Record WatchRecord
A record quarter for AI-software vulnerabilities: 900 in 2026Q2
25 July 2026 · Timeframe: By quarter; record across tracked quarters
900 vulnerabilities in AI and machine-learning software were disclosed in 2026Q2, the most in any quarter we have tracked. The AI attack surface is expanding as the software ships, though the volume is still a fraction of the overall CVE count.
Why it matters
AI-software vulnerability volume is the concrete counter to both the hype and the complacency: it is real and growing, but it is a measured trend, not a tsunami.
What to do
- CISOs. Add the AI/ML tools you actually run to your asset inventory; a record quarter is a prompt, not a panic.
- Lean IT orgs. Track your AI/ML software as its own class now, before the volume compounds.
- MSPs. Offer AI-asset tracking to clients as a differentiated service ahead of the curve.
Our take
A record but measured quarter of AI-software CVEs is exactly the evidence-first framing that beats selling the flood. Real, growing, and quantified.
The data behind this