WatchGuard Blog

More Vulnerabilities Are Being Found Than Ever Before. That's Good News.

Why record-breaking disclosure numbers are a sign of a healthier industry and how WatchGuard's Firebreak Ideology fits into that shift.

If you've glanced at a vulnerability tracker lately, the numbers look alarming. The Forum of Incident Response and Security Teams (FIRST) now projects roughly 66,000 CVEs will be published in 2026; up from a February forecast of 59,427 and closing in on 70,000 by some counts. That would follow a record 2025, which finished at roughly 48,000 disclosed CVEs, itself a sharp climb from about 40,000 the year before.

It's tempting to read that curve as a sign that software is getting worse. It isn't. It's a sign that the industry is now finding what was always there.

Why disclosures are spiking

FIRST's own researchers point to a specific cause: AI-assisted vulnerability discovery is surfacing flaws that have been sitting in production code for years. Mozilla's CNA alone saw a 164% jump in Q1 CVE disclosures that FIRST attributes directly to AI-assisted tooling run against the Firefox engine. GitHub Security Advisory volume is up 449% year over year. None of that is decay – it's visibility.

The uncomfortable part is that the same acceleration is available to attackers. Adversaries are already using frontier AI to automate reconnaissance, map attack path, and compress exploit development timelines that once took weeks into hours. The data backs that up: the median time-to-exploit for a new vulnerability now sits under five days, and more than half of critical vulnerabilities face active exploitation within the first week of disclosure.

The real risk was never the disclosure count. It's the gap between when a flaw is found and when someone closes it, and defenders have been on the slow side of that gap for years.

Closing the gap requires the same technology that created it

That persistent lag underpins the logic behind WatchGuard's new investments in frontier AI, which include its recently announced participation in OpenAI's Daybreak Cyber Partner Program and Anthropic's Cyber Verification Program (CVP). Both exist for the same reason. Legitimate vulnerability research, exploitability analysis and adversarial simulation require reasoning about systems the way an attacker would. Marc Laliberte, WatchGuard's Head of Security Operations, framed the stakes plainly: “Cybercriminals are already using these technologies to uncover weaknesses and accelerate attacks. Our responsibility is to ensure defenders benefit from equally powerful capabilities.”

This is work that frontier models restrict by default unless an organization is vetted for it and validation processes unlock that reasoning specifically for defensive teams. With this in mind, WatchGuard is deliberately not betting on one model provider. As CEO Joe Smolarski said, “The future of cybersecurity won't be built on a single AI model. That's why we're aggressively investing across the frontier AI ecosystem, giving our teams access to advanced capabilities from multiple providers.” 

The Firebreak Ideology

Internally, this effort has a name: WatchGuard's Firebreak Ideology. We fight fire with fire.

When a wildfire moves faster than any crew can outrun, containment teams don't wait for it to arrive, they get ahead of it and burn the ground themselves, consuming the fuel in its path before the real fire ever gets there. That controlled burn is what creates a firebreak, and it only works because it uses the same force as the thing it's stopping. Frontier AI plays that role inside WatchGuard now, used against our own products and defenses first: hunting vulnerabilities in our own code, red-teaming our defenses continuously, accelerating our SOC analysts, and burning through threat intelligence at machine speed. We light that fire on our own products first, on our own schedule, before it reaches the more than 25,000 MSPs and 1.5 million businesses that depend on WatchGuard.

What this means for WatchGuard, its partners and its customers

WatchGuard is already leveraging these capabilities within its own platform, proactively deploying Frontier AI against our own products and defenses first. We are hunting vulnerabilities in our own code, red-teaming our defenses continuously, accelerating our SOC analysts and burning through threat intelligence at machine speed. We are using Frontier AI on our own products first, on our own schedule, before it reaches the more than 25,000 MSPs and 1.5 million businesses that depend on WatchGuard.

Here's the part worth being upfront about: these efforts will turn up more findings before it turns up fewer. In the short term, that can mean an uptick in disclosures in WatchGuard's own products, as this does exactly what it's designed to do. That's not a regression. It's the same pattern playing out industry-wide right now: more ground covered, producing more disclosures and leaving attackers with fewer opportunities for exploitation.

The alternative - quietly hoping the old cadence of manual review keeps up with attackers now operating at machine speed - isn't a real option anymore. The industry's disclosure numbers this year are the clearest evidence of that shift. WatchGuard's Firebreak Ideology is a bet that the same fire reshaping the vulnerability landscape can be turned inward, continuously, to mitigate an attacker's ability to exploit organizations before they reach the end user.

Further reading