More Terrifying Than Runaway AI: The Tsunami of AI-Generated Vulnerabilities Has Arrived

09/20 2026 460

Stop Freaking Out About the AI Apocalypse—For Now.

Recently, AI doomsday enthusiasts have shifted their anxiety to a new track.

Instead of fixating on the old script of a software vulnerability meltdown, they’re collectively fretting over one thing: In the next decade, runaway AI will likely trigger large-scale human safety incidents.

Just as industry leaders are stepping up to slow down the development pace of cutting-edge large models and collectively cool off the hype, a seismic shift in cybersecurity has already quietly unfolded. There’s no need to wait for future super-powered AI—mainstream AI tools and open-source models readily available today have already overhauled the cybersecurity offensive-defensive landscape.

In recent months, AI’s ability to uncover software vulnerabilities has gone into overdrive, with the number of disclosed vulnerabilities surging like a tsunami. This has pushed already understaffed corporate IT and security teams to their limits, while volunteers silently maintaining core open-source software are gasping for breath.

Image Source: Generated by Doubao AI

Let’s be honest: Before AI-driven vulnerability hunting became mainstream, security researchers were already on the lookout for flaws. But this year’s surge is unprecedentedly extreme.

Microsoft dropped a bombshell last week: It batch-patched 974 CVE vulnerabilities this month, shattering historical records. For the uninitiated, CVEs are universally recognized identifiers for software security flaws—if it’s got a CVE number, it’s a confirmed system defect.

Patch data from major companies is wildly inconsistent: Oracle updated 1,448 vulnerability patches in July 2026, a multiple-fold increase from 309 in July 2025; Google Chrome rolled out two major updates in June, fixing 1,072 vulnerabilities—a tally that surpasses the total from 23 previous major updates; Mozilla announced in April that it identified 271 Firefox browser vulnerabilities in a single sweep using Anthropic’s Mythos AI model.

Jerry Gamblin, founder of industry research firm RogoLabs and operator of the CVE tracking project cve.icu, revealed his latest stats: As of Wednesday, the total number of registered security vulnerabilities online has skyrocketed to 66,401.

To put this in perspective: The total number of vulnerabilities in September last year was just 33,512, doubling in a single year. When ChatGPT first launched in 2022, the annual increase in vulnerabilities was only 25,000. Visibly, the pace of vulnerability discovery has accelerated to an absurd degree.

The AI-fueled vulnerability surge has sparked heated debates between security and AI experts, with sharply divided opinions.

Image Source: Generated by Doubao AI

Some call it a catastrophic disaster that will upend cybersecurity order; others argue AI is merely amplifying pre-existing industry issues rather than creating new problems out of thin air.

Long before AI’s rise, the industry grappled with delayed patch updates and inadequate security investments, with hackers exploiting these gaps to orchestrate countless cyber incidents. Now, with vulnerabilities multiplying, the conversation has shifted from theoretical speculation to tangible industry reality, prompting both sides to moderate their stances.

Jerry Gamblin sees it clearly: “This growth isn’t hype, but don’t get lost in the numbers. More vulnerabilities don’t mean our software is worse or riskier—it means AI is uncovering flaws that were previously hidden, reflecting an evolving security detection system.”

Yet the risks are undeniable and far from optimistic.

While AI rapidly uncovers vulnerabilities in bulk, human developers struggle to keep up with patching, and end-users lag even further in applying updates. Meanwhile, more hackers are leveraging AI to autonomously discover new vulnerabilities, escalating cyberattacks to new heights.

The UK’s National Cyber Security Centre once bluntly remarked: “Merely identifying vulnerabilities does nothing to improve cybersecurity.”

For now, the industry has a brief respite: AI maintains a fragile equilibrium in the offensive-defensive dynamic, aiding both hackers in rapid vulnerability discovery and defenders in fortifying systems.

Image Source: Generated by Doubao AI

Matthew O’Neill, Cisco’s Threat Intelligence Director, quipped: “Whether it’s legitimate businesses or cybercriminals, everyone’s trying to figure out how to maximize AI’s potential.”

The industry landscape remains in flux. Regulatory policies or voluntary research slowdowns might avert extreme doomsday scenarios like “AI-driven human extinction.”

But here’s the kicker: The vulnerability tsunami triggered by existing AI tools is unstoppable. Restricting new AI model development won’t reverse the current security crisis.

To wrap up with Jerry Gamblin’s blunt assessment: “Vulnerability discovery relies on computing power—you can speed it up indefinitely with money. But vulnerability fixing relies on human effort, which can’t double overnight, no matter how much cash you throw at it.”

This article is compiled by Leikeji from Wired

Original Link: Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening | WIRED

Source: Leikeji

Images in this article are from 123RF Licensed Image Library. Source: Leikeji

Solemnly declare: the copyright of this article belongs to the original author. The reprinted article is only for the purpose of spreading more information. If the author's information is marked incorrectly, please contact us immediately to modify or delete it. Thank you.