The number of documented software security weaknesses discovered so far in 2026 has climbed sharply, with the U.S. National Vulnerabilities Database recording 45,207 flaws between January and Monday. That figure is close to the total number cataloged during all of 2025, indicating a near doubling in the pace of vulnerability identification.
The database, which catalogs digital security holes that can be exploited by hackers for criminal acts or espionage, shows a dramatic uptick in reported defects affecting widely used technology products.
Large July patch volumes from major vendors
Several major technology companies disclosed far larger-than-normal July patch tallies compared with the prior year. Oracle Corp. (NYSE:ORCL) issued 1,449 security fixes in its July software update, eclipsing its July 2025 package of 309 patches and marking a record monthly total for the company.
Microsoft Corp. (NASDAQ:MSFT) disclosed 642 security bugs in July, nearly five times the number it reported for the same month in 2025. Alphabet Inc.'s (NASDAQ:GOOGL) Google identified and remedied 433 bugs in a recent Chrome browser update, compared with 11 in an equivalent update one year earlier.
Expert view
Gabriel Shapiro, distinguished AI research scientist at cybersecurity firm SentinelOne Inc. (NYSE:S), said these tools are increasing people’s ability to find vulnerabilities in software.
Shapiro's observation links advancements in artificial intelligence to the accelerating rate of vulnerability discovery. The comment reflects an assessment that new tooling is amplifying researchers' and attackers' capacity to identify flaws.
Implications and context
The surge in reported vulnerabilities has manifested in record-sized patch releases by several large vendors, reflecting both a higher detection rate and a corresponding increase in remediation work required by software maintainers and users. The National Vulnerabilities Database continues to serve as a central repository documenting these issues and their potential for exploitation.
At present, the raw counts documented in the database and the patch figures announced by vendors underline a notable change in the volume of identified security flaws during 2026, but do not by themselves indicate the severity of each individual issue beyond what vendors have disclosed.