Research2026-07-27

The number of software security flaws recorded in the US National Vulnerabilities Database is on pace to roughly double in 2026 compared with 2025, a rise attributed to more capable AI systems being used to hunt for weaknesses. The database logged 45,207 flaws between January and 27 July, already approaching the whole of last year's record total. The count reflects flaws found and reported, not attacks carried out.

What changed

2025 set the previous record for recorded software vulnerabilities, a total 2026 is already close to matching by late July.

  • 45,207 flaws recorded January to 27 July 2026
  • 2026 on pace to roughly double the 2025 tally
  • 2025 was an all-time record year for recorded vulnerabilities

Send this to someone who needs it

Shares the story and its sources. Nothing about you.

What does this mean for your job?

This is the story as everyone gets it. Once a week we send you the version written for your role — what changed, why it matters for the work you actually do, and one thing to try. Free while we tune it.