3 lessons from frontier AI vulnerability research
Microsoft says its FORGE AI research helped uncover 140 Windows CVEs and 155 open-source bug reports since May.
Microsoft’s FORGE lab said that from May through September 2026 its AI-assisted vulnerability research contributed to 140 Windows CVEs, including 52 fixed in the September security release, plus 155 internally validated reports across 23 open-source projects including the Linux kernel. One Linux report, coordinated through the Linux Foundation’s Akrites program, was the first Akrites submission merged into the kernel. The post argues that at scale the limit is validation, reproducible proofs, and remediation capacity rather than model intelligence alone. It describes the MDASH multi-model scanning harness and internal deduplication that reduced about 45 percent of duplicate findings.