Cyber Resilience

The flood that came in slow

2026 has crossed a six-figure pace for the first time. It is still running several times under the LLM-discovery forecasts, and the reason is now the more interesting half of the story. Last updated: 23 August 2026 00:24 UTC

Two things are true about 2026 at once. It is on pace to be the highest-volume year for CVE disclosure on record. And it is running several times below the flood that consensus forecasts (ours included) predicted once large language models could hunt vulnerabilities at scale. Both facts matter, and the space between them is the interesting part.

81AI Hype Index (series low)
56,571published so far in 2026
102,213projected CVEs in 2026
2.0×the 2025 total of 49,972
30-Mar-202617-Aug-2026819481new low
AI Hype Index, weekly · security-resilience.ai

A record year, well below forecast

At the current pace, 2026 lands around 102,213 CVEs, a new high, up 105% on 2025's 49,972. Overall vulnerability volume is not plateauing; it is climbing. But the aggressive scenarios for LLM-assisted discovery pointed at a middle estimate near 328,534 for the year, and as high as 588,800. Measured against those, 2026 is a fraction of the projection. Our AI Hype Index, which scores real volume against those forecasts, reads 81/100, much closer to the pre-AI baseline than to the predicted explosion.

When this piece was first published the index read 86 by the series as we reconstruct it today. It now reads 81/100. Both the index and the pace have moved the same direction since. The flood is arriving. What it is not doing is arriving fast.

Why the undershoot? Three explanations

1. Discovery is concentrating, not exploding

The new attack surface (LLM application platforms, agent frameworks, the Model Context Protocol, enterprise AI assistants) is where researcher and model attention is pooling. That concentration produces intense, category-specific bursts (our AI-subcategory data shows it) rather than a uniform lift across the whole 250,000-CVE back catalogue. Firms are also shipping new software faster than they are re-auditing old software; discovery follows where the code and the interest are.

2. Guardrails are doing something

Frontier model providers restrict overtly offensive use, refuse weaponization prompts, and rate-limit at the API. Governments have layered on export controls and disclosure norms. None of this stops a determined researcher, but it raises the friction on large-scale, hands-off discovery, the exact mode that would produce the forecast flood. Friction doesn't cap the total; it slows the ramp.

3. The pipeline is staffed at both ends

Publication is not the end of the disclosure pipeline. A finding still has to be triaged, validated, coordinated and enriched, and those steps are done by people. Our own CVE records show what that costs. Of the CVEs published in 2024, NVD analysed 80.5%. Of those published in 2026 and old enough to have settled (before 25-May-2026), it has analysed 64.7%, while 31.7% carry NVD's "Deferred" status, which means it has said it will not enrich them at all.

One number is new this year. In 2024 and 2025 essentially nothing stayed unprocessed: 0.0% and 0.0% of each year's publications are still awaiting or undergoing analysis today. For 2026 publications of the same age, 3.6% are still unprocessed. Earlier years converged to nothing. This one has not yet.

The other end is the one defenders feel. Mean time-to-remediate has been climbing for years; the patch queue already grows faster than teams can drain it. In that world, flooding the disclosure pipeline helps no one: not vendors, not coordinators, not the researchers who want their finding fixed rather than shelved.

Discovery is the only elastic step in a chain that is staffed at both ends. A finding nobody can process and nobody can fix does not become safety. It becomes backlog.

What happens next? Two forecasts

A. The flood peaks lower, but lasts longer

If discovery is being paced by absorption capacity rather than by how many bugs exist to find, the curve doesn't spike and recede; it plateaus high and stays there. Expect sustained record volume for years rather than one dramatic AI-driven year. That is arguably harder to manage than a spike: a spike you surge-staff through; a plateau you have to build for.

B. Attackers adopt LLMs regardless

The guardrails and pacing that moderate public disclosure do not bind the offensive side. Attackers will use the same models to find and weaponize vulnerabilities without filing a CVE at the end. The discovery asymmetry then shifts quietly toward offense. And because the binding constraint on defenders is remediation, not awareness, the gap between what is known and what is fixed becomes the exposure that matters.

The takeaway

The flood is arriving into a pipeline whose throughput did not change. That is a different problem from the one most 2024 forecasts described, and a harder one, because none of the steps that absorb a finding scale the way discovery does. The leverage for a defender in 2026 is not a better scanner or one more feed. It is capacity: automation, patch-pipeline throughput, and the discipline to rank by real exploit risk. Build for the plateau, not the spike.

Figures on this page update by themselves from our live CVE records and the AI Hype Index.