---
title: "AI Is Finding Software Vulnerabilities Twice as Fast — And 2026 Is Breaking Every Record"
type: "News"
locale: "en"
url: "https://longbridge.com/en/news/294016957.md"
description: "AI-driven discovery is causing software vulnerabilities to double in 2026 compared to 2025. Major tech firms like Oracle, Microsoft, and Google reported record-breaking vulnerability counts in July 2026, with increases up to 39-fold for some products. While AI accelerates the identification and patching of latent risks, it also shrinks the window for attackers to exploit them, creating a massive patching burden for organizations."
datetime: "2026-07-28T05:59:10.000Z"
locales:
  - [zh-CN](https://longbridge.com/zh-CN/news/294016957.md)
  - [en](https://longbridge.com/en/news/294016957.md)
  - [zh-HK](https://longbridge.com/zh-HK/news/294016957.md)
---

# AI Is Finding Software Vulnerabilities Twice as Fast — And 2026 Is Breaking Every Record

The number of software security vulnerabilities being discovered in major technology products is on track to double in 2026 compared to 2025, driven almost entirely by the accelerating capability of artificial intelligence systems to detect flaws at a speed and scale no human security team could match. The figures emerging from the U.S. National Vulnerability Database and individual company disclosures this month are not incremental — they represent a step change in the volume of known vulnerabilities entering the security ecosystem simultaneously.

## **The numbers are unprecedented**

According to the U.S. National Vulnerability Database, 45,207 vulnerabilities were recorded between January and late July 2026 — nearly reaching the total recorded across the entire year of 2025, with months still remaining. Last year itself set the highest vulnerability count ever recorded. 2026 is on course to shatter that record by a significant margin.

The scale becomes clearer when broken down by company. Oracle's July monthly software update patched 1,449 security vulnerabilities — a record high for a single update cycle, and nearly five times the 309 fixes included in the equivalent update one year earlier. Microsoft disclosed 642 security vulnerabilities in July, also a record, representing almost five times the figure from the same period in 2025. Google identified and fixed 433 vulnerabilities in its most recent Chrome browser update — compared to just 11 in the equivalent update a year ago, a 39-fold increase in a single annual cycle.

## **AI is the primary driver**

The common thread across all of these figures is artificial intelligence. Security researchers and engineering teams at major technology companies have increasingly integrated AI tools into their vulnerability discovery workflows — and those tools are finding flaws that years of human review had not surfaced.

"We must acknowledge that these tools are enhancing people's ability to discover software vulnerabilities," said Gabriel Shapiro, Distinguished AI Research Scientist at cybersecurity firm SentinelOne.

Doug Turner, Engineering Director at Google Chrome, was more direct about the scale of the shift, stating that vulnerabilities are being discovered at an "unprecedented scale and speed" as a direct result of advances in AI models and the corresponding investment being made in deploying them across security research operations.

The implication is significant. Many of the vulnerabilities now being disclosed were not created recently — they existed in software that had been in production for years or decades, undetected by conventional security review processes. AI is surfacing a backlog of latent risk that has been accumulating inside widely deployed technology products, making it visible for the first time.

## **A double-edged reality**

The surge in discovered vulnerabilities is, in one sense, good news. A vulnerability that is found and patched is a vulnerability that cannot be exploited — and the acceleration of discovery means that flaws which might previously have gone undetected for years are being identified and remediated faster than ever before.

But the same AI capabilities that are powering defensive vulnerability research are available to attackers conducting offensive security research. The gap between a vulnerability being discovered and that same vulnerability being weaponised is shrinking as AI tools accelerate both sides of that process. A landscape in which tens of thousands of new vulnerabilities are being disclosed annually creates an enormous and continuously expanding patching burden for every organisation that relies on the software those vulnerabilities affect.

The record figures from Oracle, Microsoft and Google in July 2026 alone represent thousands of individual security decisions that enterprises, government agencies and individual users must now make — which patches to prioritise, which systems are most exposed and how quickly remediation can realistically be completed across complex and interconnected technology environments.

## **What this means going forward**

The trajectory suggests 2026 will not be an outlier. As AI systems continue to improve and their deployment in security research becomes more systematic, the annual rate of vulnerability discovery is likely to remain elevated — potentially permanently. The National Vulnerability Database and the patch cycles of major technology vendors are being reshaped by a technological shift that is still in its early stages.

For security teams, the practical consequence is a patching workload that is growing faster than the workforce available to manage it — reinforcing the case for AI-assisted triage and remediation tools that can help organisations prioritise and act on vulnerability disclosures at a speed that manual processes cannot sustain.

The same AI that is discovering the vulnerabilities may ultimately be the most effective tool for managing the consequences of finding them.

**_Sources_**

_U.S. National Vulnerability Database, vulnerability count data January to July 2026. Oracle July 2026 software update patch disclosure. Microsoft July 2026 security vulnerability disclosure. Google Chrome vulnerability disclosure, most recent update cycle, 2026. Gabriel Shapiro, Distinguished AI Research Scientist, SentinelOne, statement July 2026. Doug Turner, Engineering Director, Google Chrome, statement July 2026. ME News reporting, July 28, 2026._

### Related Stocks

- [ORCL.US](https://longbridge.com/en/quote/ORCL.US.md)
- [ORCX.US](https://longbridge.com/en/quote/ORCX.US.md)
- [ORCS.US](https://longbridge.com/en/quote/ORCS.US.md)
- [ORAC.US](https://longbridge.com/en/quote/ORAC.US.md)
- [ORCU.US](https://longbridge.com/en/quote/ORCU.US.md)
- [MSFT.US](https://longbridge.com/en/quote/MSFT.US.md)
- [GOOGL.US](https://longbridge.com/en/quote/GOOGL.US.md)
- [GOOG.US](https://longbridge.com/en/quote/GOOG.US.md)
- [S.US](https://longbridge.com/en/quote/S.US.md)
- [ORCL-D.US](https://longbridge.com/en/quote/ORCL-D.US.md)

## Related News & Research

- [Oracle Is One Step From Junk—Can It Afford the AI Boom?](https://longbridge.com/en/news/293336061.md)
- [PNC Financial Services Group Inc. Boosts Stake in Alphabet Inc. $GOOG](https://longbridge.com/en/news/293817915.md)
- [The $7 Billion Reason Oracle Stock Is in Focus Today](https://longbridge.com/en/news/293785114.md)
- [Monday.com is the latest tech company to blame AI for layoffs — here are 20 others](https://longbridge.com/en/news/293832427.md)
- [08:41 ETTrevera, Inc. Launches Advanced Project Enablement Capabilities](https://longbridge.com/en/news/293934591.md)