Critical Software Vulnerabilities Surge 500% Monthly
Key Takeaways Critical and high-severity software vulnerabilities have seen an unprecedented surge, increasing by 500% monthly. This dramatic rise is largely attributed to AI-powered vulnerability...
Key Takeaways
- Critical and high-severity software vulnerabilities have seen an unprecedented surge, increasing by 500% monthly.
- This dramatic rise is largely attributed to AI-powered vulnerability discovery initiatives, such as Anthropic’s Project Glasswing.
- The window for exploitation has drastically shrunk, with the median time to weaponize a flaw now around one day, down from 771 days in 2018.
- Major technology vendors including Microsoft, Google, Apple, Adobe, Oracle, Cisco, and IBM are affected by these disclosures.
- Defenders face an escalating challenge, as attackers are weaponizing vulnerabilities almost immediately after disclosure, often before patches are available.
Unprecedented Surge in Critical Software Vulnerabilities Reshapes Threat Landscape
The cybersecurity landscape is undergoing a rapid transformation, with new data revealing a dramatic increase in critical and high-severity software vulnerabilities. Epoch AI’s latest analysis indicates that disclosures from leading technology firms have skyrocketed since early spring, climbing from a few hundred per month to over 600. Notably, critical-severity CVEs alone have surged from single-digit figures to more than 600 in recent months, marking a 500% monthly increase.
Table Of Content
AI-Driven Discovery Fuels Disclosure Explosion
By June 2026, a collective of twenty-one prominent organizations, including industry giants like Microsoft, Google, Apple, Adobe, Oracle, Cisco, and IBM, had disclosed approximately 1,500 high- and critical-severity CVEs. This figure represents more than 3.5 times the previous monthly record, which was set prior to the release of Anthropic’s Claude Mythos Preview. The upward trend continued relentlessly into July, with disclosures reaching roughly 2,500—nearly five times the pre-Mythos baseline and a 60 percent increase over June’s already record-breaking totals.
Researchers widely attribute this explosion in disclosures to Anthropic’s Project Glasswing, an AI-powered initiative specifically designed for vulnerability discovery. This program has reportedly uncovered over 10,000 high- or critical-severity flaws, many of which are still awaiting individual public disclosure. While it remains unclear if this reflects an actual increase in exploitable weaknesses or simply a more efficient method of identification and classification, analysts concur that AI-assisted tools have fundamentally accelerated the pace at which software flaws are brought to light.
Exploitation Window Shrinks Dramatically
Compounding the challenge of increased disclosures is a parallel and alarming trend: the drastically reduced time attackers require to weaponize newly discovered flaws. According to ZeroDayClock, the zero-day rate—defined as the percentage of exploited vulnerabilities attacked on or before their public disclosure—has climbed to nearly 87 percent. This represents approximately a 60 percent increase from last year and is almost quadruple the rate observed in 2020.
The median time to exploit a vulnerability now stands at approximately one day, a stark contrast to the 771 days recorded in 2018. By 2023, this window had shrunk to roughly six days, and by 2024, it was measured in mere hours. Some researchers even project that this median time could compress to just one minute by next year.
The “exploit survival curve,” which tracks the percentage of eventually-exploited CVEs that remain unexploited over time, now plummets to zero within about 1.5 months of disclosure, reads the report. This is a significant shift from 2022, when half of all eventually weaponized exploits were still untouched at the 1.5-month mark, with a substantial portion remaining unexploited even after three months. Today, cybersecurity defenders effectively have no buffer once a vulnerability becomes public.
Security teams accustomed to patching cycles measured in weeks are now forced to operate in an environment where exploitation can commence before a fix is even made available. Ransomware operators have quickly adapted to this new reality, with over half of ransomware-linked CVEs in 2025 initially identified through zero-day exploitation, a sharp increase from the previous year.
Industry analysts observe that AI is reshaping both offensive and defensive cybersecurity strategies, accelerating the discovery of flaws while also promising to enhance automated defense and detection capabilities. For the immediate future, organizations that delay patching by even a few days are increasingly likely to find their systems compromised before mitigation can occur.
What You Should Do
- Prioritize patching critical and high-severity vulnerabilities immediately upon release, aiming for a response time of hours, not days or weeks.
- Implement automated vulnerability scanning and patch management systems to accelerate detection and deployment of fixes.
- Adopt a proactive threat intelligence strategy to stay informed about newly disclosed vulnerabilities and active exploitation campaigns.
- Strengthen incident response capabilities, assuming that exploitation may occur rapidly after public disclosure.
- Regularly review and update security policies to account for the accelerated pace of vulnerability discovery and exploitation.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.