CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Surge in CVE-classified vulnerabilities linked to AI-generated code in production environments

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

Researchers at Georgia Tech’s Systems Software & Security Lab (SSLab) report a significant increase in vulnerabilities directly introduced by AI coding tools, with at least 35 new CVE entries disclosed in March 2026 alone—up from six in January and 15 in February. The findings, part of the Vibe Security Radar project launched in May 2025, track flaws across multiple public advisories (NVD, GHSA, OSV, RustSec) and confirm 74 cases where AI tool signatures (e.g., co-author tags, bot emails) were present in vulnerability-introducing commits. Anthropic’s Claude Code is the most frequently identified tool, though underreporting is suspected due to metadata stripping and lack of traces in tools like GitHub Copilot.

Timeline

  1. 26.03.2026 18:40 1 articles · 2h ago

    AI-generated code directly linked to surge in CVE-classified vulnerabilities in March 2026

    Georgia Tech researchers report at least 35 new CVEs in March 2026 introduced by AI coding tools, with 74 confirmed cases tracked via metadata signatures. The Vibe Security Radar project highlights underreporting due to metadata stripping and the dominance of Anthropic’s Claude Code in detectable cases. Estimates suggest 400–700 total AI-induced vulnerabilities in open-source projects, with future detection methods shifting to commit patterns and coding style analysis.

    Show sources

Information Snippets