The CVE Surge: Why Vulnerability Management Has to Change

The CVE Surge: Why Vulnerability Management Has to Change

The number of serious software vulnerabilities being disclosed is rising dramatically. Epoch AI reports that around 2,500 high- and critical-severity CVEs were disclosed by 21 major technology organizations in July 2026, roughly five times the monthly record seen before the announcement of Anthropic's Claude Mythos Preview. With AI systems becoming increasingly capable of finding software vulnerabilities, it is tempting to conclude that artificial intelligence is responsible for the surge. The reality appears more complicated, but for organizations trying to keep their systems secure, the implications may be just as important.

The rise started before Mythos

Researchers at PolyBridge examined the increase using data from VulnCheck and found that the acceleration appears to have begun around November 2025, several months before Mythos was announced. CVE disclosures have also been increasing for years as vulnerability research expands and the CVE ecosystem itself changes. AI therefore cannot simply be credited with creating the trend. What it may be doing, however, is accelerating it.

Monthly high and critical CVE disclosures from 2022 to July 2026, showing that the increase began before the April 2026 Claude Mythos Preview announcement.
High and critical CVE disclosures were already accelerating before the Claude Mythos Preview announcement. Source: PolyBridge Research, based on VulnCheck data.

Oracle shows why headline numbers need context

July also demonstrates why headline CVE numbers can be misleading without context. PolyBridge found that Oracle alone accounted for 747 critical and high-severity CVEs, approximately a quarter of its total for the 21 organizations examined. Oracle's July 2026 Critical Patch Update was unusually large, containing 1,449 new security patches. Oracle has also stated that the growth reflects several factors, including expanded product coverage, accelerated security engineering and AI-powered identification of security findings.

This distinction matters. AI may indeed be helping to increase vulnerability numbers, but at least some of that increase comes from defenders finding vulnerabilities in their own software more efficiently rather than attackers suddenly discovering thousands of new weaknesses. A higher number of disclosed vulnerabilities does not necessarily mean that software has suddenly become dramatically less secure.

Should organizations be worried?

Yes, but perhaps not for the obvious reason. Finding and fixing more vulnerabilities is ultimately positive for software security. The problem is that organizations must process this growing stream of information and determine which vulnerabilities actually threaten them. If AI-assisted research substantially increases vulnerability discovery, traditional approaches based on periodically checking vulnerability lists and treating every high CVSS score as an emergency will become increasingly difficult to sustain.

A thousand new vulnerabilities do not represent a thousand equally urgent problems. Organizations need to determine whether they actually use the affected product, whether vulnerable systems are exposed, whether exploitation is occurring in the wild, how likely exploitation is and how important the affected asset is to the business. Vulnerability management is therefore becoming increasingly focused on prioritization rather than simply enumeration.

High and critical CVEs by organization in July 2026, showing Oracle with 747 vulnerabilities and accounting for approximately 25% of the total across the 21 organizations studied.
Oracle accounted for approximately 25% of all high and critical CVEs in the 21-vendor dataset in July 2026. Source: PolyBridge Research, based on VulnCheck data.

The old model of vulnerability management is disappearing

For years, many organizations could reasonably follow newly published CVEs, examine their severity scores and patch accordingly. That approach becomes increasingly difficult when vulnerability disclosure moves from hundreds to potentially thousands of serious findings in a single month. AI-assisted discovery could accelerate this change considerably by allowing vendors and security researchers to inspect software at a scale that would previously have required enormous amounts of manual work.

This means vulnerability management increasingly requires context. CVSS remains useful for understanding technical severity, but it should be considered alongside information such as CISA's Known Exploited Vulnerabilities catalogue, EPSS exploitation probability, available exploits, asset exposure and business importance. Automation becomes increasingly valuable because security teams cannot realistically investigate every vulnerability with the same level of urgency.

How BaseFortify helps

This is precisely the problem BaseFortify.eu is designed to address. BaseFortify continuously monitors vulnerability and threat information and helps organizations identify and prioritize the vulnerabilities that matter to their environment. Rather than expecting users to manually make sense of an ever-growing stream of disclosures, BaseFortify brings together intelligence from sources including CVE data, CVSS severity, EPSS exploitation probability and CISA's Known Exploited Vulnerabilities catalogue.

AI will continue to change both offensive and defensive cybersecurity, and BaseFortify will continue evolving alongside those developments. Our goal remains the same regardless of how vulnerabilities are discovered: provide users with relevant, timely and actionable information so they can concentrate on the vulnerabilities that present the greatest risk to their systems.

More vulnerabilities, but better decisions

The recent CVE surge should therefore not simply be interpreted as evidence that software has suddenly become several times less secure. It reflects a combination of long-term growth in vulnerability reporting, changes in the CVE ecosystem, unusually large vendor disclosures and increasingly capable AI-assisted security research. AI is part of the story, but it is not the entire explanation.

For defenders, the larger lesson is more important than the cause of any individual spike. The era in which vulnerability management meant keeping an eye on a manageable list of CVEs is disappearing. The challenge now is knowing which vulnerabilities matter, understanding how they relate to your own infrastructure and acting on them quickly.

References

Epoch AI — Serious cyber vulnerability disclosures kept climbing in July
https://epoch.ai/data-insights/cve-severity-spike-july-2026

PolyBridge Research — The Spike: A closer look at the surge in severe vulnerability disclosures
https://polybridge.ai/research/the-spike

Oracle — Critical Patch Update Advisory, July 2026
https://www.oracle.com/security-alerts/cpujul2026.html

Oracle — July 2026 Critical Patch Update Released
https://blogs.oracle.com/security/july-2026-critical-patch-update-released

CISA — Known Exploited Vulnerabilities Catalog
https://www.cisa.gov/known-exploited-vulnerabilities-catalog