🎉 New here? Use code WELCOME10 for 10% off any plan at checkout
All posts

Cyber Risk Goes Parabolic: Critical CVEs Spiked 6× This Year — and AI Is Finding the Zero-Days

October 7, 2026 · PlayCISO
TL;DR

Two signals landed the same week and point the same direction. (1) A16z published a chart — “Cyber Risk Goes Parabolic” — built on Epoch.ai data covering 21 major software vendors (Adobe, AMD, Apache, Apple, AWS, Cisco, GitHub, Google, IBM, Intel, Linux, Microsoft, Mozilla, NVIDIA, OpenSSL, Oracle, Qualcomm, Red Hat, Samsung, SAP, VMware). For four years, reported CRITICAL-severity CVEs across that set essentially never cleared ~100 per month; since spring 2026 they have jumped past 600 per month, and HIGH-severity reports spiked toward ~2,200 per month — a near-vertical bend. (2) In an a16z conversation, Kevin Mandia — Mandiant’s founder — said his new company Armadin has, since January 2026, found 90+ zero-days at customer sites, all in production, scanning black-box from the internet with no source code, using models post-trained with real red-teamers who can actually develop exploits: “When you have an AI-based attack, it’ll find logic flaws rather than code flaws… It’ll exhaust all routes all the time.” Caveat first: the chart’s own authors note reporting procedures, labeling and cadence vary substantially between organizations, so some of the rise is better/faster disclosure, not purely more bugs — but the shape and Mandia’s field data agree that AI is compressing the time-to-find for exploitable flaws. The leadership takeaway: patch windows measured in weeks are now outrun by discovery measured in hours; prioritise by exploitability not raw count, shrink and watch your external attack surface, and rehearse the “RCE in your DMZ, found by an outsider” call. Sources: a16z (chart, data via Epoch.ai, 3 Sep 2026); Kevin Mandia / Armadin via a16z (David George).

This post references: https://a16z.news/subscribe
Critical and high-severity vulnerability reports bending into a near-vertical curve as AI accelerates exploit discovery

Two charts-worth of bad news arrived the same week, and they rhyme. First, a16z published a plot — bluntly titled “Cyber Risk Goes Parabolic” — showing reported critical- and high-severity vulnerabilities across 21 of the biggest software vendors bending into a near-vertical line in 2026. Second, Mandiant founder Kevin Mandia described finding 90+ zero-days in production at customer sites this year with AI that works black-box, from the internet, with no source code. One is the macro signal; the other is what it feels like from the field.

As always, we separate what is confirmed from what is reported or claimed — then get to what a security leader should actually do.

The chart: critical CVEs broke a four-year ceiling

The a16z chart uses data from Epoch.ai, counting monthly critical- and high-severity CVEs across 21 major vendors: Adobe, AMD, Apache, Apple, AWS, Cisco, GitHub, Google, IBM, Intel, Linux, Microsoft, Mozilla, NVIDIA, OpenSSL, Oracle, Qualcomm, Red Hat, Samsung, SAP and VMware. The shape is the story:

  • Critical severity: for roughly four years (2022 through early 2026), the line essentially never cleared ~100 reports per month. Since spring 2026 it jumps past 600 a month — a 6×-ish step change in a few months.
  • High severity: long range-bound in the low hundreds, then spiking toward ~2,200 a month at the right edge of the chart.

Cyber, as the framing goes, is having a moment.

The honest caveat (straight from the chart)

A16z’s own footnote matters: “Reporting procedures, labeling, and cadence vary substantially between organizations.” So some of this curve is disclosure getting better and faster — more vendors, more automation in triage, more consistent CVE issuance — not purely more flaws appearing from nowhere. A parabola in a reported-counts chart is never 100% “more bugs.” Keep that discipline.

But “it’s partly reporting” is not comfort. More high- and critical-severity issues are becoming known and weaponizable, faster — and that is exactly the variable your patch cycle races against.

The field data: AI is finding the zero-days

Which brings in the second signal. In an a16z conversation (with a16z’s David George), Kevin Mandia — who founded Mandiant — described his new venture, Armadin. The quotes are his; treat the figures as his company’s claims rather than independently audited numbers, but they line up with the macro curve:

“When you have an AI-based attack, it’ll find logic flaws rather than code flaws in custom applications. It’ll exhaust all routes all the time.”

“Armadin — since January of this year, we have found over 90 zero-days at customer sites, all in production.”

“We’ve post-trained all our models with real red-teamers, real folks that actually can develop exploits.”

“When we’re scanning networks, we don’t have source code to review… We are black box, coming from the internet.”

“Usually within 48 hours [we’re calling a CISO]: ‘Hey, we’ve got remote code execution in your DMZ.’ … That’s not a pen test. That is like a real adversary coming at you.”

