bloomberg.com web signal

Microsoft credits AI as 2026 vulnerability tally hits 45,207

cybersecurity microsoft ai-business

TL;DR

  • The US National Vulnerabilities Database has logged 45,207 flaws between January and Monday, on pace to roughly double the 2025 tally, per Bloomberg.
  • Microsoft fixed a record 570 vulnerabilities in July's Patch Tuesday, with its MDASH scanner surfacing 16 Windows networking and authentication bugs.
  • NIST is dropping routine enrichment of CVEs published before March 1, 2026, after moving roughly 29,000 backlogged entries to Not Scheduled.

The interesting number in Bloomberg's reporting this week is not the record itself, it is what it says about who is doing the finding. The US National Vulnerabilities Database has logged 45,207 software flaws between January and Monday, a count Bloomberg says is on pace to roughly double the 2025 tally. The driver, per the reporting, is increasingly capable AI systems being pointed at codebases.

Microsoft is the case study. In July's Patch Tuesday, the company shipped fixes for a record 570 vulnerabilities. On the Windows Experience Blog, executive vice president Pavan Davuluri credits a tool called MDASH, the Multi-Model Agentic Scanning Harness, that runs across the Windows codebase with multiple model families debating candidate findings before anything reaches an engineer. Microsoft says that pipeline surfaced 16 Windows networking and authentication bugs in this month's batch alone.

Why this matters if you are not writing patches: the constraint has quietly moved. Finding the bugs is no longer the bottleneck; triaging and patching them is. That is why NIST, on April 15, announced it is dropping routine enrichment of CVEs published before March 1, 2026, moving roughly 29,000 backlogged entries into a Not Scheduled bucket. Most enterprise vulnerability-management workflows run on NVD metadata. If it is not going to be there, the industry has to build a substitute or learn to live without.

The honest caveat is that a raw CVE count is a famously noisy signal, bent by duplicates, severity mix, and how vendors choose to split bugs into advisories. What the reporting does not give you is that severity breakdown, or any read on how much of this AI-driven acceleration is also flowing to offense rather than defense; take the doubling as a pace, not a settled year-end number.

The opening for the vendors already selling enrichment and prioritization, and for the MSSP layer above them, is unmistakable. The uncomfortable question for everyone else is whether patch cycles can absorb a doubled input without something breaking downstream.