SecurityNot yet confirmed elsewhere1 publisher3 min readPublished
Kaspersky's CVE surge has two sources, and only one of them lands in the CVE count
Kaspersky's Q2 2026 figures credit AI with both writing the bugs and finding them. The disclosures carrying working exploit code never got a CVE identifier at all.
The Watch · Security desk
What happened
- Kaspersky's Q2 2026 report puts the number of registered CVEs at an unprecedented level, credited mainly to AI use in both development and bug hunting.
- The firm says entire new classes of vulnerability emerged in the quarter, particularly in the Linux networking subsystem.
- Published flaws scoring above 9.0 on CVSS jumped sharply in the same period, on Kaspersky's five-year monthly series.
- A researcher using the name Nightmare Eclipse published named Windows flaws with technical details before any CVE identifiers had been assigned.
Why it matters
- constraint Triage built on CVE identifiers cannot open a ticket for the Windows bugs at all, so the flaws with public exploit code are the ones with no queue position.
- cost The reading burden falls on whoever maintains dependency inventories: one AI project alone can add several hundred advisories a quarter to be assessed and mostly dismissed.
- precedent If exploit-first publication becomes the norm, vendors lose the disclosure window they have relied on to prepare and stage a fix.
- contradiction Because the knowledge base blends three registers and its historical figures get revised, the size of the jump is less firm than the direction of it.
Two different mechanisms are being counted in one number, and they do not have the same consequence for the people who run patch queues. Kaspersky says AI development tools contribute defects because the quality of the code they emit varies widely, and separately that AI-assisted research can read volumes of code nobody had examined before, surfacing whole classes of flaw that went unnoticed for decades [20][21]. New code with new bugs is a forward problem. Old code with newly visible bugs is a backlog problem, and it arrives already deployed.
Dirty Frag is the example the report offers for the second kind: not one kernel bug but a series, found with AI assistance in the Linux kernel [6]. Class findings are the expensive sort, because the fix is rarely a single commit and the severity call has to be made again across variants that look alike.
The volume side has an arithmetic tell the report does not spell out. OpenClaw, described as a popular AI project, ranked twelfth by CVE count with more than 200 registered in the quarter [4]. Twelfth place means eleven projects at least matched it [16], so a floor of roughly a dozen projects each cleared 200 CVEs in three months. For OpenClaw alone that is better than two published CVEs per day, every day of the quarter [17].
The Windows section shows where the gap opens. Three of the five named entries in the list published by Nightmare Eclipse are Windows Defender bugs [15]: BlueHammer, a time-of-check to time-of-use race during signature updates that lets an attacker substitute the temporary update directory [11]; RedSun, which overwrites or restores files marked as cloud detections with elevated privileges [12]; and RougePlanet [9]. YellowKey walks past BitLocker through the Windows Recovery Environment [13], and GreenPlasma injects system objects via the CTFMON loader [14]. All four of the entries described in full shipped with exploit code [18], and Kaspersky treats publication ahead of CVE registration and patching as a precedent set this quarter [7]. Defender is the mitigating control on those machines, and three of the published bugs are in it.
So the surge and the exposure are drifting apart. The intake queue fills with advisories from projects that generate them in the hundreds, while the disclosures carrying usable exploits arrive with no identifier to sort on and no vendor fix behind them [3].
One caveat is Kaspersky's own. The knowledge base merges the CVE database, the Russian BDU register and GitHub Advisory, and the firm notes that its figures for earlier reporting periods may differ from what it published before [10]. The direction of travel is credible, and Kaspersky expects the discovery rate to keep climbing [20]. The height of the curve is measured against a baseline that moves.
What to watch
- Whether the Nightmare Eclipse Windows bugs get CVE identifiers, and how long after the exploit code was published.
- Whether Microsoft addresses the three Windows Defender flaws through a scheduled update cycle or out of band.
- Whether Kaspersky's next quarterly report separates CVE volume from AI projects, which would show if the surge is broad or concentrated in a dozen repositories.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence48
- Adoption44
- Hype gap+30
- Incentives66
- Confidence45
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Kaspersky's Securelist report on exploits and vulnerabilities in Q2 2026 states that the number of registered CVEs reached an unprecedented level.
ReportedSupportedSource: Kaspersky (Securelist)2 sources— create a free account to open themView cited source - [2]
Kaspersky says the result was entire new classes of vulnerabilities emerging, particularly in the Linux networking subsystem.
ReportedSupportedSource: Kaspersky (Securelist)2 sources— create a free account to open themView cited source - [3]
Kaspersky says security researchers have been publishing exploits for unpatched vulnerabilities more frequently, and that such publications potentially open the door for attackers to target unprotected systems.
ReportedSupportedSource: Kaspersky (Securelist)2 sources— create a free account to open themView cited source - [4]
OpenClaw, described as a popular AI project, ranked 12th among projects with the highest number of vulnerabilities discovered and published in Q2 2026, with over 200 CVEs registered during the reporting period.
