AI’s Vulnerability Surge May Be More Manageable Than First Feared

A recent study has shed new light on the rapid acceleration of vulnerability discovery thanks to AI. At first glance, the numbers may seem daunting: monthly Common Vulnerabilities and Exposures (CVE) disclosures have risen 145% in just two years, with a staggering 49,979 vulnerabilities disclosed in 2025 alone. But according to Echo’s Mythos Readiness Report, which analyzed nearly 40,000 CVE life cycles across 250 open source container projects, the situation may not be as dire as feared for enterprise security teams.

The key to managing this surge lies in quickly validating findings, prioritizing risk, and getting available fixes into production. AI has indeed accelerated one side of the equation – vulnerability discovery – while the other side, remediation, remains largely manual. Echo’s research found that vulnerabilities are now being discovered at machine speed, but it takes significantly more time to address them. This gap in efficiency is particularly concerning given the growing number of known CVEs in popular container base images such as Node and Python.

The report also highlighted the role of Anthropic’s Claude Mythos in fundamentally changing the economics of exploit development. According to Echo, Mythos has made it possible for researchers and bad actors alike to develop a working exploit for a known vulnerability in less than one day and for under $2,000. This alarming trend raises questions about the preparedness of organizations to deal with such an onslaught of vulnerabilities.

However, Echo’s findings also offer some much-needed optimism. While AI tools are discovering a vast number of potential vulnerabilities, many of these turn out to be less serious than initially assumed. In fact, fewer than 10% of the 23,019 potential vulnerabilities discovered by Mythos had been externally validated or independently checked. This means that security teams may not need to completely overhaul their vulnerability management strategies, but rather focus on infrastructure for quickly validating a larger number of vulnerabilities and remediating them efficiently.

Furthermore, Echo’s study revealed that at least some of the vulnerability management challenges organizations face are self-inflicted. A notable 89% of fixable vulnerabilities examined by Echo had a fix available, yet nearly 40% remained unresolved for more than six months. This suggests that organizations may need to take a closer look at their own patching and remediation processes rather than solely relying on AI-driven vulnerability discovery.

Ultimately, the Mythos Readiness Report paints a nuanced picture of the current state of vulnerability management. While AI has undoubtedly accelerated the pace of vulnerability discovery, it is not necessarily a reason for organizations to panic. With the right strategies in place – including efficient validation and remediation processes – security teams can better manage this surge and stay ahead of potential threats.


Source: Dark Reading — 2026-09-02