As AI finds more vulnerabilities, patching work tightens
Diagnostics at the development stage in focus
Newly found vulnerabilities in software reached 36,000 in the six months from January to June 2026. The arrival of advanced AI such as Anthropic's Claude Mythos has increased detection counts, heightening the risk that manual fixes will not keep pace.
A vulnerability refers to a condition in which flaws or mistakes in code that runs software can trigger behavior that was not originally intended. Such issues can lead to system stoppages and unauthorized access, as well as information leaks through SQL injection and malfunctions that exploit buffer overflows. New registrations in CVE, a database that collects vulnerabilities disclosed worldwide, rose to about 48,000 in 2025, or 1.9 times the 2022 level. By June 2026, the total had already reached about 36,000.
The asymmetry between attack and defense
Anthropic has said it found a large number of vulnerabilities with Mythos, and improving AI performance is seen as one factor behind the increase in detections. Undisclosed vulnerabilities are called zero-days, and advanced AI can find issues that have been overlooked for years. Even so, fixes require careful verification within limited staffing and budgets. The U.S. National Institute of Standards and Technology, which handles vulnerability analysis, has also said it will focus responses on the most urgent cases.
Junichi Murakami, a partner at PwC Consulting, points out that guidelines issued by cybersecurity bodies in Europe and Britain, as well as Japan's Ministry of Internal Affairs and Communications, do not assume autonomous vulnerability remediation by AI. In 2024, an update to security software from U.S. company CrowdStrike caused a major disruption to Microsoft's Windows operating system. Attackers can exploit AI-found vulnerabilities indiscriminately, while defenders must verify and patch them through experts, making cyber conflict around AI prone to become an asymmetric battle favoring the attacker.
Importance of pre-release diagnostics
An effective use for companies and organizations is vulnerability diagnostics during development or before release. Traditionally, the common approach was to launch software quickly and update it after release if problems emerged, but AI could reduce vulnerabilities at low cost. Going forward, there may also be cases in which clients require pre-release diagnostics in contracts.
Allowing AI to autonomously fix vulnerabilities found after release carries high risk, but it could be used to assist experts in their work. Shortening the time needed for fixes and making it possible to manage responses with limited staff will become important. Even so, eliminating vulnerabilities entirely is difficult. In July, the Japan Software Association, a general incorporated association based in Minato, Tokyo, released a proposal stating that there may be situations in which systems in operation or service delivery must be halted to address vulnerabilities. Service interruptions and switches to alternative services may increase in the future.
Enjoyed this article? Share it with your network!