A new study suggests that while AI is rapidly accelerating vulnerability discovery, enterprise organizations are better equipped to handle the surge than generally assumed.
The key is their ability to quickly validate findings, prioritize risk, and get available fixes into production.
Software supply chain security firm Echo recently analyzed nearly 40,000 CVE life cycles across 250 open source container projects, drawing on a year of its own platform telemetry, survey responses from more than 80 security leaders, and an independent analysis of Anthropic’s Claude Mythos.
AI Has Accelerated One Side of the Equation
The results, detailed in a report titled “Mythos Readiness Report,” show how AI is transforming vulnerability discovery and exploit development — something that security teams have been encountering firsthand over the past year.
Monthly CVE disclosures rose 145% over two years, from 3,173 in June 2024 to 7,765 in June 2026, partly due to the expansion of the CVE program and increasingly because of AI-assisted vulnerability discovery. On an annual basis, CVE disclosures shot up from 30,949 in 2023 to 49,979 in 2025 and, based on the numbers so far, 2026 is on track to surpass even that number.
Echo discovered the same pattern with container base images, of which Node and Python are the most frequently used. Between January and June 2026, the number of known CVEs in Node base images surged 338%, from around 16,000 to 70,000, while for Python the numbers went from 17,500 to 45,000 in the same period.
“Vulnerabilities are now being discovered at machine speed, while remediation remains largely manual,” Echo wrote in its report. “In essence, AI has dramatically accelerated one side of the equation, but the other has yet to catch up.”
Echo found that Claude Mythos has fundamentally changed the economics of exploit development and made it possible for researchers and bad actors to develop a working exploit for a known vulnerability in less than one day and for under $2,000.
A More Nuanced Reality for Security Teams
While the raw data might suggest a situation that is quickly spiraling out of control for organizations, Echo found some reasons for optimism.
For one thing, a lot of the vulnerabilities that AI tools are discovering are not yet vetted and often turn out to be less serious than initially assumed. For example, over the period that Echo studied, Mythos discovered some 23,019 potential vulnerabilities. But fewer than 10% had been externally validated, or independently checked. Of the 27 vulnerabilities that Anthropic publicly disclosed, Mythos initially classified eight of them as being of critical severity. But after researchers independently reviewed the eight flaws, only one retained the critical rating.
“One of the biggest surprises was that being ready for Mythos is actually much more achievable than expected,” Eylam Milner, chief technology officer (CTO) and co-founder at Echo, tells Dark Reading. “Mythos is really good at finding real vulnerabilities, but it’s much less reliable at determining how serious those vulnerabilities actually are, which is a really important distinction for security teams trying to decide what requires their attention.”
Rather than completely rethinking everything they’re doing around vulnerability management, he says, organizations need to focus on infrastructure for quickly validating a larger number of vulnerabilities, understanding what matters, and then remediating them efficiently.
Self-Inflicted Exposures?
Echo also found that at least some of the vulnerability management challenges that organizations might be facing are the result of their own doing. A notable 89% of the vulnerabilities that Echo examined had a fix, for example. The numbers were even higher for critical and high-severity vulnerabilities. Yet Echo found nearly 40% of fixable vulnerabilities remained unresolved for more than six months
The numbers indicate that fix availability isn’t actually the biggest problem; rather, it’s getting those fixes into production, Milner says. “A fix being available doesn’t mean it’s easy to deploy. Applying it can require upgrading dependencies, testing for compatibility and breaking changes, and moving the change through an organization’s normal development and release process.”
When security teams need to apply that process across thousands of vulnerabilities, remediation can become a massive prioritization/resource problem. Engineering teams have limited time, and security fixes compete with product work and other priorities, so vulnerabilities that have a fix available can sit in the backlog for months.
“That’s why we think the answer is to remove as much of that manual work as possible — continuously delivering patched software rather than relying on engineering teams to chase and deploy every fix themselves,” he says.
Echo uncovered another problem: Many organizations, even those that assessed themselves as having mature security practices, often had self-inflicted vulnerability exposures. Nearly 6 in 10 (56%) of container vulnerabilities stemmed from packages, utilities, development tools, and other software not needed in production.
“Before worrying about how to keep up with every new vulnerability AI finds, organizations should focus on reducing the attack surface they already have,” Milner advises. “Build with less vulnerable software to begin with, remove the dependencies they don’t need, and focus on getting available fixes into production much faster.”

No responses yet