/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

The US National Vulnerabilities Database has recorded 45,207 software security flaws so far in 2026, on pace to roughly double the tally of flaws found in 2025

The number of software security flaws discovered in popular technology products in 2026 is on pace to roughly double the tally …

Bloomberg Patrick Howell O'Neill

Context & Ripple Effects

The reported pace follows a CVE ecosystem that had already surpassed 40,000 reported issues in 2024, with 413 organizations contributing disclosures to the identifier program the expanding CVE reporting pipeline.

It also arrives as vendors confront larger remediation loads: Microsoft’s June release fixed nearly 200 issues, amid greater use of AI by vendors and researchers to find bugs a record-sized Microsoft patch release.

First-order effects

  • Security and IT teams inherit a substantially larger stream of newly cataloged issues to assess, prioritize and remediate.
  • The National Vulnerabilities Database becomes an even more important operational input for organizations tracking exposure across their software estates.

Second-order effects

  • Patch-management and vulnerability-management programs will be pushed toward exploitability-based triage rather than treating raw disclosure volume as a proxy for immediate risk; earlier research found only a small share of cataloged flaws had been exploited in the wild the historical gap between disclosed and exploited vulnerabilities.
  • Software vendors face added pressure to shorten the path from bug discovery to fix and customer guidance as disclosure volume expands.

Third-order effects

  • If high-volume discovery persists, application security will increasingly depend on automated, closed-loop workflows that connect discovery, prioritization, remediation and verification rather than periodic manual review.
  • The industry’s security challenge shifts from finding vulnerabilities alone to maintaining trusted prioritization signals across an expanding public disclosure infrastructure.

The trend: This is one data point in the shift toward AI-accelerated vulnerability discovery, which raises the premium on automated remediation and risk-based prioritization.

Discussion

  • @joemenn Joseph Menn on bluesky
    Known exploited vulnerabilities have not surged as much as the number of new bugs.  But the operative word there might be KNOWN.  [embedded post]
  • @ericjgeller.com Eric Geller on bluesky
    The NVD “recorded 45,207 flaws between January and Monday, a count approaching the total number found in all of 2025,” @patrickhowelloneill.com reports, but “there's been no rise in the number of exploited issues this year despite the uptick,” per CISA's KEV. www.bloomberg.com/ne…
  • @patrickhowelloneill.com Patrick Howell O'Neill on bluesky
    New: AI is driving new records in software vulnerabilities but prophecies of a so-called “bugpocalypse” haven't come to pass www.bloomberg.com/news/article...