NVD Logs More Than 45,000 Vulnerabilities Through July 27

A July 27 Bloomberg snapshot counted 45,207 vulnerability records published in the U.S. National Vulnerability Database during 2026, close to the database's full-year 2025 total. Vendor disclosures show AI-assisted discovery contributing to the increase, but reporting found no comparable rise in vulnerabilities known to be actively exploited.
The U.S. National Vulnerability Database had recorded 45,207 vulnerabilities published between January 1 and July 27, 2026, according to a Bloomberg snapshot republished by The Business Times. That was already close to the database's total for all of 2025, although the NVD is a live repository and historical counts can change as records are added or updated.
Disclosure volume is rising faster than exploitation evidence
The disclosure count measures recorded vulnerabilities, not successful attacks. Bloomberg reported that the U.S. government's Known Exploited Vulnerabilities catalog had not shown a corresponding increase in exploited issues during 2026. That distinction matters: better discovery can expand defenders' patch queues without proving that attackers are exploiting the same number of newly disclosed flaws.
Vendor releases illustrate the scale of the discovery and remediation workload. Oracle said its July Critical Patch Update was its largest security release to date, with 1,449 patches covering 1,434 distinct CVEs across 334 products. A Chrome stable-channel update listed 433 security fixes, many reported internally by Google.
Both companies connected the larger release volume to expanded security work. Oracle explicitly cited AI-powered identification of actionable findings, while Google told Bloomberg that advances in AI models and greater investment were driving an unusual pace of vulnerability discovery.
AI changes the bottleneck
The practical consequence is not simply that AI is finding more bugs. It is that remediation teams must validate, prioritize and deploy fixes at a pace that can exceed established patch cycles. Automated discovery can help vendors find weaknesses before attackers do, but it can also create triage pressure when maintainers receive more reports than they can quickly investigate.
For security and engineering teams, the useful signal is the gap between disclosure volume and exploitation evidence. A growing CVE count should increase attention to asset inventories, internet-facing systems and patch automation, but it should not replace risk-based prioritization. Exploit status, exposure, severity and the importance of the affected system remain more useful deployment signals than the headline count alone.
Key Points
- 1Bloomberg counted 45,207 NVD vulnerability records published from January 1 through July 27, 2026, close to the full-year 2025 total.
- 2Oracle's July update delivered 1,449 patches for 1,434 distinct CVEs, while a Chrome update listed 433 security fixes.
- 3The disclosure surge did not correspond to a reported rise in the government's known-exploited catalog, so teams still need risk-based patch prioritization.
Scoring Rationale
The disclosure pace materially affects vulnerability triage and patch operations across technology vendors. Official vendor records and the NVD support the scale, while the absence of a matching exploitation increase tempers the headline risk.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems

