CVE rates are exploding
After Nicholas Carlini’s famous talk at Black Hat conference this year, his predictions have become shockingly real. Critical bugs are being found at an alarming rate. This means patches are also coming at a never before seen rate – and system developers and software engineers must now deal with this historic flood of patches. How many? Most companies would release in the low double digits of bug fixes in a given period. Now we’re seeing hundreds – in mere days.
- Over 600 CVEs were identified in the Security Updates Guide across all of Microsoft’s products for July 2026 alone.
- Oracle dropped 1449 security patches in one week.
- 432 Linux kernel CVE’s were published in just one 24 hour period
None of this appears to be slowing – and we have AI to thank for it. AI is able to find bugs at a rate never before seen. It’s a reminder to the software development world, and especially security specialists, that they have been leaving a LOT of bugs and issues in some of the most secure software (BSD) that was undiscovered for decades.
Now people are talking about how to deal with astronomical numbers of patches coming out every week. It’s definitely something your production pipeline must be prepared for – because this will likely be the new normal for the rest of this year.