Software

AI Doubles Vulnerability Discovery Speed: NVD Records 45,207 Vulnerabilities This Year

According to Bloomberg, AI is significantly accelerating software vulnerability discovery. The number of security vulnerabilities found in popular products in 2026 is projected to double compared to 2025, and the U.S. National Vulnerability Database has already recorded 45,207 vulnerabilities since January.

M
By Michael Torres Senior Software Editor
July 29, 2026 / 6 min read

According to Bloomberg, AI is significantly accelerating the speed at which software vulnerabilities are discovered. The report projects that the number of security vulnerabilities found in popular products in 2026 will double compared to 2025.

Another key data point from Bloomberg: since January of this year, the U.S. National Vulnerability Database (NVD) has recorded 45,207 vulnerabilities. This scale is close to last year's full-year total, indicating that vulnerability disclosure and reporting are growing rapidly.

What the Rising Numbers Mean

A rising number of vulnerabilities does not necessarily mean software has become less secure in a short period. It may also indicate that detection tools are finding more issues that were previously overlooked. AI can help researchers expand their analysis scope, filter suspicious code, and improve efficiency on repetitive tasks.

  • NVD Records: 45,207 vulnerabilities recorded since January.
  • Annual Forecast: Vulnerability discovery in popular products is projected to double versus 2025.
  • Primary Driver: Bloomberg's reporting points to AI accelerating vulnerability discovery.

Pressure as Discovery Outpaces Remediation

As vulnerabilities are discovered faster, software vendors, security teams, and open source maintainers need to verify, triage, and patch them more quickly. If the rate of reporting outpaces remediation capacity, security teams may face a larger backlog.

Analysis: AI improving discovery efficiency is only one part of the security process. Whether a vulnerability is exploitable, how broad its impact is, and whether fixes will introduce compatibility issues still require rigorous validation. A rising number of reports does not mean every entry carries the same level of risk.

What Software Teams Need to Adjust

Development organizations need to treat vulnerability handling as ongoing engineering work rather than a post-release patch-up. Faster detection means patch prioritization, dependency management, and regression testing all rise in importance at the same time.

According to Bloomberg, the number of security vulnerabilities found in popular products in 2026 is projected to double compared to 2025.

Outlook: The bottleneck in the next phase may shift from "can we discover vulnerabilities" to "can we triage and remediate them in time." When evaluating AI security tools, accuracy, false positive rates, and remediation closure will matter more than raw discovery counts.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.