Look at four numbers in sequence. In 2023 the world published 28,818 CVEs. In 2024, 40,009. In 2025, 48,185.1 In the first eight months of 2026, 53,373 - already more than any prior full year, arriving at 233 per day, or roughly one every six minutes.2
NIST's own language on this is unusually direct for a federal agency. Vulnerability submissions to the National Vulnerability Database rose 263% between 2020 and 2025.3
Every security program in the world is a queue. Findings arrive, get triaged, get assigned, get fixed. For thirty years that queue was survivable, because the arrival rate was survivable. That is no longer the case, and almost nothing about how enterprises staff, budget, or organize security has been rebuilt around the new arrival rate.
Here is the part most security leaders have not fully registered.
In 2025 the NVD enriched nearly 42,000 CVEs - a 45% increase over any prior year in its history, its single best year ever. It still fell behind. In April 2026 NIST formally conceded the point and moved every backlogged CVE published before March 1, 2026 into a category it calls "Not Scheduled." Enrichment is now reserved for vulnerabilities on the CISA KEV catalog, software used by the federal government, and critical software under EO 14028. Everything else is labeled lowest priority.
The practical consequence: as of this month, roughly 48% of the CVEs published in 2026 have never been analyzed by the NVD at all. Nearly half of new vulnerabilities cannot be automatically matched to the product they affect on the day they publish.
The reference data layer that the entire vulnerability management industry silently assumed would always be there did its best year of work in history and lost anyway. That is what a throughput failure looks like from the inside. It does not look like incompetence. It looks like a very good team running at maximum sustainable output while the input curve goes vertical behind them.
If it happened to NIST, it is happening to you.
Now the defender's side of the equation, measured.
Veracode and Cyentia's 2026 State of Software Security analyzed 1.6 million applications and 141 million findings and reported that the median organization fixes about 10% of its total vulnerability backlog each month, a rate that fails to keep pace with new flaw creation. Eighty-two percent of organizations carry security debt older than a year.
Verizon's 2026 DBIR, drawing on 515,170 KEV resolution records across 13,000 organizations, found that only 26% of KEV vulnerabilities were fully remediated, down from 38% a year earlier. Median time to remediate rose to 43 days from 32. Between 60% and 70% of KEV vulnerabilities remain open at day seven regardless of the organization's size or maturity. Forty-seven million vulnerability instances are simply never fixed at all.
Ten percent a month against an intake curve that has doubled in three years. That is the whole problem stated arithmetically. You do not solve it with a better ranking algorithm.
Attackers no longer operate on human timelines. Reconnaissance, exploit development, and lateral movement can now run as an automated pipeline, and the gap between a proof of concept going public and active exploitation in the wild has compressed to hours. That is not a window for analysis. It is barely enough time to open a ticket.
Security programs were built for a different threat model, one where attackers faced the same bottlenecks defenders did: skilled labor, manual effort, time. That symmetry is gone. AI removed it on the offensive side first, and the defensive side has not kept pace.
The measurements are unambiguous. CrowdStrike found that 88% of observed exploitation of vulnerabilities with a public proof of concept happened within 48 hours of the PoC going live. VulnCheck reports that 29% of vulnerabilities added to the KEV catalog in 2025 showed exploitation on or before the day the CVE was published. And Mandiant's M-Trends 2026 puts the mean time to exploit at negative seven days. Not seven days. Negative seven - exploitation is now routinely occurring before a patch is released.
Exploitation of vulnerabilities is now the single most common initial access vector in the DBIR at 31%, and exploits have been the most common initial infection vector in Mandiant's incident data for six consecutive years.
And the intent has industrialized. IBM's 2026 Cost of a Data Breach study found that one in four malicious breaches were AI-enabled, a 56% increase year over year, costing an average of $6 million. Anthropic mapped 832 accounts banned for malicious cyber activity between March 2025 and March 2026 and found the share operating at medium risk or above rose from 33% to 56% in a single year, with 80% of them using agentic coding tools rather than chat interfaces.
Median remediation of 43 days. Mean time to exploit of minus seven. There is no version of that spread that a ticketing workflow closes.
The part almost nobody is pricing in: defenders are the ones accelerating the arrival rate.
Sundar Pichai stated in April 2026 that 75% of all new code at Google is AI-generated and engineer-approved, up from 50% in fall 2025 and just over 25% in late 2024. Across four years and more than 100 models, Veracode measures the average security pass rate of AI-generated code at 56%. It has not moved. The best model available still fails nearly one in three security tasks.
