The two largest AI vulnerability discovery programs on the planet just published their numbers, and the numbers say exactly where this is headed. Anthropic's Project Glasswing found 26,153 vulnerabilities.
2,096 were disclosed to maintainers and just 202 have been fixed so far, which is 0.8%. OpenAI's Patch the Planet found 1,646 issues, brought in Trail of Bits to write 615 patches and hand them to maintainers, and 13% have merged.
None of that is a failure. Both programs did something the industry could not do a year ago, and both labs were unusually transparent about the results. Anthropic's own update calls independent human triage and review the rate limiting step. The model is not the constraint. The humans are.
These programs were the best case scenario, with frontier models, frontier researchers, high profile projects that actually wanted the help, and in OpenAI's case patches written and delivered.
If remediation was ever going to keep pace with discovery, it was going to happen here.
Open source has lived this for years, and AI discovery is about to export the same experience to every enterprise codebase, most of which were already underwater before any of this started.
In the video I cover:
What Glasswing and Patch the Planet actually did, and what their own funnels show about where the bottleneck sits
The severity gap, with Claude rating 91.5% of its findings critical or high and maintainers rating 51.3% that way
Why your backlog was already a problem, with FIRST now forecasting 66,000 to 68,000 CVEs for 2026 and Empirical Security finding 15,222 exploited CVEs that never made the KEV
What attackers are doing with the same models, including Anthropic's research on exploit chains finishing before patches reached devices
Six practical moves, starting with buying triage instead of more scanners and layering exploitation signals beyond the KEV
Shout to my friend to Patrick Garrity at VulnCheck for reconciling the Glasswing ledger, and to Casey Ellis for the line I keep quoting
The volume apocalypse was already here, it just wasn't evenly distributed.
For the full written analysis, see my article The Bottleneck Was Never Finding Bugs.
The question I close on is the same one from the article, are we going to build the remediation capacity to match, or keep celebrating the size of the backlog?









