IBM Warns of 66,000 Vulnerability Disclosures in 2026
IBM's Jamie Thomas told the Linux Foundation Open Source Summit that exploit times have fallen and AI-generated reports are overwhelming maintainers.
Jamie Thomas, IBM's Chief Client Innovation Officer for Enterprise Security, warned at the Linux Foundation Open Source Summit of what she described as a "tsunami in vulnerability disclosures," with approximately 66,000 unique entries expected in 2026 alone. Thomas said that figure represents a fourfold increase compared with seven years ago.
Thomas also said the time required to exploit a vulnerability has shrunk from days to as little as 29 minutes, and that the time to exploit is often negative, with disclosures arriving before patches exist.
She argued that AI should be part of the solution, pointing out that AI currently creates inaccurate, duplicated and unactionable vulnerability reports that burden open source maintainers.
Maintainers already under strain
The pressure Thomas described follows earlier strain on bug bounty and security reporting systems. Earlier this year, the developers of curl terminated their HackerOne bug bounty program due to poorly researched and fake reports, including AI-generated submissions. In October 2025, Google suspended its Open Source Software Vulnerability Rewards Program due to an increase in invalid and irrelevant reports, many AI-generated, with no new submissions accepted as of October 1, 2026, and reassessment planned for early 2027. Linux creator Linus Torvalds also recently said AI-powered bug hunters have made the Linux security mailing list "almost entirely unmanageable."
Quick answers
How many vulnerability disclosures are expected in 2026?
IBM's Jamie Thomas said approximately 66,000 unique entries are expected in 2026, a fourfold increase compared with seven years ago.
How fast can a vulnerability be exploited?
Thomas said the time required to exploit a vulnerability has shrunk from days to as little as 29 minutes, and can be negative when disclosures arrive before patches exist.
What did Google do with its Open Source Software Vulnerability Rewards Program?
Google suspended the program due to an increase in invalid and irrelevant reports, many AI-generated, with no new submissions accepted as of October 1, 2026, and reassessment planned for early 2027.