Story
Software Vulnerability Discoveries Nearly Double in 2026, Driven by AI Tools

Summary
The number of software security flaws is on pace to double this year, with data showing a massive increase in disclosed vulnerabilities at major tech firms like Oracle and Microsoft as AI accelerates the discovery process.
The discovery of software security flaws is surging in 2026, with the number of reported vulnerabilities on track to nearly double the total from 2025, a trend attributed to the growing use of powerful artificial intelligence tools by security researchers.
A Surge in Disclosures
According to a Bloomberg News report on Monday, the U.S. National Vulnerabilities Database has recorded 45,207 new flaws between January and July 27. This figure is already approaching the total number of vulnerabilities discovered throughout all of 2025. The database serves as a critical repository, tracking digital security holes that malicious actors could exploit for criminal or espionage purposes.
The increasing volume of disclosures is putting pressure on corporate cybersecurity teams to patch systems at an unprecedented rate. The trend highlights a double-edged sword: while more flaws are being found and fixed, it also reveals a vastly expanded potential attack surface for hackers.
Tech Giants Report Record Patches
Several major technology companies have reported a significant spike in the number of bugs they are addressing. The latest software updates show a dramatic year-over-year increase in patched vulnerabilities:
Ad- Oracle Corp. (ORCL) fixed a company-record 1,449 security issues in its July software update, a sharp increase from the 309 fixes in the same update last year.
- Microsoft Corp. (MSFT) disclosed 642 security bugs in July, a figure nearly five times higher than the count from July 2025.
- Alphabet Inc.’s (GOOGL) Google found and patched 433 bugs in a recent Chrome browser update, compared to just 11 in an equivalent update one year prior.
AI's Role in Vulnerability Discovery
The proliferation of AI-powered tools is seen as the primary driver behind the accelerated pace of discovery. These systems can analyze code and identify potential weaknesses far more efficiently than human researchers alone.
"These tools are increasing people’s ability to find vulnerabilities in software," said Gabriel Shapiro, distinguished AI research scientist at cybersecurity firm SentinelOne Inc. (S), in a comment to Bloomberg. The trend suggests that both ethical hackers and malicious actors are leveraging AI, intensifying the race between cyber defense and offense.
Read next
More on Stocks
Northern Star Rejects Takeover Overture From Gold Fields, Bloomberg Reports
South Africa's Gold Fields Ltd. recently approached Australia's Northern Star Resources about a potential acquisition, but the offer was rejected, according to a report. The move comes as Northern Star faces pressure from an activist investor and deals with operational challenges.

European Telecoms Face AI-Driven Price Pressure, Bank of America Warns
Bank of America analysts report that while AI agents could increase customer churn for European telecom operators by simplifying price comparisons, the technology also offers powerful tools for sales and personalized customer retention.

ShinyHunters Hackers Renew Attacks on Oracle PeopleSoft Flaw, Google's Mandiant Reports
Google's cybersecurity unit, Mandiant, reports that the hacking group ShinyHunters has resumed and adapted its exploitation of a known vulnerability in Oracle's PeopleSoft enterprise software, targeting organizations that failed to apply a full security patch.

Manulife Stock Climbs, Supported by Cross-Border Investor Optimism
Shares of Manulife Financial gained on Tuesday, buoyed by a strong performance in U.S. markets rather than any specific company news. The stock's move is also supported by a bullish technical posture and positive analyst ratings.