big releases combined. Mozilla said in April that it found 271 vulnerabilities in Firefox during a single bug-hunting sprint using Anthropic's Mythos model.

Researchers are split on what the trend means. Gamblin said he does not consider the discovery explosion overblown, but disputed the framing that a higher count is itself the damage, describing more CVEs as more known vulnerabilities rather than more vulnerabilities, and mostly the system working. The concern raised by others is that discovery will outpace patching, that users will fall behind on fixes, and that attackers using AI to find flaws on their own will drive escalating cyberattacks. Britain's National Cyber Security Center has said that merely finding vulnerabilities does nothing to improve security.

Some researchers describe at least a fragile balance between AI-assisted bug discovery and AI-assisted defense. Matthew Olney, director of threat intelligence at Cisco Systems, said actors across the board, industry included, are trying to determine where to apply AI. An AI slowdown, whether through regulation or an industry accord, might avert a mass-casualty event, but it cannot halt the vulnerability wave already produced by existing AI tools, the reporting indicates.

The strain lands hardest on thinly resourced security operations and on the volunteers who maintain critical open source software, which underpins both corporate and consumer systems in the United States and elsewhere. Gamblin summarized the mismatch by saying discovery scales with computing power while remediation scales with people, and people cannot simply be purchased in greater numbers within a quarter. AI doomers have recently shifted their focus from a software vulnerability apocalypse toward the risk of rogue AI causing mass human deaths in the next decade, as AI leaders weigh a cooperative slowdown on frontier model development.

More cybersecurity news from TechManNews.