Bloomberg reported on July 28 that AI is significantly accelerating the discovery of software vulnerabilities. According to current trends, the number of security vulnerabilities found in popular technology products in 2026 is expected to double compared to last year. AI has become both a "magnifying glass" for security teams and an "accelerator" for hackers.

From January this year to Monday of this week, the National Vulnerability Database in the United States has recorded 45,207 vulnerabilities, approaching the total number from last year—while 2025 itself already set a record for the database. A security vulnerability refers to a software flaw that could be exploited by hackers, allowing attackers to infiltrate computer systems for criminal or espionage activities.

Record Numbers of Vulnerabilities Reported by Tech Giants

Recent data disclosed by several tech giants have all set new records. In its July routine update, Oracle fixed 1,449 security vulnerabilities, a new high in the company's 49-year history, compared to just 309 in the same period last year. Microsoft disclosed 642 vulnerabilities in July, nearly five times the number from the same period last year; when updating Chrome, Google found and fixed 433 vulnerabilities, while there were only 11 in similar updates a year ago.

Gabrielle Bernadette-Shapiro, a distinguished AI research scientist at SentinelOne, said it is necessary to face a fact: these tools are enhancing people's ability to find software vulnerabilities. Doug Turner, director of Chrome engineering at Google, also pointed out that the scale and speed of vulnerability discovery have reached unprecedented levels, mainly due to advances in AI models and increased investment.

Vulnerability Surge but Attacks Not Synchronized, Hackers' Conversion Time Reduced to 24 Hours

Notably, the surge in discovered vulnerabilities has not yet been fully converted into actual attacks. The U.S. government's known exploited vulnerabilities list shows that although the number of vulnerabilities discovered this year has increased significantly, the number of actually exploited vulnerabilities has not risen. Data disclosed by technology companies also show that many new vulnerabilities were discovered by internal security teams using their own AI tools—of the 433 Chrome vulnerabilities found by Google in July, 401 came from internal reports.