AI-discovered vulnerabilities are arriving at roughly twice last year’s rate. Almost none of them are being exploited.
The US National Vulnerabilities Database recorded 45,207 software flaws between January and 27 July, already approaching the whole of 2025, which was itself a record. On that trajectory the year ends at roughly double the 2025 total, Bloomberg reported.
The individual tallies are extraordinary. Oracle patched 1,449 vulnerabilities in its July update against 309 in the same month last year. Microsoft’s July update fixed a record 622 flaws, and credited AI discovery for the surge.
This is the moment the warnings pointed at. Attackers with frontier models, a flood of fresh holes, defenders unable to patch fast enough.
The 💜 of EU techThe latest rumblings from the EU tech scene, a story from our wise ol' founder Boris, and some questionable AI art. It's free, every week, in your inbox. Sign up now!It has not happened.







