Is AI finding more vulnerabilities — or just finding them faster?
Everyone has a take. This is the data underneath it: two years of Microsoft Patch Tuesday, a decade of CVE totals, the CWE type shifts, and the dated evidence for AI on both the attacker and defender side. Sourced, and honest about what it can't say.
The one-paragraph answer
CVE volume is climbing steeply, but the biggest drivers are structural and boring: the CVE program added more issuers, the Linux kernel and WordPress-plugin trackers became firehoses, and disclosure got more complete. AI is a factor in the 2024–2026 acceleration, but no public dataset isolates it from those confounders. The vulnerability types haven't fundamentally changed — web and authorization flaws dominate the counts, memory-safety keeps declining where memory-safe languages are adopted. What has changed is tempo: AI systems now demonstrably find real bugs (Big Sleep, DARPA's AIxCC), and time-to-exploit has collapsed to days. The strongest attacker-side claims (autonomous AI-run campaigns) remain contested and thinly evidenced. Both sides get the same tools; so far, the defenders have the louder proof and the attackers have the faster clock.
CVEs published per year
Annual CVE IDs, 2016–2026. 2026 is half-year actuals, marked in teal with an asterisk.
What's on this site
How to read this
Every number links to a named source. Where sources disagree, both are shown. Where the data can't answer a question, it says so instead of guessing. Vendor marketing is labeled as vendor marketing.
Neutrality is the point. This site takes no position on whether AI "favors" attackers or defenders beyond what the numbers support.