Security1 distinct publisher3 min readPublished
Kaspersky's Q2 2026 figures credit AI with both writing the bugs and finding them. The disclosures carrying working exploit code never got a CVE identifier at all.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Two different mechanisms are being counted in one number, and they do not have the same consequence for the people who run patch queues. Kaspersky says AI development tools contribute defects because the quality of the code they emit varies widely, and separately that AI-assisted research can read volumes of code nobody had examined before, surfacing whole classes of flaw that went unnoticed for decades [7][9]. New code with new bugs is a forward problem. Old code with newly visible bugs is a backlog problem, and it arrives already deployed.
Dirty Frag is the example the report offers for the second kind: not one kernel bug but a series, found with AI assistance in the Linux kernel [10]. Class findings are the expensive sort, because the fix is rarely a single commit and the severity call has to be made again across variants that look alike.
The volume side has an arithmetic tell the report does not spell out. OpenClaw, described as a popular AI project, ranked twelfth by CVE count with more than 200 registered in the quarter [6]. Twelfth place means eleven projects at least matched it [19], so a floor of roughly a dozen projects each cleared 200 CVEs in three months. For OpenClaw alone that is better than two published CVEs per day, every day of the quarter [20].
The Windows section shows where the gap opens. Three of the five named entries in the list published by Nightmare Eclipse are Windows Defender bugs [18]: BlueHammer, a time-of-check to time-of-use race during signature updates that lets an attacker substitute the temporary update directory [13]; RedSun, which overwrites or restores files marked as cloud detections with elevated privileges [14]; and RougePlanet [17]. YellowKey walks past BitLocker through the Windows Recovery Environment [15], and GreenPlasma injects system objects via the CTFMON loader [16]. All four of the entries described in full shipped with exploit code [21], and Kaspersky treats publication ahead of CVE registration and patching as a precedent set this quarter [11]. Defender is the mitigating control on those machines, and three of the published bugs are in it.
So the surge and the exposure are drifting apart. The intake queue fills with advisories from projects that generate them in the hundreds, while the disclosures carrying usable exploits arrive with no identifier to sort on and no vendor fix behind them [4].
One caveat is Kaspersky's own. The knowledge base merges the CVE database, the Russian BDU register and GitHub Advisory, and the firm notes that its figures for earlier reporting periods may differ from what it published before [5]. The direction of travel is credible, and Kaspersky expects the discovery rate to keep climbing [7]. The height of the curve is measured against a baseline that moves.
Ranked by verification strength, evidence, and original report placement.
Kaspersky's Securelist report on exploits and vulnerabilities in Q2 2026 states that the number of registered CVEs reached an unprecedented level.
Kaspersky says the result was entire new classes of vulnerabilities emerging, particularly in the Linux networking subsystem.
Kaspersky says security researchers have been publishing exploits for unpatched vulnerabilities more frequently, and that such publications potentially open the door for attackers to target unprotected systems.
OpenClaw, described as a popular AI project, ranked 12th among projects with the highest number of vulnerabilities discovered and published in Q2 2026, with over 200 CVEs registered during the reporting period.
Kaspersky's monthly series for 2022 through 2026 shows the number of published critical vulnerabilities (CVSS above 9.0) jumping sharply in Q2 2026.
AI was used to find a series of Dirty Frag vulnerabilities in the Linux kernel.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary vendor report, quantification off-page and uncorroborated
The cluster contains one source, but it is the originating primary document: Kaspersky's own quarterly, with an explicit methodology note and richly specific technical descriptions of six named Windows vulnerabilities and their exploit code. That specificity is what lifts the score. What holds it down is that the headline quantities - the record CVE count and the critical-CVSS jump - exist only in download-only charts, the AI attribution has no stated method, and no second publisher, vendor advisory, or CVE record in the cluster corroborates any of it.
Concrete disclosure and telemetry artifacts, AI attribution unquantified
There are real, countable artifacts here rather than intentions: 200-plus CVEs registered against one AI project in a quarter, six named Windows vulnerabilities shipped with exploit code, a Dirty Frag series in the Linux kernel, and a telemetry list of the exploits Kaspersky detects most. What is not measured is the thing the story turns on - how much of the surge is actually AI-driven, and whether the published exploits are being used in the wild, which Kaspersky itself calls isolated cases for now.
Causal AI framing outruns the published attribution data
The report's substantive disclosures are, if anything, under-sold: six exploit-carrying Windows vulnerabilities with no CVE, four of them inside Windows Defender, are described in one bullet list and then set aside. The overstatement is in the causal and forward-looking layer - AI named as the primary driver of a record CVE count with no attribution method, a mechanism story about decades-old vulnerability classes resting on one example, and the conclusion that discovery rates will 'inevitably' keep growing. Net positive but moderate, because the technical core is verifiable in detail even where the headline is not.
Commercial security vendor reporting from its own knowledge base and telemetry
Kaspersky is a commercial endpoint-security vendor and every number here originates inside its own products: the vulnerability knowledge base it curates and the telemetry its solutions generate, including a list framed as 'the ones our solutions most frequently detect exploits for'. A narrative of unprecedented, AI-accelerated vulnerability volume plus researchers publishing exploits before patches exist aligns directly with demand for the vendor's detection and patch-management offerings. There is no disclosed sponsorship or product pitch in the text and the methodology caveat is stated openly, so this is structural interest rather than evident distortion.
Single primary source, strong on detail, unverified on totals
Confidence is limited mainly by cluster structure: one publisher, one document, no corroborating advisory or CVE record, and the two quantitative backbones locked in chart downloads. Confidence is nonetheless above the floor because the source is the primary report rather than a summary of one, its technical descriptions are specific and internally consistent, and its methodology limits are self-disclosed. The article ledger's own counts of the named Windows entries (five entries, three in Defender) diverge from the source body's six entries with four in Defender, which further argues for caution on derived arithmetic.
product
AI writes the Dockerfile, and the pipeline is still checking the app code1 distinct publisher
build
A researcher is timing zero-days to Patch Tuesday, and the monthly cadence has no reply1 distinct publisher
build
NIST answers an NVD audit with an AI tool nobody outside NIST has seen1 distinct publisher
build
Fabricated SQLite CVEs cleared NVD, CISA ADP and Red Hat before anyone ran the code1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 26, 2026