Open source speeds up application development — but is it making our software insecure?

Open source software has become fundamental to modern application development. Few development teams today build an application entirely from first principles. Instead, they depend on open source databases, libraries, frameworks, cryptographic components, web servers, and thousands of smaller packages that allow them to deliver software far more quickly.
That model has been enormously successful. It has also created a difficult security question: if applications increasingly depend on software written elsewhere, are organizations importing vulnerabilities at the same time as they import functionality?
At first glance, the numbers suggest a serious problem.
In April 2026, the US National Institute of Standards and Technology reported that CVE submissions had increased by 263% between 2020 and 2025. Submissions during the first three months of 2026 were already almost one-third higher than during the equivalent period in 2025.
NIST processed nearly 42,000 CVEs during 2025, while acknowledging that the volume of vulnerability disclosures was forcing changes to the way the National Vulnerability Database operates.
It is tempting to see this as evidence that software, and open source software in particular, is becoming less secure. But another major change is taking place at the same time: artificial intelligence is becoming dramatically better at finding vulnerabilities that were already there.
Google’s work with OSS-Fuzz provides a good example. By using large language models to generate fuzzing targets, Google increased test coverage across 272 C and C++ open source projects and reached more than 370,000 additional lines of code. The work uncovered 26 previously unknown vulnerabilities, including CVE-2024-9143 in OpenSSL. Google said that the OpenSSL vulnerability may have existed for around two decades.
That distinction matters. AI did not create the vulnerability; it created a more effective way of discovering it.
Google’s Big Sleep project has demonstrated the same phenomenon. AI-based vulnerability research has identified previously unknown flaws in widely deployed open source software, including a memory-safety vulnerability in SQLite.
This is likely to become increasingly common. AI systems can analyze code continuously, follow execution paths, generate test cases, and investigate possible flaws at a scale that would be unrealistic for human security researchers alone.
Open source is particularly exposed to this new generation of scanning because the source code is readily available. An AI system can analyze every function in a project, compare code against known vulnerability patterns, and repeatedly test unusual combinations of inputs.
That creates an important statistical problem. If we become significantly better at finding vulnerabilities in open source software, the number of reported vulnerabilities will inevitably rise. But an increase in detected vulnerabilities does not necessarily mean that the underlying software has suddenly become more insecure. It may mean that our ability to observe its insecurity has improved.
Proprietary software provides a useful counterpoint.
Microsoft, for example, is also applying AI internally to vulnerability research. In May 2026, Microsoft described MDASH, a system using more than 100 specialized AI agents to analyze proprietary software. Microsoft said the system helped researchers identify 16 previously unknown vulnerabilities in the Windows networking and authentication stack, including four critical remote-code-execution vulnerabilities.
The vulnerability volumes in proprietary enterprise software are also substantial.
Tenable reported that Microsoft’s September 2026 Patch Tuesday addressed approximately 964 CVEs, including 104 vulnerabilities rated critical.
SAP’s August 2026 Security Patch Day included 28 new security notes, including several critical vulnerabilities with CVSS scores between 9.1 and 10.0. September brought a further 19 new security notes, including a vulnerability rated CVSS 10.0.
Oracle’s July 2026 Critical Patch Update was larger still, containing 1,448 new security patches. Oracle E-Business Suite accounted for 410 and Fusion Middleware for 355. Oracle notes that these figures include vulnerabilities in both Oracle and third-party components, which itself demonstrates how difficult it has become to draw a clean dividing line between proprietary and open source software.
The conclusion should therefore not be that open source is inherently less secure. Open source may simply be becoming more measurable. Its openness makes it easier for researchers, security vendors, and increasingly AI systems to inspect the code systematically. Proprietary software can contain the same classes of defect, but they may remain invisible until a vendor, customer, researcher, or attacker discovers them.
For enterprise development teams, the more important question is therefore not whether a component is open source or proprietary. It is whether organizations know what software they are using, whether vulnerabilities can be identified quickly, and whether affected systems can be remediated before a vulnerability is exploited.
AI will almost certainly push reported vulnerability numbers much higher over the next few years. That may initially make the software industry appear less secure.
In reality, we may simply be discovering vulnerabilities that have been present for years.
A vulnerability that nobody knows about is not safer than one that has been identified and patched. As AI turns vulnerability research into an increasingly automated process, the uncomfortable rise in reported vulnerabilities may ultimately be evidence that we are becoming better at seeing the security problems that were there all along.

Moshe Bar is co-founder and CEO of Codenotary, provider of security software, especially for use with AI. Previously, he co-founded Qumranet (sold to Red Hat) and XenSource (acquired by Citrix).






Be First to Comment