News & Market Updates

AI Bug Hunters Overwhelm Security Teams With Record Vulnerabilities

AI Bug Hunters Overwhelm Security Teams With Record Vulnerabilities © fayfo.com
AI Bug Hunters Overwhelm Security Teams With Record Vulnerabilities © fayfo.com
AI-powered bug hunting is flooding security teams with more vulnerabilities than they can handle. Patch rates can’t keep up, and both attackers and defenders are racing to adapt. The real bottleneck now is human capacity.

Security teams are under siege. AI-driven bug hunting tools are finding software flaws faster than humans can patch them. In just one month, Microsoft rolled out fixes for 974 CVEs-confirmed vulnerabilities-breaking all previous records. The Check Point Research analysis shows that September 2026’s update included two bugs already being exploited and more than 110 critical issues. Oracle wasn’t far behind. Its September update brought over 800 fixes: 672 unique CVEs across 17 risk matrices, plus 130 more CVEs handled by extra patches, according to SecurityWeek. Google Chrome’s two big June releases packed in 1,072 patches-more than the previous 23 releases combined. These aren’t just big numbers. They’re historic.

What’s changed? AI models-open weight and commercial-are now standard tools for scanning code for weaknesses. Mozilla, for example, found 271 Firefox vulnerabilities in a single sprint using Anthropic’s Mythos model. The impact is huge. This week, Jerry Gamblin from Empirical Security and RogoLabs reported 66,401 CVEs logged so far-almost double the 33,512 counted by September 16 last year. For perspective: in all of 2022, when OpenAI launched ChatGPT’s first version, cve.icu tracked just 25,000 CVEs.

In September 2026, Chrome 153 closed 230 vulnerabilities, including an actively exploited bug in the V8 engine, demonstrating that large-scale patch releases remain the norm even after record-breaking months.

Cybersecurity News bulletin

This isn’t just a theoretical problem. Security and AI researchers are split: does the spike in discovered bugs mean disaster, or does it just make old problems more visible? Some say attackers already had the upper hand, thanks to slow patching and underfunded security, long before AI arrived. But with the number of found flaws exploding, the debate is no longer academic. Gamblin warns: more CVEs don’t always mean more risk. “More CVEs is not more vulnerability. It's more known vulnerability, which is mostly the system working.” Still, the worry is real. Developers may fall behind. Users might not patch fast enough. Attackers could use AI to find and exploit new bugs even quicker.

Right now, there’s a shaky balance. AI speeds up both bug discovery and the tools defenders use. Matthew Olney, Cisco’s director of threat intelligence, says both hackers and security teams are testing where AI gives the biggest edge. But the scale of the problem is obvious. Britain’s National Cyber Security Center puts it plainly: “Just finding vulnerabilities does nothing to improve your security.”

In September 2026, Microsoft patched two vulnerabilities-CVE-2026-85880 in Windows ALPC and CVE-2026-81963 in Windows Update Stack-that had already been exploited in attacks, both allowing privilege escalation to SYSTEM.

Even if AI progress slows-whether by regulation or industry agreement-the flood of vulnerabilities found by today’s AI tools can’t be undone. As Gamblin puts it, “Discovery scales with compute. Remediation scales with people-and people are the part you can't buy more of in a quarter.” The human factor is now the choke point, not the tech.

For digital publishers and content teams, the message is clear. AI can surface flaws at a scale that teams can’t match. This echoes the risks seen in earlier incidents, where unchecked automation led to data and credibility crises. The current wave of AI-driven bug discovery isn’t a future threat-it’s happening now. Teams that don’t adapt their patching and security processes will be left exposed, as both attackers and defenders use AI’s relentless speed. The future of the industry won’t be about how many bugs AI can find, but how fast and well human teams can respond.

Anthropic, the company behind the Mythos model used in Mozilla’s bug hunt, was founded in 2021 and quickly became a major force in AI research. The company has drawn big investments and is known for focusing on safety and alignment in large language models. Its tools are now in use by major tech firms for both attacking and defending in cybersecurity, showing just how much AI research labs are shaping the security world.

Paul Christiano Journalist FAYFO Media
Editor-in-Chief

Paul Christiano

American journalist with a strong focus on AI and content technology.