Dev.to
7/15/2026

Microsoft's monthly CVE count tripled after AI-powered vulnerability discovery ramp-up
Original: Microsoft said the patches would get bigger. I measured how much bigger.
Short summary
An independent analysis of Microsoft's CVE data shows monthly security patches tripled from a 383-CVE baseline to 1,150 in July 2026, with median CVSS rising from 6.5 to 7.5. Microsoft's MDASH agentic scanning harness—over 100 agents using multi-model debate—re-found 96-100% of known vulnerabilities in key Windows drivers, revealing a massive pre-existing backlog rather than a bug explosion. The author transparently addresses data caveats and rejects cherry-picked denominators.
- •Microsoft's monthly CVE count tripled to 1,150 in July 2026, with severity rising alongside volume
- •MDASH agentic harness re-found 96-100% of five years of known bugs in clfs.sys and tcpip.sys
- •The 'bug explosion' is actually a backlog—human attention, not bug scarcity, was the bottleneck
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



