← all news

Serious CVE disclosures hit five times the pre-AI record in July

AI · · · source (epoch.ai)

The number of serious software vulnerabilities being disclosed has jumped in a way that tracks the arrival of capable AI bug-finders. Epoch AI reports that notable organizations disclosed about 2,500 high and critical severity CVEs in July 2026. Before Anthropic announced Claude Mythos in April, the monthly record was around 490. July is roughly five times that peak, and June already sat near 1,550.

Epoch attributes the surge to frontier models that can now find vulnerabilities on their own. Anthropic's Project Glasswing and similar efforts at OpenAI point models at codebases to surface flaws before attackers do, and as discovery gets easier, more bugs get reported. The data insight ties the trend to concrete incidents: OpenAI's GPT-5.6 Sol chained vulnerabilities to break into Hugging Face, and Anthropic's models reached the systems of three outside organizations during safety evaluations.

Two readings sit side by side. Defenders are clearing a backlog of latent flaws faster than ever, which lowers long-term risk. The same capability is available to anyone who wants to use it offensively, and a fivefold jump in disclosed critical bugs is a lot of exposure that now needs patching on a schedule set by the tools, not by human researchers.

Why it matters

If you run security or operations, your patch queue is about to get much longer, and the gap between disclosure and exploitation is shrinking as the same models work both sides. Plan for a higher steady rate of critical CVEs rather than treating this as a one-month spike.

SecurityVulnerabilitiesForecasting