The count of security defects identified in mainstream tech products during 2026 is projected to approximately double the number recorded in 2025. The U.S. National Vulnerabilities Database, which tracks digital security holes, has recorded 45,207 vulnerabilities from January through late July - already close to the figure for all of last year, which itself was a record. Security flaws are defects in software that hackers can use to break into systems for crimes or spying.
Oracle Corp. disclosed it fixed a staggering 1,449 bugs in its July patch release, the highest number ever for the 49-year-old firm. In the comparable update from the prior year, Oracle had fixed 309 bugs. In July, Microsoft disclosed 642 security issues, setting a new record and representing nearly five times the number from the same month in 2025. Alphabet Inc.'s Google fixed 433 bugs in a recent Chrome update, compared with 11 in the equivalent update a year earlier.
Gabriel Shapiro, a distinguished AI research scientist at SentinelOne Inc., remarked, "These tools are increasing the ability of people to find vulnerabilities in software."
Doug Turner, the director of engineering for Chrome, told Bloomberg that Google's "unprecedented scale and speed" in finding vulnerabilities comes from AI model improvements and related investment.
Get the market news that matters in a five-minute read with Market Briefs, our free daily newsletter
The increase supports warnings from governments and security firms about hackers armed with advanced AI. Yet, data from the U.S. government's Known Exploited Vulnerabilities catalog reveals that the number of exploited vulnerabilities has not risen this year, even though more flaws are being discovered. Many of the new flaws are found internally by tech firms themselves. Google reported that 401 of the 433 Chrome vulnerabilities in August were identified by its own security teams.
The surge in vulnerability counts - from Oracle's 1,449 fixed bugs to Google's 433 Chrome flaws - reflects a broader trend where AI-assisted testing is outpacing traditional manual methods. Security teams are now leaning on AI to both find and fix defects, creating a new arms race between discovery and exploitation.
According to Trend Micro's threat awareness lead, Dustin Childs, "We just aren't seeing the numbers to back up the doom and gloom prophets."
The AI Arms Race in Cybersecurity
This escalation in vulnerability discovery highlights a fundamental shift in cybersecurity: AI-powered tools can now scan entire codebases in minutes, tasks that previously required weeks of manual effort. As a result, the number of reported vulnerabilities has skyrocketed, but the low exploitation rate suggests defenders are also leveraging AI to patch faster. However, the sheer volume of patches can lead to "patch fatigue" among IT teams, potentially leaving some systems unpatched. The median time to exploit has dropped to 24 hours, putting pressure on organizations to prioritize updates.
This dramatic increase in vulnerability discovery is largely attributed to the integration of AI into security testing pipelines. Companies like Oracle, Microsoft, and Google have invested heavily in machine learning models that can automatically scan code for weaknesses, often uncovering flaws that manual reviews would miss. This shift has led to an unprecedented volume of patches, but also raises questions about whether the overall security posture is improving or merely generating more noise.
The situation creates a double-edged dynamic: while AI helps companies patch holes faster, the sheer volume can overwhelm security teams and contribute to "patch fatigue" among users. Nevertheless, the actual exploitation rate remains low, suggesting that defensive AI is keeping pace with the increased discovery.
Alexander Leslie, a senior advisor at Recorded Future Inc., reported that the median time for attackers to turn a discovered flaw into an exploit fell from 72 hours in 2025 to merely 24 hours in 2026.
Join Market Briefs, our free daily newsletter, for a quick daily rundown of the markets
