Vulnerability management is drowning, and AI is being sold as the lifeboat

Security teams face more software flaws than they can patch, and vendors are pitching frontier AI as the fix. Lucy Green looks at what that actually means for the people running these programmes.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
A security team's war room with walls covered in charts and graphs showing vulnerability backlogs, patch management timelines, and AI-powered threat assessment
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Vulnerability management, the process of finding and fixing software flaws before criminals exploit them, is buckling under the sheer volume of reported bugs.
  • The public CVE database keeps setting new records for reported flaws, and no security team can patch everything it flags.
  • Security vendors are now pitching frontier AI, meaning the largest general-purpose AI models, as a way to triage and prioritise fixes.
  • The bottleneck isn't detection: scanners already find plenty. It's deciding what to patch first and getting it done.
  • Ordinary users aren't the audience here, but they inherit the risk when companies fall behind on patches.

Vulnerability management is one of the oldest jobs in cybersecurity. Find the flaws in your software. Rank them. Fix them before someone breaks in.

For decades that's been a partnership between the people who scan for problems and the people who apply patches, the small software updates that close a security hole. The relationship has always been tense. It's now close to breaking.

Why is the old approach failing?

There are simply too many flaws to fix. The public catalogue of known software weaknesses, called CVEs (Common Vulnerabilities and Exposures), keeps setting volume records year on year. No team, however well staffed, patches everything.

So teams triage. They try to work out which handful of flaws, out of thousands, criminals will actually exploit this week. That guesswork is where programmes fall down.

A missed call becomes a breach. A patched flaw nobody was going to exploit becomes wasted overtime. Both outcomes erode trust between security and the IT staff installing the fixes. We traced exactly this dynamic in our 14 August story on growing security backlogs.

What is "frontier AI" and why is it suddenly in the pitch deck?

Frontier AI is the industry's label for the biggest, most capable general-purpose models, the same class of system that powers tools like ChatGPT and Claude. Security vendors, in coverage from The Hacker News, are pitching these models as a way to read every new vulnerability report, cross-reference it against a company's actual software stack, and rank what matters.

The promise is straightforward. Instead of a human analyst spending an hour reading advisories and threat feeds, a model does it in seconds and returns a short list.

That pitch isn't fantasy. Large models are genuinely good at summarising technical text and spotting patterns across messy data, which is much of what vulnerability triage involves.

Does it actually work?

Early signs are promising but unproven at scale. AI can rank flaws faster than a person, but it can also be confidently wrong, a behaviour called hallucination, where the model invents plausible-sounding details that aren't true.

In vulnerability management, a hallucinated "this one is safe to ignore" is a genuine problem. So is the opposite: a model that flags everything as urgent recreates the same alert fatigue teams already suffer from. Our earlier look at AI across security operations found the same caveat applied across every use case: realistic expectations matter more than the technology itself.

AI shifts the bottleneck. It doesn't remove it. Someone still has to install the patch, test that nothing broke, and answer to the business when a critical system reboots at 2am.

Should you worry?

Ordinary customers don't run vulnerability management programmes. They do inherit the consequences when a bank or retailer falls behind on patches and gets breached.

Keep your own devices updated: phones, laptops, home routers. When a company you use discloses a breach caused by an unpatched flaw, take the notification letter seriously, change the password on that account, and turn on two-factor authentication, the second code sent to your phone at login.

The deeper story is that the industry is betting on AI to dig itself out of a hole it's been in for twenty years. Whether that bet pays off will show up in next year's breach reports, not this quarter's marketing decks.

© 2026 Threat Vectr