Skip to main content

AI Is On The Way To Doubling Vulnerabilities In a Year And Why That Isn't Necessarily a Bad Thing

0
Medium
Published: 09/23/2026 (09/23/2026, 19:10:35 UTC)
Source: Reddit Cybersecurity

Description

The volume of publicly disclosed software vulnerabilities is projected to nearly double within a year, largely attributed to the influence of AI in both discovering and introducing vulnerabilities. While the increase in vulnerabilities may seem concerning, it is expected to be a transitional phase leading to more secure software development as AI improves. This trend suggests an initial surge in vulnerability counts followed by a decline as AI learns to code more securely.

Reddit Discussion

r/cybersecurity·posted by u/rogeragrimes
00

Last year, we had 48,449 publicly announced vulnerabilities (https://www.cvedetails.com/browse-by-date.php). This year, so far, we’ve had 69,670 vulnerabilities.

I’ve been predicting since 2025 that we would see a doubling and/or over 100K vulnerabilities this year because of AI.

We are 73% of the way there with over 3 months left.

It’s been 266 days as of today in the year. That means we have 99 days left (excluding leap years and seconds for analysis purposes).

69,670 vulnerabilities in 266 days is 261.91729 vulns per day.

99 days left x 261.91729 vulnerabilities per day for the year is 25,930 vulnerabilities left to discover and publish if we continue at “just” the average rate.

I’m not sure how the year will end up, because although the number of vulnerabilities per day tends to increase greatly in the last few months (over the prior month’s averages), AI could impact those numbers. So, I’ll just use the average for our run rate for the rest of the year.

69,670 existing vulnerabilities plus 25,930 estimated to occur (average number of vulnerabilities left with 99 days to go) is 95,600 total estimated total vulnerabilities for the year.

48,449 x 2 (a doubling in the number of vulnerabilities from 2025) would result in 96,898 vulnerabilities.

So, we are currently on track to be a little short of my original prediction: 1,298 vulns, or 1.3% short.

But knowing that vulnerability counts tend to greatly increase in the last month or two, I’m not going to sweat the difference.

Anyone want to start a Kalsi bet?? <grin>

To be clear, my entire 2025 prediction stated that the number of vulnerabilities found and reported would double or exceed 100K this year. It’s close to that or will be that.

I further predicted that vulnerability counts would be excessive for a few years because of the vulnerabilities AI finds and all the new vulnerabilities that AI inserts in vibe code, but that eventually vulnerability counts would greatly diminish. AI will learn how to code securely. AI will find fewer and fewer bugs in existing code. One day, likely within 5 years, we will see significantly fewer vulnerabilities. Soon, we will have significantly more secure software (and services, APIs, firmware, hardware, etc.).

Imagine that…finally!!...more secure software as we have dreamed of for over half a century. And it took AI to get there. Humans, themselves, without AI, could not do it.

We just need to get through the next few years.

Smile, we are almost there!

Links cited in this discussion

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/24/2026, 14:47:49 UTC

Technical Analysis

Data shows that in 2025 there were 48,449 publicly announced vulnerabilities, and in 2026 the count is on track to reach approximately 95,600, nearly doubling the previous year. This increase is linked to AI's dual role in identifying more vulnerabilities and inadvertently introducing new ones in code. The prediction includes a future scenario where AI will enhance secure coding practices, reducing vulnerabilities significantly within about five years. The analysis is based on vulnerability disclosure rates and trends observed up to the current date in 2026.

Potential Impact

The immediate impact is a substantial increase in the number of reported vulnerabilities, which may strain vulnerability management and remediation efforts. However, this rise is not necessarily negative, as it reflects improved vulnerability detection capabilities. Over time, the impact is expected to shift towards improved software security as AI contributes to more secure coding and fewer vulnerabilities.

Defensive Guidance

No specific mitigation actions are required at this time as this is an observational trend rather than a single vulnerability or exploit. Organizations should continue standard vulnerability management practices. The increase in vulnerability disclosures underscores the importance of maintaining robust patching and risk assessment processes. No official patches or fixes are applicable since this is a trend analysis, not a discrete vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":35,"reasons":["external_link","established_author","recent_news"],"isNewsworthy":true}
Has External Source
true
Trusted Domain
false

Threat ID: 6ab5380df7a7c541066f93df

Added to database: 09/24/2026, 14:47:41 UTC

Last enriched: 09/24/2026, 14:47:49 UTC

Last updated: 09/25/2026, 03:17:46 UTC

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses