The Vulnerability Curve Bent With the AI Curve
Summary
The global vulnerability landscape has dramatically shifted, with Common Vulnerabilities and Exposures (CVEs) increasing from 18,000 in 2018 to nearly 50,000 in 2025, coinciding with the rise of AI models like ChatGPT and GPT-4. This surge includes a doubling of high-severity CVEs, overwhelming defensive capabilities. Critically, the average time-to-exploit has turned negative, moving from 63 days in 2018-2019 to approximately -7 days by 2025, meaning vulnerabilities are often exploited before public disclosure. This is partly due to AI systems generating exploits in 10-15 minutes. The National Vulnerability Database (NVD) backlog exceeded 27,000 CVEs by late 2025, leading NIST to cease enriching older entries. Concurrently, malicious open-source packages in the software supply chain surged from 123,000 (2019-2022 combined) to over 1.35 million by 2026, with projected costs reaching \$69 billion in 2026.
Key takeaway
For MLOps Engineers or AI Security Engineers managing modern software stacks, your traditional vulnerability management strategies are now insufficient. With average time-to-exploit being negative and AI-driven attacks occurring in minutes, you must shift to continuous, automated security operations. Prioritize tools that provide real-time exploitability proof and rapid remediation guidance to close the exposure gap before attackers weaponize new flaws.
Key insights
AI's rapid advancement has inverted the vulnerability timeline, making proactive defense impossible with traditional methods.
Principles
- Vulnerability volume outpaces human triage capacity.
- Zero-day exploitation now dominates attack vectors.
- Patching velocity is critical for defense.
In practice
- Implement continuous vulnerability scanning.
- Prioritize rapid patch deployment.
- Automate exploitability proofing.
Topics
- AI Security
- Vulnerability Management
- Zero-Day Exploits
- Software Supply Chain
- NVD Backlog
- Automated Security
Code references
Best for: CTO, VP of Engineering/Data, Executive, AI Security Engineer, MLOps Engineer, Director of AI/ML
Related on AIssential
See Counsel's argued verdicts on the open AI decisions leaders are weighing →
Editorial summary, takeaway, and curation by AIssential. Original article published by ProjectDiscovery Blog.