When Finding Bugs Becomes the Easy Part

By Kampourakis Vyron, Researcher, NTNU

For most of cybersecurity’s history, finding a serious vulnerability has been difficult. It takes time, patience, technical skills and, of course, intuition. In other words, a security individual might spend days studying implementation, constructing malformed inputs, tracing protocol states or reproducing a crash before being confident that a vulnerability is real. We built tools to automate and accelerate this work. Static analysis found suspicious code. Fuzzers generated millions of unexpected inputs. Scanners searched for known weaknesses. But the process still had an important constraint: human attention. But, artificial intelligence is beginning to change that constraint, with the numbers suggesting that vulnerability discovery itself is already entering a period of extraordinary growth.

The CVE Program [1] recorded 28,961 published vulnerabilities in 2023. That rose to 40,077 in 2024 and 48,244 in 2025. FIRST [2] now projects approximately 66,000 CVEs for 2026. If that forecast holds, annual disclosures will have more than doubled in just three years. Obviously, AI is not solely responsible. Better reporting, more CVE Numbering Authorities and increased security research all contribute to the rise. But FIRST specifically identifies AI-assisted vulnerability discovery as one of the structural forces accelerating it. The interesting question is no longer simply whether AI will help us find more vulnerabilities. It already is. The more important question is: What happens when finding vulnerabilities becomes easier than dealing with them?

From workshop to factory

Traditional vulnerability research can feel a little like craftsmanship. A security individual understands a system, forms a hypothesis, tests it, examines the result and adjusts the next experiment. Fuzzing industrializes part of that process. Machines can generate enormous numbers of inputs and explore behaviours that humans would have never been able to test manually. In the ongoing era, Large Language Models (LLMs) add something different. They can reason about source code, configuration files, APIs, protocol messages and documentation. Instead of simply mutating an input, an AI-assisted system can increasingly help decide what might be worth testing next.

The shift is already visible among security researchers. HackerOne reported in 2025 that around 70% of surveyed researchers were using AI in their workflows [3]. In the same vein, autonomous security agents had begun submitting valid vulnerability reports, with more than 560 accepted reports attributed to autonomous “hackbots”. Combine AI reasoning with fuzzers, scanners and automated testing, and vulnerability discovery begins to look less like a workshop and more like a production line. On the first reading, that sounds like excellent news for defenders. And in many ways, it is. But every factory creates another problem. Someone must deal with what comes off the production line.

The Warehouse Fills Up

Imagine that a security team is currently handling 50 meaningful vulnerability findings in a month. Now make that 500. Or 5,000. Naturally this exponential rise leads to the first challenge: are they all real? A crash is not necessarily an exploitable vulnerability. A suspicious execution path may never occur in a real deployment. Ten apparently different findings might represent the same underlying defect. Someone or some system still must reproduce the problem, understand the affected environment, estimate its severity and determine whether an attacker could realistically exploit it. Despite the dramatic increase in disclosed vulnerabilities, FIRST [2] reports that the volume of vulnerabilities representing more actionable exploitation risk has remained relatively flat when filtered using indicators such as CISA’s Known Exploited Vulnerabilities catalogue or higher Exploit Prediction Scoring System (EPSS) probabilities. Simply put, more vulnerabilities do not necessarily mean proportionally more dangerous vulnerabilities. That distinction matters. AI may make discovery abundant while leaving validation scarce. The bottleneck moves.

Twenty Thousand Critical Vulnerabilities

Security teams already struggle with prioritization. A vulnerability can receive a severe technical score yet pose limited practical risk. Another apparently modest weakness may sit on an internet-facing system protecting a critical business function. Increasing the number of findings magnifies that problem. For example, if an AI system reports 20,000 potential vulnerabilities, handing all 20,000 to a security team is not intelligence. It is mostly noise. Therefore, future AI-based security systems will need to do more than discover weaknesses. They will need to provide evidence. Can the flaw be reproduced? Under what conditions? What does successful exploitation actually achieve? Which systems are affected? Is the vulnerability reachable in the real environment? And perhaps most importantly: why should this vulnerability be fixed before the other 19,999? There is also less time available to answer those questions.

Google’s Mandiant [4] analyzed vulnerabilities exploited in the wild during 2023 and found that, among vulnerabilities first exploited after disclosure, exploitation could follow disclosure remarkably quickly. In one category, the median time from disclosure to exploitation was only 15 days. Discovery is accelerating while the window for response remains unforgiving.

Beyond Code

There is a tendency to discuss AI-generated vulnerabilities as if the problem begins and ends with source code. It does not. Wireless networks, connected devices, industrial systems and other cyber-physical environments introduce a different kind of complexity. A vulnerability may emerge from a particular sequence of protocol messages, a device state, an authentication exchange, a timing condition or an unexpected interaction between several components. Consider an authentication protocol. Traditional fuzzing can explore enormous numbers of malformed messages. An AI-assisted system can potentially go further, reasoning about protocol structure and deliberately exploring unusual state transitions. The machine is no longer only changing inputs. It is beginning to make decisions about which inputs are worth trying. And in cyber-physical environments, the consequence of getting that decision right may extend beyond a software crash to operational disruption.

Discovery Is Only Half the Problem

The vulnerability race is changing. Stakeholders that benefit most from AI-driven security may not be those that discover the greatest number of vulnerabilities. They may be those that are best at determining which vulnerabilities are real, exploitable and relevant. That requires validation, context and prioritization. It also requires resisting one of the easiest mistakes to make with generative AI: confusing a convincing explanation with evidence. An AI system may produce an excellent argument for why a vulnerability appears exploitable. Security still must prove it. For years, one of cybersecurity’s central questions has been: Can defenders find the vulnerability before attackers do? AI adds another: What happens when both can find vulnerabilities faster than humans can understand, prioritize, and fix them? That is the transition organisations should be preparing for. Because once the vulnerability factory starts running, finding the bugs may become the easy part.

References

[1]: Published CVE Records. https://www.cve.org/About/Metrics

[2]: The 2026 Vulnerability Forecast Update: Navigating the AI Epoch. https://www.first.org/blog/20260615-vulnerability-forecast-update

[3] HackerOne Report Finds 210% Spike in AI Vulnerability Reports Amid Rise of AI Autonomy. https://www.hackerone.com/press-release/hackerone-report-finds-210-spike-ai-vulnerability-reports-amid-rise-ai-autonomy

[4] How Low Can You Go? An Analysis of 2023 Time-to-Exploit Trends. https://cloud.google.com/blog/topics/threat-intelligence/time-to-exploit-trends-2023

Hot Topics

Related Articles