FIRST reported that 2026 vulnerability disclosures are running far above expectations, with cumulative CVE volume tracking 46.3% above its original forecast and adding roughly 6,420 excess entries, pushing the projected annual total to about 66,000. The organization attributed the surge to AI-assisted discovery and broader reporting pipelines tied to tools and programs including Anthropic Mythos, OpenAI GPT-5.4-Cyber, GitHub Security Advisories, and VulnCheck. Despite the jump in raw disclosures, FIRST said practical defender risk appears more stable when filtered through exploitability signals such as CISA KEV inclusion or EPSS scores above 10%, and warned that AI-generated ephemeral software may create short-lived “micro-vulnerabilities” that never reach traditional CVE registries.
Security practitioners said the growing volume is colliding with persistent limits in AI-based triage. Dark Reading reported that large language models still struggle to reliably find and prioritize vulnerabilities for application security teams, producing high false-positive rates, inconsistent results, and weak understanding of code reachability and deployment context. Pixee CTO Arshan Dabirsiaghi said organizations are being flooded by vulnerability findings and dependency update noise without enough staff to validate issues at scale, reinforcing FIRST’s view that the bottleneck has shifted from discovering bugs to human verification, coordination, patching, and detection engineering.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
On 2026-06-15, FIRST published its mid-year 2026 vulnerability forecast update, reporting that cumulative CVE volume was running 46.3% above the original forecast and raising the projected 2026 total to about 66,000. The report attributed the increase primarily to AI-assisted vulnerability discovery and expanded reporting activity, while arguing that exploitability-filtered risk remained comparatively stable.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.