Critical Software Vulnerabilities Top 600 a Month

Rapid rise in critical CVEs and near-immediate exploitation risk

Critical software vulnerabilities are being disclosed at an unprecedented reported rate, placing greater pressure on organisations to identify and address exposed systems quickly. New figures published on 7 September 2026 indicate that critical disclosures have risen from single digits to more than 600 in some recent months.

The increase is accompanied by a sharp reduction in the time between disclosure and exploitation. According to the reported data, the median time to exploit is now approximately one day, while a large proportion of exploited vulnerabilities are attacked by the day they become public.

Critical software vulnerabilities surge in 2026

Research attributed to Epoch AI indicates that disclosures of high and critical severity vulnerabilities began rising rapidly in spring 2026. The figures cover 21 notable technology organisations, including Microsoft, Google, Apple, Adobe, Oracle, Cisco and IBM.

By June 2026, these organisations had reportedly disclosed around 1,500 high and critical severity Common Vulnerabilities and Exposures, or CVEs. That total was more than 3.5 times the previous monthly record recorded before the release of Anthropic’s Claude Mythos Preview.

The growth continued during July 2026. Approximately 2,500 high and critical severity vulnerabilities were disclosed that month, according to the report. This represented an increase of about 60 percent compared with June and was nearly five times the baseline recorded before the Anthropic release.

The reported totals require careful interpretation. They combine high and critical severity CVEs across multiple vendors, while a separate claim says critical severity CVEs alone rose from single figures to more than 600 in recent months. The source does not provide a complete underlying list that would allow each monthly total, severity rating or affected product to be independently assessed.

Vendors, products and versions covered

The research names major technology suppliers rather than a single affected platform. It does not identify all product names, editions or version ranges represented by the reported critical software vulnerabilities. Organisations should therefore not treat the aggregate totals as a substitute for reviewing individual vendor advisories.

Users of software and services from the named vendors may be affected where a disclosed CVE applies to a product and version deployed in their environment. However, the research does not suggest that every product from Microsoft, Google, Apple, Adobe, Oracle, Cisco or IBM contains one of these flaws, or that every disclosed vulnerability is being exploited.

AI discovery drives critical software vulnerabilities

Researchers linked much of the disclosure surge to Anthropic’s Project Glasswing, described as an AI-powered vulnerability discovery initiative. The project reportedly surfaced more than 10,000 high or critical severity weaknesses, although many had not been disclosed individually by 7 September 2026.

This distinction is important. A discovered weakness does not automatically become a public CVE, and disclosure may be delayed while a vendor investigates the finding, develops a patch and coordinates publication. Several findings can also relate to the same product or underlying coding issue.

The available information does not establish whether software quality has suddenly deteriorated or whether AI-assisted tools are finding existing weaknesses more efficiently. The reported rise could reflect both factors, alongside changes in classification and reporting. What has clearly changed is the volume and speed at which potential security defects can be identified.

AI-assisted discovery can analyse source code, test application behaviour and generate inputs intended to trigger unexpected conditions. When this process identifies a crash, access control failure or other abnormal response, researchers can investigate whether it creates a practical path to data exposure, privilege escalation, remote code execution or another security impact.

Exploitation windows fall to around one day

The disclosure volume is only one part of the event. Data attributed to ZeroDayClock indicates that the zero-day rate has climbed to nearly 87 percent. In this context, the rate refers to the proportion of exploited vulnerabilities attacked on or before their public disclosure date.

The report says this figure is approximately 60 percent higher than in 2025 and almost four times the rate recorded in 2020. It also places the current median time to exploit at around one day, substantially reducing the opportunity to apply a patch after a vulnerability becomes public.

Historical figures included in the report illustrate the speed of this change. In 2018, the median period between disclosure and the first observed exploitation was said to be 771 days. It fell to about six days by 2023 and to a matter of hours during 2024.

Researchers cited in the article projected that median exploitation time could fall to one minute in 2027. That is a forecast rather than a confirmed outcome, but it reflects concern that automated vulnerability analysis, exploit development and internet scanning are compressing the attack timeline.

How attackers use newly disclosed flaws

Once a security advisory or patch is released, attackers can compare updated and previous software versions to identify the corrected code. This process, commonly called patch comparison or patch diffing, can reveal the location and nature of a vulnerability even when an advisory contains limited technical detail.

Attackers can then scan internet-accessible systems for matching products and test exploit code against unpatched targets. Automation allows these activities to occur at scale. If exploitation began before disclosure, defenders may also need to investigate whether systems were compromised before a fix became available.

The reported exploit survival curve reinforces that risk. This measure tracks the proportion of eventually exploited CVEs that remain unexploited over time. It now reportedly falls to zero within about 1.5 months of disclosure, meaning all vulnerabilities in that measured group which will eventually be exploited have been attacked by that point.

In 2022, half of the vulnerabilities that would eventually be weaponised were still unexploited after 1.5 months. A substantial proportion remained untouched at three months. The new figures suggest that a patching cycle measured only in weeks may no longer match the exploitation timeline for the most exposed critical software vulnerabilities.

Who is affected by the vulnerability surge?

The immediate impact falls on organisations operating products covered by the individual vendor disclosures, particularly systems accessible from the internet or capable of providing privileged access. Managed service providers and software suppliers may also need to assess whether vulnerable components are present within services delivered to customers.

The current exploitation figures are aggregate measurements. They do not confirm active exploitation of all 1,500 CVEs reported in June or all 2,500 reported in July. Exploitation status, affected versions, prerequisites and available fixes must still be established from each vendor’s advisory and trusted vulnerability catalogues.

Why the shorter window matters

The combination of more critical software vulnerabilities and faster weaponisation increases the number of urgent decisions security teams must make. Traditional monthly patching may leave a high-risk, internet-facing service exposed during the period when attackers are most actively searching for targets.

Teams may also encounter disclosures before patches are available. In those cases, the practical response depends on vendor-specific mitigations, exposure reduction and monitoring for indicators associated with that particular vulnerability.

Actions organisations should take now

  • Review September 2026 and recent vendor advisories for the named suppliers, matching affected products and exact versions against the asset inventory.
  • Prioritise confirmed critical software vulnerabilities affecting internet-facing systems, identity infrastructure, remote access services and products with known exploitation.
  • Apply vendor patches or documented mitigations rather than relying on severity scores alone.
  • Where no fix is available, consider disabling the affected feature, restricting external access or isolating the system, where the vendor recommends those measures.
  • Check logs and endpoint or network alerts for exploitation attempts when an advisory indicates attacks began before public disclosure.

Originally reported by cybersecuritynews.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call