Epoch AI data shows AI-driven vulnerability discovery pushed monthly critical CVE reports to more than 3.5 times the previous record.
In June 2026, 21 organizations reported roughly 1,500 high-severity and critical vulnerabilities — more than 3.5 times the previous monthly record — according to data charted by Epoch AI [1].
The surge matters for anyone who ships or secures software: AI models are now finding exploitable bugs at a pace that manual research never approached, and the disclosure pipeline is only beginning to clear [1].
What’s driving the numbers
Epoch AI attributes the jump directly to a wave of AI-driven discoveries [1]. The trend accelerated after Anthropic announced in April that its model Claude Mythos Preview can autonomously find software vulnerabilities [1]. Anthropic said trusted partners were already using the model to find and fix bugs before its public release [1].
Anthropic’s internal program, called “Glasswing,” has reportedly uncovered more than 10,000 high-severity or critical vulnerabilities to date, and some of those findings have not yet been published [1]. OpenAI runs a parallel effort called “Daybreak,” which is also likely contributing to the overall spike, according to Epoch AI [1].
What it means in practice
For developers and security teams, the practical implication is a disclosure backlog: a portion of the 10,000-plus Glasswing findings are still unpublished [1], meaning patches and mitigations for some critical issues have not yet reached the public. Organizations relying on CVE (Common Vulnerabilities and Exposures) feeds to prioritize remediation may be looking at a sustained surge in new entries as that backlog clears.
Epoch AI’s data shows the June 2026 figure of roughly 1,500 critical and high-severity CVEs from 21 organizations as the clearest single-month signal yet of how AI-assisted research is reshaping the vulnerability disclosure pipeline [1].
Sources
This article was drafted with AI from the cited sources and checked against them before publication. Spot an error? Let us know.



