AI is finding twice as many software flaws. Almost none get exploited.
Back to Home
tech

AI is finding twice as many software flaws. Almost none get exploited.

July 28, 202635 views2 min read

AI is discovering software vulnerabilities at twice the rate of last year, but most are not being exploited, raising questions about the cybersecurity industry's response.

AI is revolutionizing vulnerability detection in software, but the path from discovery to exploitation remains a critical gap.

Recent data from the US National Vulnerabilities Database reveals a striking trend: AI-powered tools are identifying software flaws at a rate nearly double that of last year. As of July 27, 2026, the database had logged 45,207 vulnerabilities—already surpassing the total for all of 2025, which was itself a record-breaking year for software flaws. If current trends continue, 2026 could see a total that is double that of 2025, highlighting the growing complexity and scale of cybersecurity challenges.

AI's Role in Discovery

Organizations like Anthropic, with tools such as Claude and Mythos, are leading the charge in AI-assisted vulnerability detection. These systems are capable of scanning vast codebases and identifying potential security flaws in a fraction of the time it would take human experts. According to reports, AI tools are not only discovering vulnerabilities faster but also with greater accuracy. However, the real test lies in whether these discoveries translate into actionable security improvements.

The Exploitation Gap

Despite the surge in AI-generated vulnerability reports, the majority of these flaws are not being exploited in the wild. This suggests that while AI is a powerful tool for detection, the cybersecurity ecosystem still struggles with timely patching and remediation. The gap between discovery and exploitation is a key area for improvement, as unpatched vulnerabilities remain a prime target for malicious actors. Experts are calling for better integration of AI findings into existing security workflows to ensure that newly discovered flaws don’t become future attack vectors.

In conclusion, AI’s contribution to vulnerability detection marks a significant leap forward in cybersecurity. However, to fully realize its potential, the industry must bridge the gap between detection and defense to ensure that AI's findings are not just noticed but acted upon.

Source: TNW Neural

Related Articles