Software Vendors Just Shipped Records Numbers of Security Patches. Your Patch List Didn't Get Longer by Accident.
Something changed in how software vulnerabilities get found this year, and the numbers are startling: disclosed flaws are on pace to roughly double last year's already-record total, and the biggest names in software have each shattered their own patch-count records, sometimes by five times over. The cause isn't sloppier code. It's that the tools doing the looking got dramatically better — on both sides of the fight. Here's what's actually happening, and why the way you decide what to patch first matters more now than it ever has.
If your IT provider has seemed busier than usual with updates this year, that's not your imagination, and it isn't a coincidence specific to your systems. Something structural shifted in how software vulnerabilities get discovered in 2026, and the scale of it is large enough that security researchers are describing it as breaking the traditional model of patching altogether.
The core fact is simple to state and a little startling to sit with: the number of software vulnerabilities being found this year is on pace to roughly double last year's total — and last year was already an all-time record. The driver is automated, AI-assisted scanning, which can comb through code far faster and more thoroughly than human researchers working alone ever could. Software companies are increasingly using these tools on their own products, finding weaknesses before anyone else does — which is good news wearing an alarming costume, because it shows up as a wall of new patches rather than a quiet fix.
vulnerabilities were logged in the US government's vulnerability database between January and late July 2026 alone
That figure already approaches the total recorded for the entirety of 2025 — itself the biggest year on record at the time. With five months still left when that count was taken, 2026 is on track to roughly double it. This isn't a seasonal spike or a one-off event tied to a single product. It's a sustained, accelerating trend across the entire software industry.
The records, one after another
The clearest evidence isn't the aggregate number — it's what individual companies have been reporting about their own products, each one breaking its own prior record within the same few months.
Every one of those is an all-time record for the company involved, set within weeks of the last one. And in Google's case specifically, the company disclosed that 401 of the 433 Chrome fixes — nearly all of them — were found internally through its own AI-assisted security work, not reported by outside researchers. The company is finding its own problems faster than anyone else can, and the patch count is the visible evidence of that search succeeding.
The number that actually matters for your business
The record patch counts are the headline. The number underneath them is the one that should change how you operate. Independent research tracking real-world exploitation found that the median time for an attacker to turn a newly disclosed vulnerability into a working, usable attack fell from roughly 72 hours in 2025 to about 24 hours in 2026 — a threefold acceleration in a single year.
Put the two trends together and the shape of the problem becomes clear. The list of things that could theoretically be exploited is growing faster than any team can review. The window between "a flaw becomes public" and "someone is actively using it" is shrinking faster than most patch cycles can respond. Waiting for a monthly or quarterly update schedule, treating every disclosed vulnerability as equally worth your limited time, was already a losing strategy. This year made it a much more expensive one.
Why "patch everything" was never going to work — and definitely won't now
If you've read our earlier explainer on CVE, CVSS, and EPSS scores, this is the moment that argument stops being theoretical. Research from FIRST — the organization that maintains those scoring systems — already showed that patching strictly by severity score wastes the overwhelming majority of the effort involved, because most severe-sounding flaws are never actually exploited. That inefficiency was expensive when the list was smaller. At double the volume, treating every new disclosure as equally urgent isn't just wasteful anymore. It's mathematically impossible to keep up with.
Researchers tracking this shift describe it plainly: the traditional model of a scheduled, periodic patch cycle, working through a list roughly by severity, is breaking down under the sheer volume now involved. What's replacing it is a shift toward prioritizing by exposure and confirmed exploitation — is this actually reachable from the internet, and is it confirmed to be under active attack right now — rather than by a severity score alone.
What this means for a small business specifically
Stop trying to patch everything, and say so out loud
Mindset shiftIf your provider has been quietly falling behind an ever-growing patch list, that's not necessarily a sign they're doing a bad job — it may be a sign the list itself has become unmanageable using the old approach. Ask directly whether prioritization has shifted to focus on confirmed-exploited flaws on your internet-facing systems first, rather than working through everything in order of severity score.
Know which of your systems face the internet — that's where the 24-hour clock starts
FreeThe collapsing exploitation window matters most for anything reachable from outside your network. An internal system with a known flaw is a lower-urgency problem than the same flaw on something internet-facing. If you don't have a current list of what's actually exposed, that's the starting point before any prioritization discussion is useful.
Lean on automated update settings wherever they exist
Free · Set onceWith exploitation windows measured in hours rather than days, manual, scheduled patching cycles are increasingly too slow on their own for anything internet-facing. Where automatic updates are available — browsers, operating systems, many cloud services — turning them on removes the delay between a fix being available and it actually being applied.
The short version
Software vulnerabilities are being discovered this year at roughly double last year's record pace, and the biggest names in the industry have each shattered their own patch-count records within months. The cause is better search tools, mostly used defensively, mostly finding problems before attackers do — which is a genuinely good sign wearing an alarming-looking headline. The part that should change how you operate is quieter: the time between a flaw becoming public and someone exploiting it has fallen from three days to one. The list got longer. The clock got shorter. Knowing which few items on that list actually matter today is no longer a nice-to-have. It's the only version of "patched" that's still achievable.
Know which of today's tens of thousands of flaws are actually confirmed exploited — and relevant to you.
View the Threat Intelligence feed → Find Out More About Veriti Spottr →📚 Credential Security Series → Read the full series

Comments
Post a Comment