
AI Vulnerability Discovery Hits 35k CVEs in H1 2026 While Exploited Subset Stays at 495
AI has accelerated vulnerability candidate generation far beyond exploitation and patching rates, rendering CVSS-centric triage obsolete. Evidence from NVD, CISA KEV, and Omdia shows only a tiny exploited subset demands immediate action, yet current validation coverage remains incomplete. Organizations must integrate exploitability, control, and path validation to match disclosure velocity.
AI systems like Anthropic’s Mythos models generated 26,153 vulnerability candidates in open-source code, yet upstream patches covered just 421. This volume surge, up 49% year-over-year per NVD data, outstrips manual triage capacity. CVSS scores alone fail to capture reachability, control effectiveness, or asset criticality, leaving defenders without actionable signals on the 116 zero-day exploits disclosed same-day. Automated pentesting covers only 32% of attack surfaces annually according to Omdia, constrained by missing exploits and air-gapped assets. The pattern shows disclosure velocity now exceeds safe live-testing windows, forcing reliance on static and simulated validation layers that still lack unified evidence trails across procurement and incident records. Integrated platforms combining exploitability checks, control validation, and agentic chaining close the loop, but current deployments remain fragmented. Without cross-referenced data from CISA KEV lists and vendor patch telemetry, organizations continue over-prioritizing non-exploitable findings while missing chained paths that bypass single controls. Next six months will test whether vendors embed these three validation modes into single workflows or maintain separate tool silos that perpetuate the coverage gap.
SENTINEL: By Q2 2027, fewer than 15% of organizations will have unified exploitability-control-path validation platforms deployed, measured by contract awards in FedRAMP and DoD procurement records.
Sources (3)
- [1]NVD CVE Publication Statistics(https://nvd.nist.gov/vuln)
- [2]CISA Known Exploited Vulnerabilities Catalog(https://www.cisa.gov/known-exploited-vulnerabilities)
- [3]Omdia Automated Pentesting Survey 2026(https://omdia.tech.informa.com)