Three times the code volume at a flat defect rate. GitGuardian measured it in the wild: AI-assisted commits leak secrets at 3.2% versus a 1.5% baseline across all public GitHub commits.
The same capability curve is being pointed at the output. Mozilla shipped Firefox 150 with fixes for 271 vulnerabilities found in a single AI-assisted evaluation, and noted that in 2025 any one of them would have been a red alert. Google fixed 1,072 security bugs across Chrome 149 and 150, more than the previous 23 milestones combined. HackerOne saw vulnerability submissions rise 76% year over year to a record in March 2026 - while the number resolved each month fell 46%, leaving a validated-but-unresolved backlog 21 times larger and unresolved criticals 25 times larger. Anthropic's own disclosure dashboard tells the cleanest version of the story: 1,596 vulnerabilities responsibly disclosed, 97 patched. A 6% close rate.
Discovery scaled. Remediation did not.
Here is what I want to be careful about, because it would be easy to read everything above as an argument about volume. It is not.
This is not primarily a numbers problem. The numbers are symptoms. The underlying condition is a speed mismatch between how fast risk arrives and how fast defenders close it, and that mismatch has one structural solution: removing human execution from the remediation loop.
Prioritization was the right response to the last version of this problem. When a team can work through 10% of the queue in a month and the queue is survivable, ranking it correctly is sound discipline. That logic still applies to everything it ever applied to. It stops applying the moment exploitation begins before the patch exists - which, per Mandiant's 2026 data, is now routine.
Ranking a queue does not shorten it. It only changes the order in which things go unfixed. Prioritization is not a strategy. It is a backlog with better labeling. In a world where every real risk can be exploited, every real risk must be remediated. The only acceptable outcome is zero remaining risk.
That is the throughput gap. Closing it is not a prioritization decision. It is an architecture decision.
You cannot win a machine-speed war with human-speed defenses. You fight it with machine-speed defense, governed by humans who set what the machine is authorized to do.
That distinction matters. This is not about removing human judgment. It is about removing human execution from a loop that is already over by the time a human touches it. A skilled analyst can thoroughly investigate 10 to 20 vulnerabilities a day. That is not a training problem or a headcount problem. It is a physical constraint, and no amount of budget moves it materially.
Which is why we did not build a better ranking engine. We built for throughput.
One Global 1000 customer had 2.5 million software composition analysis findings across 5,000 container images. Kai processed all of them in under an hour, eliminated 99.5% as false positives, and triggered auto-remediation for everything genuinely exploitable - work that saves that customer roughly 3 million engineering and security hours a year. In another environment, Kai investigated and triaged 250 million vulnerabilities from enterprise scanners in 20 hours, eliminated 83% as benign, and auto-remediated the rest. In a third, 10 million infrastructure findings triaged in three and a half hours, 4 million validated as real risk, 3.8 million auto-remediated, the remainder routed to Kai Assisted remediation.
That last number is the one that matters. Not findings surfaced. Findings closed.
Getting there is an architecture decision, not a model decision. Raw security data does not go straight into a language model at Kai. It passes through a harness - a layer of deterministic algorithms that ingests, cleanses, deduplicates, validates, and chunks every input before any of it reaches the reasoning layer. Autonomy without that discipline is not defense. It is a new attack surface with a friendly interface, and it is the reason most of what the market calls AI security is a chatbot on top of the same broken stack. When the foundation is fragmented, AI makes fragments faster.
It also settles where security teams belong. Humans set intent, define guardrails, and control the boundary between autonomous action and human review. The machine does the throughput.
Here is the uncomfortable close.
The capability to survive this transition already exists. It is running in production environments today. The organizations that get hurt over the next two years will not be the ones that lacked options. They will be the ones that had options and were still in procurement.
Our own research bears this out. In a survey of 500 CISOs at companies with $500 million or more in revenue, 63% said attackers currently hold the advantage because of AI. Sixty-five percent said their vulnerability management processes remain at least half manual. Sixty percent need more than a week to remediate a critical vulnerability. And only 32% permit automated remediation actions today.
An attacker does not have to onboard a hospital. A defender does. That asymmetry - not model capability, not budget - is what determines who is standing in 2028.
I remain convinced the long run belongs to defense. Machines that audit continuously, verify formally, and fix faster than anyone can weaponize are a better world than the one we have. But that world does not arrive on its own, and it does not arrive in time for anyone who waits for it. It gets built, by the organizations that decide the transition is happening now rather than later.
The ceiling is the problem. Raise the ceiling.
And we are just getting started.