Sit with the mechanism, because it explains the chart. Traditional scanners match known signatures; a model post-trained to think like an exploit developer hunts unknown logic flaws in your bespoke code — the auth check that can be skipped, the state machine that can be driven out of order — and it does so tirelessly, enumerating every path. When finding a novel bug drops from “a skilled human for weeks” to “a model for hours,” the number of discovered criticals goes up and the time-to-discovery collapses. Both curves bend at once.

Why this changes the math for defenders

The quiet assumption under most vulnerability programs is that you have time — a patch window of days or weeks between a bug becoming known and an attacker using it. AI-accelerated discovery erases that margin from both ends: more criticals to triage, and adversaries who can find your custom-app zero-days without waiting for a CVE at all. A backlog ranked by raw count, patched on a monthly cadence, is now structurally behind.

The security-leader playbook

You can’t patch a parabola by working harder on the same cadence. You change what you optimise for:

  • ☐ Prioritise by exploitability, not count. Rank remediation by internet-exposure, auth-bypass/RCE potential, and known-exploited status — not by how many CVEs scrolled past. Map it as owned risk in the Risk Register →.
  • ☐ Shrink and watch the external surface. The attacks Mandia describes come from the internet, black-box. Find what you’re exposing before they do — including forgotten agent endpoints and runtimes — with the free Open Agent Exposure Scanner →, and keep a live view rather than a quarterly scan.
  • ☐ Red-team your custom apps for LOGIC flaws. Known-CVE scanning won’t catch the auth-skip in your own code. Threat-model the bespoke stuff and hunt abuse paths with the AI Threat Model Builder → and Threat Model Studio →.
  • ☐ Pre-stage mitigations for crown jewels. Assume a critical lands before you can patch: have WAF rules, segmentation and kill-switches ready for your highest-value, internet-facing apps so you can buy hours.
  • ☐ Watch the supply chain too. The same AI that finds your zero-days is being pointed at the packages you install — scan them continuously with the NPM Scanner → and Package Scanner →.
  • ☐ Rehearse the 48-hour call. An outsider phones with RCE in your DMZ — who owns the next two days, what do you isolate, who do you tell? Run it as a tabletop in the War Room → before it’s a real Tuesday.
  • ☐ Know your number. If you can’t say, in one figure, how ready you are for this, start with the free CISO Scorecard →.

The takeaway

The “parabolic” chart and the “90 zero-days in production” field report are the same story told two ways: the cost of finding an exploitable flaw is collapsing, so both the count and the speed of critical discoveries are bending upward at once. Some of the chart is better reporting — but the direction is not in doubt, and a program that prioritises by raw count and patches monthly is already losing the race. The leaders who do well will triage by exploitability, keep their external surface small and watched, red-team their own logic, and have already rehearsed the morning a stranger calls about their DMZ.

Start with your CISO Scorecard, map exposure in the Risk Register, find what you’re exposing with the Open Agent Exposure Scanner, and rehearse the response in the War Room. Related: an open-weights offensive-security model and the economics of the breach, and the npm worm that keeps coming back. Chart: a16z, data via Epoch.ai (3 Sep 2026); quotes: Kevin Mandia / Armadin via a16z.

Related articles
Hacking Moves to the Factory: An Open-Weights Offensive-Security Model and the Economics of the Breach
A lab has released apex-flash-1, an open-weights model post-trained for cybersecurity, and framed offensive security as an economics problem: cheap capable models plus harnesses plus compute make finding and exploiting vulnerabilities a scaling exercise. The self-reported claims ($1M in bounties, #1 on the HackerOne US leaderboard, trillions of tokens a month) are the team’s own, but the trend they describe is corroborated by Anthropic’s own threat reports of largely-automated intrusion campaigns. What is claim vs. signal, why the cost-to-breach is falling, and the concrete playbook for a security leader when attack becomes industrialised.
Anthropic's GLM-5.3 Warning: Right About the Capability, Contestable About the Cure
Anthropic's Frontier Red Team says Zhipu's open-weight GLM-5.3 can build end-to-end exploits and ships without robust safeguards — then concludes governments should gate open models and expand access to Anthropic's own frontier models. The capability finding deserves to be taken seriously. The policy conclusion is where the argument is weakest. A defender's critique.
Critical Langflow Flaw (CVE-2026-0768) Now Exploited en Masse to Steal OpenAI & AWS Keys
Attackers are mass-exploiting CVE-2026-0768, a CVSS 9.8 unauthenticated RCE in the Langflow AI app builder, to run code as root and harvest OpenAI API keys and cloud secrets. What the flaw is, why AI gateways are the target, and what to do today.

Ready to practise the decisions these articles describe?

Run a free War Room →
Cyber Risk Goes Parabolic: Critical CVEs Spiked 6× This Year — and AI Is Finding the Zero-Days | PlayCISO Blog · PlayCISO