Security teams are under siege. AI-driven bug hunting tools are finding software flaws faster than humans can patch them. In just one month, Microsoft rolled out fixes for 974 CVEs-confirmed vulnerabilities-breaking all previous records. The Check Point Research analysis shows that September 2026’s update included two bugs already being exploited and more than 110 critical issues. Oracle wasn’t far behind. Its September update brought over 800 fixes: 672 unique CVEs across 17 risk matrices, plus 130 more CVEs handled by extra patches, according to SecurityWeek. Google Chrome’s two big June releases packed in 1,072 patches-more than the previous 23 releases combined. These aren’t just big numbers. They’re historic.
In September 2026, Chrome 153 closed 230 vulnerabilities, including an actively exploited bug in the V8 engine, demonstrating that large-scale patch releases remain the norm even after record-breaking months.
This isn’t just a theoretical problem. Security and AI researchers are split: does the spike in discovered bugs mean disaster, or does it just make old problems more visible? Some say attackers already had the upper hand, thanks to slow patching and underfunded security, long before AI arrived. But with the number of found flaws exploding, the debate is no longer academic. Gamblin warns: more CVEs don’t always mean more risk. “More CVEs is not more vulnerability. It's more known vulnerability, which is mostly the system working.” Still, the worry is real. Developers may fall behind. Users might not patch fast enough. Attackers could use AI to find and exploit new bugs even quicker.
In September 2026, Microsoft patched two vulnerabilities-CVE-2026-85880 in Windows ALPC and CVE-2026-81963 in Windows Update Stack-that had already been exploited in attacks, both allowing privilege escalation to SYSTEM.
Even if AI progress slows-whether by regulation or industry agreement-the flood of vulnerabilities found by today’s AI tools can’t be undone. As Gamblin puts it, “Discovery scales with compute. Remediation scales with people-and people are the part you can't buy more of in a quarter.” The human factor is now the choke point, not the tech.
For digital publishers and content teams, the message is clear. AI can surface flaws at a scale that teams can’t match. This echoes the risks seen in earlier incidents, where unchecked automation led to data and credibility crises. The current wave of AI-driven bug discovery isn’t a future threat-it’s happening now. Teams that don’t adapt their patching and security processes will be left exposed, as both attackers and defenders use AI’s relentless speed. The future of the industry won’t be about how many bugs AI can find, but how fast and well human teams can respond.
Anthropic, the company behind the Mythos model used in Mozilla’s bug hunt, was founded in 2021 and quickly became a major force in AI research. The company has drawn big investments and is known for focusing on safety and alignment in large language models. Its tools are now in use by major tech firms for both attacking and defending in cybersecurity, showing just how much AI research labs are shaping the security world.