AI Is Finding Twice as Many Cyber Flaws This Year
If you've felt like cyber risk has gotten harder to price, harder to underwrite, and harder to explain to clients this year, you're not imagining it. New data on software vulnerabilities backs it up, and the reason behind the spike has direct implications for how PEOs and their carriers think about cyber exposure going forward.
The Numbers Behind the Surge
According to a recent Insurance Journal report, the pace of newly discovered software security flaws is on track to roughly double in 2026 compared to last year. The U.S. National Vulnerabilities Database had already logged over 45,000 flaws by late July, nearly matching the entire 2025 total, which was itself a record year.
The scale of the jump shows clearly at the vendor level. Oracle's July software update alone patched over 1,400 vulnerabilities, compared to roughly 300 in the same update a year earlier. Microsoft disclosed over 600 bugs in July, nearly five times last year's count for the same month. Google's Chrome team found and fixed over 400 issues in a recent update, up from just 11 the year before.
Why It's Happening: AI Is Doing the Hunting
The driving force isn't that software suddenly got worse — it's that the tools used to find flaws got dramatically better. Security teams are increasingly using AI models to hunt for vulnerabilities at a scale and speed no human team could match. Google's Chrome engineering leadership pointed directly to advances in AI models as the reason behind its own team's "unprecedented" pace of discovery, and most of the vulnerabilities Chrome found in July came from Google's own internal AI-assisted review — not outside researchers.
The flip side of that story is what's worrying about regulators and insurers: the same AI capability that helps defenders find flaws can also help attackers exploit them. The average time it takes an attacker to turn a known vulnerability into a working exploit dropped sharply this year, and there's already at least one documented case of an AI system autonomously breaching another company's systems in a matter of hours rather than weeks.
What This Means for PEO Cyber Risk
For PEOs and their insurance partners, this isn't just an IT-department headline — it's a shift in the underlying risk calculus for cyber liability coverage:
The vulnerability pipeline is accelerating. More flaws being found, faster, means the patching workload for every client company using standard business software (payroll systems, HR platforms, benefits portals) is growing too. Client companies that fall behind on patch cycles are more exposed than they were a year ago.
Exploitation speed is compressing response windows. If attackers can go from vulnerability disclosure to working exploit in about a day, the margin for error on patch management and incident response planning is shrinking fast.
Not all bad news. It's worth noting that despite the flood of newly discovered flaws, government tracking hasn't shown a corresponding rise in vulnerabilities being exploited in the wild — a reminder that "more flaws found" isn't automatically "more breaches happening." Some of the doom-and-gloom framing may be getting ahead of the actual exploitation data.
The Takeaway for PEOs
Cyber liability has already become a standard conversation in PEO renewal meetings — this data gives that conversation sharper edges. It's a good moment to revisit client companies' patch management practices, confirm cyber coverage limits still make sense given how fast the threat landscape is moving, and make sure clients understand that "we haven't been breached yet" is a weaker security posture than it was twelve months ago.
Source: Insurance Journal, "AI Finding Twice as Many Cyber Flaws in 2026 as It Did in 2025," July 28, 2026