ReportedSupportedSource: Kaspersky (Securelist)2 sources— create a free account to open themView cited source - [5]
Kaspersky's monthly series for 2022 through 2026 shows the number of published critical vulnerabilities (CVSS above 9.0) jumping sharply in Q2 2026.
ReportedSupportedSource: Kaspersky (Securelist)2 sources— create a free account to open themView cited source - [6]
AI was used to find a series of Dirty Frag vulnerabilities in the Linux kernel.
ReportedSupportedSource: Kaspersky (Securelist)2 sources— create a free account to open themView cited source - [7]
Kaspersky describes Q2 2026 as a new precedent in the publication of Windows vulnerabilities and exploits, with researchers no longer waiting for CVE registration, let alone patches.
ReportedSupportedSource: Kaspersky (Securelist)2 sources— create a free account to open themView cited source - [8]
A researcher who goes by Nightmare Eclipse (also known as Chaotic Eclipse) published a list of new named vulnerabilities across various Windows subsystems; at the time the technical details were published, none of them had been assigned a CVE identifier.
ReportedSupportedSource: Kaspersky (Securelist)2 sources— create a free account to open themView cited source - [9]
RougePlanet is listed as a further Windows Defender vulnerability in the same publication; the description in the available material is cut off.
ReportedSupportedSource: Kaspersky (Securelist)2 sources— create a free account to open themView cited source - [10]
Kaspersky's figures come from its vulnerability knowledge base, which draws on the CVE database, the Russian BDU database and GitHub Advisory (GHSA); as a result, figures for previous reporting periods may differ from those published in earlier reports.
- [11]
BlueHammer is a local privilege escalation vulnerability in Windows Defender: during signature database updates a time-of-check to time-of-use race condition allows an attacker to substitute the directory where temporary update files are written. The researcher published a fully functional exploit.
- [12]
RedSun is a logical vulnerability in Windows Defender with a working exploit: suspicious and malicious files marked as cloud can be overwritten or restored to their original directory with elevated privileges. The exploit combines a large number of popular Windows exploitation techniques.
- [13]
YellowKey lets a user bypass BitLocker full-disk encryption and access system data through the Windows Recovery Environment (WinRE); a fully functional exploit was published.
- [14]
GreenPlasma enables system object injection via the CTF loader for the Collaborative Translation Framework (CTFMON) service in Windows; the original publication included an exploit with limited functionality.
- [15]
Three of the five named Windows entries in the Nightmare Eclipse list (BlueHammer, RedSun, RougePlanet) are Windows Defender vulnerabilities.
- [16]
OpenClaw's 12th-place ranking implies at least eleven other projects each registered at least as many CVEs as its 200-plus in Q2 2026.
- [17]
More than 200 CVEs across the 91 days of a second calendar quarter is more than two published CVEs per day for a single project.
- [18]
All four of the Nightmare Eclipse entries described in full were published with exploit code, three of them working or fully functional and one with limited functionality.
- [19]
Kaspersky attributes the CVE surge primarily to the widespread adoption of AI, both for application development and for the search for security flaws.
ReportedInsufficientSource: Kaspersky (Securelist)2 sources— create a free account to open themView cited source - [20]
Kaspersky says AI development tools contribute to the vulnerability picture because the quality of the code they produce can vary widely, and concludes that the rate at which new vulnerabilities are discovered will inevitably keep growing.
ReportedInsufficientSource: Kaspersky (Securelist)2 sources— create a free account to open themView cited source - [21]
Kaspersky says using AI for vulnerability research makes it possible to analyse massive amounts of previously unexamined code, uncover new attack surfaces, and identify entire classes of vulnerabilities that have gone unnoticed for decades.
ReportedInsufficientSource: Kaspersky (Securelist)2 sources— create a free account to open themView cited source
Sources
1 independent publisher whose own reporting we read for this story.
- securelist.comExploits and vulnerabilities in Q2 2026
1 article · August 26, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Linux kernel and networking securityFollow
- AI-Generated Code SecurityFollow
- Windows endpoint securityFollow
- Pre-CVE exploit disclosureFollow
- AI-assisted vulnerability researchFollow
- CVE ecosystem scalingFollow
Entities
- KasperskyFollow
- OpenClawFollow
- Nightmare EclipseFollow
- Windows Security / DefenderFollow
- BitLockerFollow
- Windows Recovery EnvironmentFollow
- Linux kernelFollow
- BlueHammerFollow
- RedSunFollow
- YellowKeyFollow
- GreenPlasmaFollow
- RougePlanetFollow
- UnDefendFollow
- Dirty FragFollow
- CVE ProgramFollow
- GitHub Advisory DatabaseFollow
- BDU vulnerability databaseFollow
- CVSSFollow