Google Threat Intelligence Group counted 10,740 vulnerability disclosures in August, more than double the monthly figure at the start of 2026. Exploitation is rising more slowly, so the first call on any budget reopened this quarter is triage capacity.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+25
- Incentives45
- Confidence65
VulnCheck counts Chrome CVEs up 563% and GitHub-issued CVEs up 476% this year, a rise it calls consistent with AI-assisted bug finding. Whether the volume lasts is unknown, so exploitation data still sets patch order.
Reality
- Evidence55
- Adoption45
- Hype gap+20
- Incentives55
- Confidence50
A Federal Register RFI calls periodic scanning, static prioritization and manual remediation increasingly inadequate. Comments on redesigning the feed close October 13.
Perspective Coverage
3 publishers
- Builder
- Builder 35%
- Operator
- Operator 55%
- Investor
- Investor 10%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence70
CISA's 2026 election security plan names outdated certification rules as one of three problems in how election system flaws get fixed. The attack path it describes starts at a compromised office inbox or workstation and moves laterally into those systems.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+10
- Incentives45
- Confidence66
The image parsing bug had been fixed upstream about a year earlier, and the decision not to ship that fix belonged to Discourse. OpenAI's forum shared single sign-on with internal systems, so a forum account became GitHub access.
Perspective Coverage
9 publishers
- Builder
- Builder 35%
- Operator
- Operator 39%
- Investor
- Investor 26%
Reality
- Evidence70
- Adoption63
- Hype gap+28
- Incentives60
- Confidence62
Patrick Wardle showed that one undocumented key, endo_voyager_dictation_endpoint, let unprivileged local code reroute Muse's dictation audio and account token. Meta stripped the key from production builds and requested no CVE.
Reality
- Evidence58
- Adoption30
- Hype gap+20
- Incentives72
- Confidence55
Canonical is merging two update cycles so that an Ubuntu kernel ships every week. Getting a CVE fix faster than that means running release candidates its certification testing has not yet cleared.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives45
- Confidence60
Linux distributions backport security fixes without moving the version number, so an unauthenticated scan can only report that a host might be vulnerable. The figures in one dev.to post put the median time to patch at 32 days.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+25
- Incentives30
- Confidence55
Oracle says AI-powered identification is part of why its July Critical Patch Update ran to 1,449 fixes across 334 products, and the nine steps between a finding and an installed patch are the same as they were last year.
Reality
- Evidence30
- Adoption28
- Hype gap+35
- Incentives55
- Confidence40
An arXiv paper argues that a hosted model name only routes a request, so a safety finding filed against that name loses its subject as soon as the weights, prompts, classifiers or serving stack change under it.
Reality
- Evidence46
- Adoption12
- Hype gap+25
- Incentives
- Insufficient
- Confidence42
The year's CVE tally has reached 66,401, close to double where it stood last September, and Microsoft alone patched 974 in a single month. Jerry Gamblin, who keeps the count, says more known bugs is mostly the system working.
Reality
- Evidence55
- Adoption45
- Hype gap+25
- Incentives45
- Confidence50
Since September 17, 2026, reports to CISA go through VINCE-NT, a platform the agency owns and manages itself, and anyone with an open case will be told individually when it moves across.
Reality
- Evidence66
- Adoption45
- Hype gap+18
- Incentives58
- Confidence72
Oracle's fifth monthly Critical Security Patch Update since May concentrates its unauthenticated remote flaws in Fusion Middleware and Hyperion, while the largest single batch of patches went to E-Business Suite.
Reality
- Evidence78
- Adoption
- Insufficient
- Hype gap+10
- Incentives60
- Confidence72
Chainguard says fix generation was never its bottleneck and that responsible disclosure at scale is, so its first public batch is built from bugs upstreams quietly fixed years ago and never filed CVEs for.
Publishers:chainguard.dev
Reality
- Evidence34
- Adoption16
- Hype gap+28
- Incentives82
- Confidence48
The industry is still shipping the defect classes CISA has flagged for years. The case that AI coding assistants will multiply them comes from two named practitioners, not from the agency's own data.
Reality
- Evidence55
- Adoption30
- Hype gap+35
- Incentives75
- Confidence45
A post at The Hacker News puts published CVEs up roughly 49 percent year over year and observed exploitation at 495. For operators the figure that changes triage is the 116 attacked on the day they went public.
Reality
- Evidence30
- Adoption20
- Hype gap+30
- Incentives85
- Confidence40
A two-week, $1m escape challenge against Vercel's Firecracker sandbox produced 1,285 reports. The most valuable one hit the Linux kernel networking stack that many clouds use to isolate tenants, and its CVEs are pending.
Reality
- Evidence45
- Adoption35
- Hype gap+25
- Incentives80
- Confidence45
VulnCheck's first-half figures put the median at 80 days, down from 120 in 2025, while the count of CVEs exploited within a month of publication held flat near 200. The tier that breaks is the 90-day one.
Reality
- Evidence58
- Adoption62
- Hype gap−12
- Incentives70
- Confidence55
ENISA says in a July 2026 assessment that the research-and-develop delay defenders implicitly count on is disappearing as automated systems take over the attacker's work, with the remaining window measured in minutes.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence45
VulnCheck logged 884 vulnerabilities with first-time exploitation evidence in 2025, and 28.96% of them were already being exploited by the day their CVE appeared, up from 23.6% a year earlier. The same report calls the year's timing highly consistent with 2024.
Reality
- Evidence52
- Adoption
- Insufficient
- Hype gap+18
- Incentives78
- Confidence48
Earlier coverage
- Automox drafts endpoint mitigations with AI for the flaws that have no patch yet
Security · September 11, 2026 · 1 publisher
- Exploitation of software flaws tops Verizon's 2026 intrusion list, up 31% year over year
Security · September 10, 2026 · 1 publisher
- WordPress disclosures with no patch on day one nearly doubled in 2025
Build · September 8, 2026 · 1 publisher
- Maintainers shipped 97 fixes against the 23,019 bugs Claude Mythos flagged
Security · September 3, 2026 · 1 publisher
- Pooling three passes turns DeepSeek Pro's 17 findings into 28 of 32
Build · August 29, 2026 · 1 publisher
- NVD stops scheduling enrichment for roughly 30,000 pre-March-2026 CVEs
Security · August 28, 2026 · 1 publisher
- Twistlock's founders raised $51M for Minimus, then handed the leftovers back
Invest · August 26, 2026 · 1 publisher
- Silent patches ship the details anyway. Only the defenders miss them
Security · August 25, 2026 · 1 publisher
- The disclosure pipeline is triaging itself: 20,700 new CVEs, 10% more exploitation
Security · August 19, 2026 · 1 publisher
- Mythos's method, not its zero-day count, is what breaks CVE-keyed vuln management
Security · August 18, 2026 · 1 publisher
- CISA's KEV triage guidance tells agencies to collect RAM before they patch
Security · August 17, 2026 · 1 publisher
- The AI hacking disclosures were all instructed attacks. The change is tempo, not autonomy
Science · August 17, 2026 · 1 publisher
- One unsigned parent, dozens of children: why image signing keeps losing to scanning
Build · August 14, 2026 · 1 publisher