Ninety Days After Mythos: What the Data Now Shows About Vulnerability Management in the AI Era
When Anthropic announced Project Glasswing on April 7, 2026, the headline was impossible to ignore: Mythos, an AI system capable of semi‑autonomous vulnerability discovery and exploitation at machine speed, uncovered thousands of high‑severity flaws across major platforms during its pilot phase. The industry understood immediately that Mythos wasn’t just another research model, it was a structural shock to the vulnerability ecosystem.
Ninety days later, the data is now unambiguous. We have entered a new phase of vulnerability discovery, exploitation, and remediation, one defined by machine‑speed asymmetry.
This post is a synthesis of what the last three months reveal, grounded in public datasets (NVD, CVE Details, CISA KEV, AV‑Test, Google Threat Intelligence Group) and the operational changes unfolding across the ecosystem.
The First 90 Days: Discovery at Machine Speed
Mythos’ early results foreshadowed what the broader industry is now experiencing: a dramatic acceleration in vulnerability discovery volume.
- By the end of 2025, the National Vulnerability Database (NVD) had accumulated ~309,000 CVEs.
- As of July 17, 2026, that number has already surpassed 349,000.
- If this rate of change continues, 2026 is on track to close with 74,000–75,000 CVEs, a 55% increase over 2025.
The following data from NVD and CVE Details illustrates how vulnerability disclosure volume has evolved across three distinct eras of cybersecurity.

This is not a statistical anomaly; it is the acceleration phase of the machine‑speed vulnerability era that began in 2024, where AI‑assisted fuzzing, autonomous exploit‑chain generation, and LLM‑based static analysis are expanding the supply of discovered vulnerabilities faster than any prior period in history.
During 1999 – 2025, the CVSS distribution reinforces the trend:
- Critical + High severities = 53% of all CVEs
- Critical = 17%
- High = 36%
The industry is not just seeing more vulnerabilities; it is seeing more serious vulnerabilities.

Exploitation Is Accelerating Even Faster
Discovery is only half the story. Exploitation timelines have collapsed. Zero Day Clock data (https://zerodayclock.com/) shows a >95% reduction in time‑to‑exploit over eight years. What once took months now takes days, sometimes hours. This is why patch management alone is no longer sufficient. The exploitation window has fallen below the floor of practical enterprise patch cycles.
Organizations now require:
- Predictive vulnerability intelligence
- Pre‑disclosure mitigation (virtual patching, exploit surface reduction)
- Governance frameworks that treat vulnerability management as real‑time risk, not maintenance
Board‑level takeaway: exploitation speed is now a governance metric.
The KEV Catalog Is Changing. And So Must Our Interpretation of It
CISA’s Known Exploited Vulnerabilities (KEV) catalog has long served as the industry’s affirmative prioritization signal. But the last 90 days show a structural shift.
Key observations:
- KEV additions are declining, even as exploitation telemetry rises.
- CISA has tightened criteria to focus on confirmed, systemic exploitation affecting critical infrastructure.
- Historically, KEV backfilled older exploited vulnerabilities. In 2026, that pattern stops entirely.
From 2021 to 2025, each year’s KEV updates included dozens of older CVEs, often reaching back more than a decade, underscoring that KEV historically functioned as a retrospective validation mechanism, not a real‑time exploitation signal.
- 2021: CVEs from 2010–2017
- 2022: CVEs from 2013–2019
- 2023: CVEs from 2014–2020
- 2024: CVEs from 2015–2021
- 2025: CVEs from 2007–2022
In 2026, that pattern breaks. Every CVE added to KEV this year is from 2025 or 2026. None pre‑2025. This marks the first year in KEV’s history with no legacy additions; this is a clear signal that CISA has likely shifted from archival completeness to real‑time exploitation tracking.
This creates a widening intelligence gap: automated exploitation is accelerating faster than authoritative validation can keep up.
Jen Easterly, former Director of CISA summarized the shift well in an article published just last week: “The problem is not that the KEV has lost value. It is that many organizations have come to use it for a job it was never designed to perform… In an age of compressed exploitation timelines, it is no longer safe…KEV still tells us when delay is indefensible. It can no longer tell us when delay is safe." (https://www.linkedin.com/pulse/kev-dead-long-live-jen-easterly-sbiee/)
The Coming Wave of Exploitation: Q3–Q4 2026
Historically, exploitation trails discovery by 3–6 months for high‑impact CVEs. Given the April–July spike in CVE publication, defenders should expect:
- A steepening exploitation curve through late summer and fall
- Increased weaponization of CVSS ≥ 9 vulnerabilities disclosed since April
- More campaigns targeting end‑of‑life hardware and software, where patching is impossible
The last five years saw 38 major products reach end‑of‑life across 17 major vendors. Every one of those products has at least one vulnerability in KEV. This is fertile ground for automated exploitation.
The Remediation Deficit Is Now Structural
The last 90 days have made the remediation deficit impossible to ignore. Five forces are driving the divergence:
- Vulnerability discovery expanding faster than remediation capacity
- AI‑assisted adversarial tools compressing exploitation windows
- Decaying vulnerability intelligence infrastructure (NVD enrichment delays, prioritization changes)
- Growing inventories of end‑of‑life systems
- Continued proliferation of malware, that has been growing at 17.6% annually, adding ~105M samples per year. If malware were a country, it would become the largest in the world this year.
The asymmetry is widening.

What the Last 90 Days Mean for Vulnerability Management Strategy
The era of vulnerability scanning is over. The era of continuous threat exposure management (CTEM) has begun.
1. Prioritize by exploitability, not just CVSS: CVSS is necessary but insufficient. Velocity‑aware inputs such as EPSS, KEV, and threat‑intel correlation, must drive prioritization.
2. Move to continuous assessment: quarterly or monthly scanning cycles are incompatible with machine‑speed exploitation.
3. Compress patch windows with automation
- Automated patch pipelines
- Pre‑approved emergency change workflows
- Compensating controls when patching lags
4. Reduce vulnerability creation
- Apply secure‑by‑design principles
- Adopt memory‑safe languages
- Enforce SBOM discipline and dependency hygiene
5. Design for containment: assume exploitation. Limit blast radius. Treat identity as the primary control plane.
6. Govern defensive AI use: AI‑assisted triage, correlation, and playbooks are essential. Human oversight remains non‑negotiable.
7. Elevate vulnerability management to a board‑level discipline: make vulnerability management a board‑level discipline with visible metrics, cross‑functional ownership, and routine scenario planning.
Closing Thoughts
The first 90 days after Mythos confirm what many suspected: AI has permanently altered the vulnerability landscape.
Discovery is accelerating. Exploitation is compressing. Remediation is falling behind.
The organizations that adapt fastest, those that embrace CTEM, velocity‑aware prioritization, secure‑by‑design engineering, and governance‑driven exposure management will be the ones that maintain resilience in the era of autonomous adversaries.
This is not a temporary spike. It is the new baseline.
The views and opinions expressed in this post are my own and do not necessarily reflect the official policy or position of my current or past employers.