securelist.com 8/26/2026, 10:21:04 AM · external

AI driven software surge fuels record Q2 2026 vulnerability spike

AI driven software surge fuels record Q2 2026 vulnerability spike
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Not in KEV
Patch Patch Available

THE report on vulnerabilities and exploits in Q2 2026 highlights a significant increase in registered vulnerabilities, largely due to the rising use of AI in software development. Key findings include a surge in critical vulnerabilities, with AI tools contributing both to discovery and exploitation. Noteworthy vulnerabilities include CVE-2026-25253 (OpenClaw), CVE-2026-41948 (Dify), CVE-2026-45386 (Open WebUI), and CVE-2026-45501 (Microsoft Exchange).

The exploitation cases indicate a trend where vulnerabilities are being published without waiting for CVE registrations, giving attackers a time advantage. The report advises organizations to adopt real-time monitoring and improve access controls alongside regular patch management.

View full article

Article by CyberSIXT