Vulnerability data · Aug 2024 – Jul 2026 · neutral analysis

Is AI finding more vulnerabilities — or just finding them faster?

Everyone has a take. This is the data underneath it: two years of Microsoft Patch Tuesday, a decade of CVE totals, the CWE type shifts, and the dated evidence for AI on both the attacker and defender side. Sourced, and honest about what it can't say.

48,185
CVEs published in 2025
+20.6% over 2024's record
569
CVEs · July 2026 Patch Tuesday
largest single month on record
~5 days
median time-to-exploit
down from 63 days in 2018–19
1,647
CISA KEV entries
actually-exploited, as of Jul 2026
Short version: the raw counts are rising fast, but most of that rise has causes that predate AI. Where AI has clearly moved the needle is speed — of discovery, and of exploitation. See the full reasoning →

The one-paragraph answer

CVE volume is climbing steeply, but the biggest drivers are structural and boring: the CVE program added more issuers, the Linux kernel and WordPress-plugin trackers became firehoses, and disclosure got more complete. AI is a factor in the 2024–2026 acceleration, but no public dataset isolates it from those confounders. The vulnerability types haven't fundamentally changed — web and authorization flaws dominate the counts, memory-safety keeps declining where memory-safe languages are adopted. What has changed is tempo: AI systems now demonstrably find real bugs (Big Sleep, DARPA's AIxCC), and time-to-exploit has collapsed to days. The strongest attacker-side claims (autonomous AI-run campaigns) remain contested and thinly evidenced. Both sides get the same tools; so far, the defenders have the louder proof and the attackers have the faster clock.

CVEs published per year

Annual CVE IDs, 2016–2026. 2026 is half-year actuals, marked in teal with an asterisk.

0 12.5k 25k 37.5k 50k 6.4k15k40k48k35k*20162017201820192020202120222023202420252026
The curve is real, but read the next section before attributing it to AI — the 2017 jump and the 2024 surge both trace mostly to more issuers, not more bugs. CVE.org / NVD / Jerry Gamblin annual reviews

What's on this site

How to read this

Every number links to a named source. Where sources disagree, both are shown. Where the data can't answer a question, it says so instead of guessing. Vendor marketing is labeled as vendor marketing.

Neutrality is the point. This site takes no position on whether AI "favors" attackers or defenders beyond what the numbers support.