Open Source

AI's Role in Exposing Hidden Vulnerabilities Across Open Source and Proprietary Software

As artificial intelligence becomes more adept at discovering security flaws, vulnerability reports are surging—but the rise may reflect better detection rather than declining software security.

4 min read
Fresh Eyes on Old Code: AI and Open Source Security

The Paradox of Rising Vulnerability Reports

Modern software development relies heavily on open source components. Teams assemble applications from databases, libraries, frameworks, cryptographic tools, web servers and countless smaller packages rather than building from scratch. This approach has accelerated development cycles dramatically, yet it raises a critical concern: when organizations adopt external code, do they also inherit its security weaknesses?

The raw data appears alarming. The US National Institute of Standards and Technology reported in April 2026 that CVE submissions jumped 263% between 2020 and 2025. Early 2026 submissions were already nearly one-third higher than the same period in 2025. NIST processed close to 42,000 CVEs in 2025 alone, a volume that has forced the National Vulnerability Database to reconsider how it operates.

This explosion could suggest that software—particularly open source—is becoming demonstrably less secure. Yet a parallel development complicates that interpretation: machine learning systems are now far more effective at locating vulnerabilities that existed long before anyone detected them.

AI as a Discovery Engine

Google's work with OSS-Fuzz illustrates the distinction. By deploying large language models to create fuzzing targets, Google expanded test coverage across 272 C and C++ open source projects, reaching more than 370,000 additional lines of code previously untested. The effort uncovered 26 previously unknown vulnerabilities, including CVE-2024-9143 in OpenSSL—a flaw that may have persisted for roughly two decades.

The key insight: AI did not introduce the vulnerability. Rather, it developed a more efficient method to uncover it. Google's Big Sleep project reinforced this pattern, using AI-driven vulnerability research to identify previously hidden defects in widely used open source software, such as a memory-safety issue in SQLite.

This trend will likely accelerate. AI systems can scan code continuously, trace execution paths, generate test cases and probe potential flaws at volumes impossible for human researchers to match alone. Open source faces particular exposure because source code is publicly accessible, allowing AI to examine every function, benchmark code against known vulnerability signatures and test countless input variations.

This creates a statistical reality worth considering: if detection capabilities improve substantially, reported vulnerability counts will naturally climb. But rising vulnerability reports do not automatically signal that underlying software has grown less secure. They may instead indicate that visibility into existing insecurity has sharpened.

Proprietary Software Faces Similar Pressures

Proprietary vendors are deploying the same technology. Microsoft, in May 2026, described MDASH, a system employing more than 100 specialized AI agents to examine proprietary code. The system identified 16 previously unknown vulnerabilities in the Windows networking and authentication stack, including four critical remote-code-execution flaws.

Vulnerability counts in proprietary enterprise software are equally substantial. Tenable reported that Microsoft's September 2026 Patch Tuesday covered approximately 964 CVEs, with 104 rated critical. SAP's August 2026 Security Patch Day included 28 new security notes, several with CVSS scores between 9.1 and 10.0, followed by 19 additional notes in September, including one rated CVSS 10.0. Oracle's July 2026 Critical Patch Update was even larger, containing 1,448 new security patches—410 affecting E-Business Suite and 355 affecting Fusion Middleware.

Oracle's own disclosures highlight a blurred boundary: the company notes that patch counts include vulnerabilities in both Oracle and third-party components, making it increasingly difficult to separate proprietary from open source software in practice.

Visibility, Not Vulnerability, May Be Changing

The evidence does not support the conclusion that open source is inherently less secure than proprietary alternatives. Open source may simply be becoming more transparent. Its public nature allows researchers, security vendors and AI systems to inspect code systematically. Proprietary software can harbor identical defect classes, but they often remain undetected until a vendor, customer, researcher or attacker stumbles upon them.

For enterprise teams, the relevant question shifts. Rather than debating whether a component is open source or proprietary, organizations should ask: Do we know what software we run? Can we identify vulnerabilities quickly? Can we patch affected systems before attackers exploit them?

AI will almost certainly drive reported vulnerability numbers significantly higher in coming years, potentially making the industry appear less secure initially. In reality, the rise may simply reflect the discovery of flaws that have existed for years. A vulnerability unknown to the world is no safer than one identified and patched. As AI transforms vulnerability research into an increasingly automated discipline, the uncomfortable climb in reported vulnerabilities may ultimately demonstrate that we are finally seeing the security problems that were always there.

Source: FOSS Force · Reporting supplemented by The Silicon Ledger staff.