The cybersecurity impact of widely available artificial intelligence is already being felt through a rapid increase in known software flaws. While AI leaders debate whether to slow frontier model development, existing mainstream products and open-weight models are helping researchers find vulnerabilities at a scale that is putting additional pressure on security teams and open-source maintainers.

Recent patch and disclosure figures illustrate the change. Microsoft said it had issued patches for 974 CVEs so far this month, setting a new record. Oracle shipped 1,448 patches in July, compared with 309 in July 2025. Google Chrome’s 2 major releases in June contained 1,072 patches, exceeding the combined total from its previous 23 major releases.

Mozilla also said it identified 271 Firefox vulnerabilities during a single bug-hunting sprint that used Anthropic’s Mythos model. CVEs, short for common vulnerabilities and exposures, are confirmed software flaws recorded for security tracking and remediation.

CVE records rise sharply

Jerry Gamblin, head of research at Empirical Security and founder of RogoLabs, said cve.icu had recorded 66,401 CVEs by Wednesday this week. The project had logged 33,512 CVEs by September 16 last year, while its total for all of 2022 was 25,000.

The figures do not mean that every newly recorded CVE represents a new security failure caused by AI. Gamblin said a larger number primarily indicates that more vulnerabilities are known, which can also reflect the security process working as intended.

“I don’t think it’s overblown,” Gamblin said of the increase in vulnerability findings. He cautioned against treating the raw CVE total itself as the harm, saying that “More CVEs is not more vulnerability. It's more known vulnerability, which is mostly the system working.”

Discovery is faster than remediation

The central concern is whether developers and users can fix flaws quickly enough after they are found. Security teams already face slow patch adoption and limited investment, while volunteers maintain much of the open-source software used across the technology industry.

A larger pool of researchers and attackers using AI could increase the discovery of novel vulnerabilities. If patching capacity does not grow at the same pace, organisations may struggle to address known problems before they are exploited.

Britain’s National Cyber Security Center has warned that “Just finding vulnerabilities does nothing to improve your security.” The statement highlights the difference between identifying a flaw and removing the risk it creates.

Defenders are using AI too

Researchers say the current balance has not yet clearly shifted entirely in favour of attackers. Security teams and industry are also assessing where AI can assist with finding, analysing and responding to vulnerabilities.

“Actors, just like industry, are trying to figure out, ‘where do I use AI?’” said Matthew Olney, director of threat intelligence at Cisco Systems.

That balance remains fragile because vulnerability discovery can be expanded through computing resources, while remediation still depends heavily on people. Gamblin summarised the pressure this way: “Discovery scales with compute. Remediation scales with people—and people are the part you can't buy more of in a quarter.”

Why an AI slowdown would not reverse the trend

An industry agreement or regulation aimed at slowing frontier AI development could affect future model progress, but it would not remove the capabilities already available in mainstream AI products and open-weight models. Those existing tools are already being used in vulnerability research.

The result is a cybersecurity challenge that is developing independently of any future decision about frontier AI. The immediate issue is whether security teams, software developers and maintainers can keep pace with the volume of findings and the work required to fix them.

Conclusion

AI has accelerated the discovery of software vulnerabilities, while the harder task of remediation remains tied to limited human capacity. The growing CVE totals show the scale of the workload facing defenders, but the security impact will depend on how quickly known flaws are patched and addressed.

Frequently Asked Questions

Q. How many CVEs had cve.icu recorded by Wednesday this week?

cve.icu had recorded 66,401 CVEs by Wednesday this week, according to Jerry Gamblin.

Q. How many patches did Microsoft issue this month?

Microsoft said it had issued patches for 974 CVEs so far this month.

Q. How many patches did Oracle ship in July?

Oracle shipped 1,448 patches in July, compared with 309 in July 2025.

Q. How did Google Chrome’s June releases compare with earlier releases?

Google Chrome’s 2 major June releases included 1,072 patches, more than the combined number in its previous 23 major releases.

Q. How many Firefox vulnerabilities did Mozilla find using Mythos?

Mozilla said it found 271 Firefox vulnerabilities during one bug-hunting sprint using Anthropic’s Mythos model.

Q. Does a higher CVE count automatically mean more vulnerability?

No. Jerry Gamblin said a higher count means more known vulnerability and can indicate that the security process is identifying flaws.

Q. What is the main cybersecurity concern linked to AI-assisted discovery?

The concern is that developers and users may not be able to patch vulnerabilities quickly enough as more flaws are identified.

Q. Can an AI slowdown stop the current rise in vulnerability findings?

An AI slowdown would not stop the capabilities already available in mainstream AI products and open-weight models, which are already being used for vulnerability research.