Will it run?
Security

The vulnerability explosion is here while doomers look far out

By Desmond Okafor Clawpit staff
The vulnerability explosion is here while doomers look far out

While the AI community argues over doomsday scenarios of rogue models, a tsunami of software vulnerabilities is already flooding the industry — fueled by tools available today, including open-weight models. Security researchers report a sharp spike in bug discoveries over recent months, and the burden lands on IT teams and open-source maintainers already stretched thin. This wave isn't theoretical. It's happening now, with capabilities already in everyone's hands.

The numbers don't lie

Microsoft released 974 CVE patches this month, a new monthly record. Oracle pushed 1,448 patches in July this year versus just 309 in July 2025. Google Chrome packed 1,072 fixes into two June releases — more than the previous 23 major versions combined. And Mozilla reported in April that it found 271 Firefox vulnerabilities in a single bug-hunting sprint using Anthropic's Mythos model. The data adds up to a record-breaking pace on every front.

Year-over-year doubling

According to Jerry Gamblin, head of research at Empirical Security and founder of the cve.icu project, 66,401 vulnerabilities had been logged as of 16 September this year. On the same date last year the count stood at 33,512 — barely half. For comparison, all of 2022, the year OpenAI's first chatbot launched, saw 25,000 CVEs total. The jump isn't linear, and it overlaps with the wide availability of AI bug-finding tools.

Working system or time bomb

Gamblin doesn't think the hysteria is overblown, but he qualifies it: "More CVEs isn't more vulnerabilities, it's more known vulnerabilities, which is mostly the system working." The real fear, though, is that developers can't keep up with patches, users won't apply them in time, and attackers will use the same tools to find new weaknesses themselves. As the UK's National Cyber Security Center put it: "Just finding vulnerabilities doesn't improve your security in any way."

A fragile balance between attacker and defender

For now, researchers describe a delicate equilibrium: AI accelerates bug discovery, but it also helps defenders. Matthew Olney, threat intelligence lead at Cisco, explains that both sides — attackers and industry — are still figuring out exactly where to plug the technology in. The answer isn't clear, and the race is just starting.

Slowing down won't stop the wave

Any agreement or regulation that slows frontier model development might prevent a future existential scenario, but it won't put the genie back in the bottle. The tools flooding the CVE databases are already out there, in wide use, and the tsunami they've created isn't waiting for any political decision.