AI Steps In as Vulnerability Management Struggles with Volume

As software flaws multiply, companies turn to AI to prioritize what to fix first. But does it work?

AI2Day Newsdesk2 min read
A dark underground marketplace bustling with AI tools being exchanged between anonymous figures, digital screens displaying code and transactions
Share

Key points

  • More than 28,000 new software vulnerabilities were recorded in 2023, breaking records again in 2024.
  • AI models, similar to ChatGPT, are being proposed to help prioritize which vulnerabilities to fix first.
  • Early AI tests show promise, but the technology can still make mistakes, known as hallucinations.

Vulnerability management, the task of identifying and fixing software flaws before criminals can exploit them, is overwhelmed by the sheer number of reported issues. According to data, more than 28,000 new vulnerabilities were catalogued in 2023, with 2024 setting another record. As first reported by ThreatVectr, security vendors are now suggesting frontier AI, large, general-purpose AI models, like those behind ChatGPT and Claude, as a solution to help triage and prioritize which vulnerabilities to address first.

Why is this a problem?

The explosion in software flaws has exceeded the capacity of security teams to manage them. Publicly known as CVEs (Common Vulnerabilities and Exposures), these vulnerabilities are too numerous for any team to patch completely. This has forced teams to guess which vulnerabilities are most likely to be exploited. However, this guesswork can lead to breaches if teams misjudge threats or waste time on vulnerabilities that pose little risk.

How can AI help?

AI is being pitched as a tool to quickly analyze vulnerability reports and determine priorities. The idea is that AI can read reports, cross-reference them with a company’s existing software, and create a priority list much faster than a human could. While AI can summarize technical data and spot patterns efficiently, it can also make errors, known as hallucinations, where the AI invents details that aren’t true. This presents a risk if AI incorrectly identifies a vulnerability as safe to ignore, or flags everything as urgent, overwhelming teams.

What does this mean for everyday users?

While ordinary users aren’t directly involved in managing these vulnerabilities, they feel the effects if companies fail to patch software and suffer breaches. For individuals, it is crucial to keep personal devices updated and to take breach notifications seriously by changing passwords and enabling two-factor authentication, a security measure that adds an extra login step with a code sent to your phone.

The industry hopes AI can address longstanding issues in vulnerability management. However, whether this bet pays off will be evident in future breach reports, not in current marketing pitches.

© 2026 AI2Day