The vulnerability storm has begun: AI finds security flaws faster than firms can fix them
AI is accelerating vulnerability discovery and exploitation, widening the gap between vulnerabilities emerging and organisations fixing them. Combined with vulnerability chaining and rapidly changing exposure, severity alone is no longer enough to...

AI is making it faster to identify and analyse these relationships across vulnerabilities, configurations, identities, privileges and network paths.
AI is widening that gap
AI is accelerating how software is analysed, vulnerabilities are discovered and exploits are developed. Researchers can examine more code and uncover weaknesses faster, while attackers increasingly have access to many of the same capabilities.This is creating a fundamental asymmetry: vulnerability discovery and exploitation are moving toward machine speed, while remediation remains constrained by the realities of enterprise technology.
This is what I call the vulnerability storm. And the data suggests it has already begun. For enterprises, this is not simply a security operations problem. It is becoming a question of business risk: which exposures could disrupt critical services, affect customers or create material financial and regulatory consequences?
Five forces changing vulnerability management in the age of AI
1. Discovery is acceleratingVulnerability disclosure was already rising, but the pace has changed dramatically. Based on the current 2026 run rate, disclosure volume is projected to increase by almost 100% over 2025, pushing the annual total toward 100,000 vulnerabilities, according to the National Vulnerability Database (NVD), the US government's official public repository of standards-based cybersecurity vulnerability management data.
This is no longer incremental growth. It is a step change in the number of vulnerabilities security teams must assess, prioritise and remediate.

Volume is only one part of the problem. Across the large population of vulnerabilities disclosed in 2026, severity remains significant, with average CVSS (Common Vulnerability Scoring System) reaching 7.19 in August, according to NVD data. Security teams are therefore dealing not only with unprecedented vulnerability volume, but with a substantial population of materially severe vulnerabilities competing for attention.

Traditional vulnerability management largely evaluates findings individually. A CVSS 9.8 receives immediate attention, while a CVSS 5 or 6 typically sits much further down the remediation queue.
Attackers, however, do not operate one vulnerability at a time. A moderate vulnerability may provide initial access. Another may enable lateral movement. A misconfiguration may expose the next system. Excessive privileges may enable escalation. Individually, none may appear critical. Together, they can create a critical attack path.

4. Exploit construction is becoming easier
Recent incidents show how quickly a disclosed vulnerability can become operational. On September 22, 2026, CVE-2026-87902 was publicly disclosed in WordPress Core. Exploitation attempts were observed the same day, progressing from vulnerability probing to attempts to achieve code execution within hours. By the following day, public scanning tooling was already circulating.
The window between disclosure and operational exploitation is no longer reliably measured in weeks or even days. In some cases, it is measured in hours.

5. Context is changing faster
Organisations have always used context to prioritise vulnerabilities: asset exposure, criticality, configuration, security controls, privileges and threat activity. What is changing is the speed at which that context can change.
A vulnerability considered manageable today can become urgent tomorrow because a working exploit appears, an asset becomes internet-facing, a preventive control fails, privileges change or a new attack path emerges.
The CVE has not changed. The context has.
When context is collected periodically and a vulnerability is placed into a remediation queue, that assessment can become outdated within days or even hours. The challenge is no longer simply having the right context. It is keeping that context current enough to reassess priority as conditions change.
Even NVD has had to prioritise
The scale problem is already affecting the vulnerability ecosystem itself.In April 2026, the National Institute of Standards and Technology (NIST) acknowledged that despite enriching nearly 42,000 CVEs in 2025, it could no longer keep pace with growing vulnerability submissions. NVD moved to a risk-based enrichment model, prioritising vulnerabilities based on criteria including known exploitation, federal use and critical software. CVEs outside those priorities may remain Not Scheduled for immediate NVD enrichment.
That is an important signal. When a foundational source of vulnerability information has to prioritise what gets enriched, enterprises cannot assume every vulnerability will arrive with equally complete analysis.
Organisations increasingly need to combine vulnerability intelligence with their own environmental context to determine what actually matters.

Most organisations were not operating perfect vulnerability management programmes before AI arrived.
Coverage gaps, unauthenticated or failed scans, stale results, fragmented data, unclear ownership, remediation delays and weak closure validation already created blind spots.
A vulnerability cannot be prioritised if the asset was never scanned. A critical exposure can remain invisible when a scan fails. And a vulnerability cannot confidently be considered closed until remediation has been validated.
AI does not create these weaknesses. It increases the consequences of having them.

The obvious response is to patch faster. Organisations should automate wherever they safely can, but there are limits to remediation velocity.
Production changes require testing. Applications have dependencies. Critical systems have availability requirements. Patches can introduce operational risk. Some vulnerabilities have no immediate patch.
At the same time, regulators and boards are demanding faster remediation and greater accountability for cyber risk. The result is a growing remediation deficit: the queue can expand faster than enterprise teams can safely reduce it.
What appears to be a vulnerability-management problem is increasingly an operational risk and governance problem.
Vulnerability prioritisation has to change
For years, vulnerability programs have asked: How severe is this vulnerability? That question still matters. But it is no longer enough. The more important question is: What does this vulnerability mean to our organisation, right now?Answering it requires understanding severity alongside exploitability, exposure, business criticality, identity, privilege, and potential attack paths. But the traditional security playbook is fundamentally broken. We are playing a high-stakes game of catch-up where the adversary moves at the speed of compute, while defenders remain bogged down by legacy ticketing, application dependencies, and human validation cycles.
In this new paradigm, static severity scores are no longer a compass; they are noise. To survive the vulnerability storm, organisations must pivot entirely from calculating how broken a component is technically, to proving how exposed the enterprise is operationally.
In Part 2, we move past the problem statement to outline a practical blueprint: a context-driven framework designed to help security teams identify, validate, and dismantle critical attack paths in real time."
Sumit Malhotra is the Founder and CEO of SPOG.AI, a cyber-mesh software development company. The views expressed in this article are personal.
The Economic Times Business News App for the Latest News in Business, Sensex, Stock Market Updates & More.