Overview
- Security databases logged 45,207 vulnerabilities from January through late July 2026, a pace that could roughly double last year’s total.
- Researchers at VulnCheck attributed 1,061 flaws to AI-assisted discovery in H1 2026 and found 14 of those (about 1.3%) were exploited in the wild, a rate similar to other disclosed bugs.
- VulnCheck also reported the average time from public CVE publication to exploitation fell from about 120 days in 2025 to roughly 80 days in the first half of 2026, speeding the threat timeline for defenders.
- Major vendors are releasing far larger patch bundles, with Microsoft’s July update listing 622 vulnerabilities and Oracle’s July patch fixing 1,449, creating heavy operational strain for enterprise IT teams.
- Commercial cyber‑AI models rolled out in spring 2026 are being used by companies and some government agencies including the NSA, and experts warn that wider access to these dual‑use tools could accelerate offensive operations unless controls and defensive investments scale quickly.