Skip to content

SecurityNot yet confirmed elsewhere1 publisher3 min readPublished

Kaspersky's CVE surge has two sources, and only one of them lands in the CVE count

Kaspersky's Q2 2026 figures credit AI with both writing the bugs and finding them. The disclosures carrying working exploit code never got a CVE identifier at all.

The Watch · Security desk

How we use AISend a correction

What happened

  • Kaspersky's Q2 2026 report puts the number of registered CVEs at an unprecedented level, credited mainly to AI use in both development and bug hunting.
  • The firm says entire new classes of vulnerability emerged in the quarter, particularly in the Linux networking subsystem.
  • Published flaws scoring above 9.0 on CVSS jumped sharply in the same period, on Kaspersky's five-year monthly series.
  • A researcher using the name Nightmare Eclipse published named Windows flaws with technical details before any CVE identifiers had been assigned.

Why it matters

  • constraint Triage built on CVE identifiers cannot open a ticket for the Windows bugs at all, so the flaws with public exploit code are the ones with no queue position.
  • cost The reading burden falls on whoever maintains dependency inventories: one AI project alone can add several hundred advisories a quarter to be assessed and mostly dismissed.
  • precedent If exploit-first publication becomes the norm, vendors lose the disclosure window they have relied on to prepare and stage a fix.
  • contradiction Because the knowledge base blends three registers and its historical figures get revised, the size of the jump is less firm than the direction of it.

Two different mechanisms are being counted in one number, and they do not have the same consequence for the people who run patch queues. Kaspersky says AI development tools contribute defects because the quality of the code they emit varies widely, and separately that AI-assisted research can read volumes of code nobody had examined before, surfacing whole classes of flaw that went unnoticed for decades [20][21]. New code with new bugs is a forward problem. Old code with newly visible bugs is a backlog problem, and it arrives already deployed.

Dirty Frag is the example the report offers for the second kind: not one kernel bug but a series, found with AI assistance in the Linux kernel [6]. Class findings are the expensive sort, because the fix is rarely a single commit and the severity call has to be made again across variants that look alike.

The volume side has an arithmetic tell the report does not spell out. OpenClaw, described as a popular AI project, ranked twelfth by CVE count with more than 200 registered in the quarter [4]. Twelfth place means eleven projects at least matched it [16], so a floor of roughly a dozen projects each cleared 200 CVEs in three months. For OpenClaw alone that is better than two published CVEs per day, every day of the quarter [17].

The Windows section shows where the gap opens. Three of the five named entries in the list published by Nightmare Eclipse are Windows Defender bugs [15]: BlueHammer, a time-of-check to time-of-use race during signature updates that lets an attacker substitute the temporary update directory [11]; RedSun, which overwrites or restores files marked as cloud detections with elevated privileges [12]; and RougePlanet [9]. YellowKey walks past BitLocker through the Windows Recovery Environment [13], and GreenPlasma injects system objects via the CTFMON loader [14]. All four of the entries described in full shipped with exploit code [18], and Kaspersky treats publication ahead of CVE registration and patching as a precedent set this quarter [7]. Defender is the mitigating control on those machines, and three of the published bugs are in it.

So the surge and the exposure are drifting apart. The intake queue fills with advisories from projects that generate them in the hundreds, while the disclosures carrying usable exploits arrive with no identifier to sort on and no vendor fix behind them [3].

One caveat is Kaspersky's own. The knowledge base merges the CVE database, the Russian BDU register and GitHub Advisory, and the firm notes that its figures for earlier reporting periods may differ from what it published before [10]. The direction of travel is credible, and Kaspersky expects the discovery rate to keep climbing [20]. The height of the curve is measured against a baseline that moves.

What to watch

  • Whether the Nightmare Eclipse Windows bugs get CVE identifiers, and how long after the exploit code was published.
  • Whether Microsoft addresses the three Windows Defender flaws through a scheduled update cycle or out of band.
  • Whether Kaspersky's next quarterly report separates CVE volume from AI projects, which would show if the surge is broad or concentrated in a dozen repositories.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence48
Adoption44
Hype gap+30
Incentives66
Confidence45
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Kaspersky's Securelist report on exploits and vulnerabilities in Q2 2026 states that the number of registered CVEs reached an unprecedented level.

    ReportedSupportedSource: Kaspersky (Securelist)2 sources— create a free account to open themView cited source
  2. [2]

    Kaspersky says the result was entire new classes of vulnerabilities emerging, particularly in the Linux networking subsystem.

    ReportedSupportedSource: Kaspersky (Securelist)2 sources— create a free account to open themView cited source
  3. [3]

    Kaspersky says security researchers have been publishing exploits for unpatched vulnerabilities more frequently, and that such publications potentially open the door for attackers to target unprotected systems.

    ReportedSupportedSource: Kaspersky (Securelist)2 sources— create a free account to open themView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. securelist.com

    1 article · August 26, 2026

    Exploits and vulnerabilities in Q2 2026

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories