Expert View
February 26, 2026
8 minutes

Preparing for the AI-Driven CVE Tsunami: Why Transparent Prioritization Matters

A tale of two forces — and why neither cancels the other out. This week, Anthropic launched Claude Code Security, an AI tool that autonomously scans entire codebases for vulnerabilities, suggests human-reviewed fixes, and reportedly uncovered 500+ high-severity vulnerabilities in production open-source projects during internal testing, some of which had gone unnoticed for years. The reaction was immediate. CrowdStrike and Cloudflare dropped 8%. A total of $15 billion was erased from cybersecurity stocks in a single session on February 20th. Markets interpreted the launch as a disruption signal: if AI can replace vulnerability scanners, what happens to the industry?But that reading misses the real story and the real risk.
Wilfrid BLANC
Co-Founder and Head of Product & Engineering
Article
On this article
Topic part 1

⚡ Effect #1 - The Accelerant: AI Is Flooding the World With Code (and CVEs)

The first effect of AI on cybersecurity is well-documented, but its consequences are still underestimated.

AI-assisted coding is a CVE factory.

When developers ship code 5x faster using Copilot, Claude, or Cursor, they don't ship 5x fewer bugs. They ship 5x more software, with each line of it a potential attack surface. The NVD has already seen record CVE volumes in recent years. Generative AI will push that curve exponentially.

There's more. AI doesn't just create vulnerabilities at scale: it exploits them at scale. Threat actors equipped with AI can now probe environments, craft payloads, and move laterally with machine-speed precision. The asymmetry between attacker and defender has never been steeper.

This is the CVE tsunami: not a gradual tide, but a wave generated upstream, by the very tools that are accelerating software development.

🛡️ Effect #2 - The Defender: AI Detects What Humans Missed

And then comes Claude Code Security.

Unlike traditional SAST tools that rely on predefined rules, Claude Code Security uses large language models to understand data flows and component interactions, thus catching business logic flaws and broken access controls that rule-based scanners routinely miss. It runs self-verification passes before surfacing findings. It presents severity and confidence scores. And crucially, it keeps humans in the loop: no auto-push to prod.

This is genuinely powerful. For security teams drowning in backlog, an AI that can intelligently triage a 3-million-line codebase is a force multiplier. It lowers the detection floor. It democratizes access to senior-level code review.

A legitimate equalizer? Potentially yes.

⚖️ The Paradox: Those Two Forces Don't Cancel Out - They Compound

Here's where the conventional narrative breaks down.

A naive reading suggests: AI creates more CVEs, AI finds more CVEs → balance restored.

The reality is far more unsettling. Both effects accelerate simultaneously. You don't get equilibrium but a faster cycle.

More code shipped → more CVEs generated
More AI scanning → more CVEs discovered
More AI on the offensive → more CVEs actively exploited

The result? Security teams now face an environment where the volume of known vulnerabilities outpaces any human team's ability to remediate. The backlog isn't shrinking; instead it's growing, faster, and under higher pressure.

Discovery is no longer the bottleneck. Prioritization is.

🎯 Why Transparent Prioritization Is the Critical Differentiator

When every tool in your stack can surface hundreds of new findings per scan, the question shifts from "what vulnerabilities do we have?" to "which ones actually matter and how do we justify acting on them first?"

This is where transparency becomes non-negotiable.

A prioritization score is only valuable if it's explainable:

  • Why is this CVE ranked critical in my environment specifically?
  • Is it because it's actively exploited in the wild? Because it sits on an internet-exposed asset? Because it's linked to a critical business process?
  • How do I communicate this to the CISO, to the board, to the audit team?

In an AI-driven world where both threats and findings multiply at machine speed, opaque prioritization is a liability. "Fix these 20 CVEs" with no rationale creates organizational paralysis and erodes trust between security teams and the business.

Transparent, risk-based prioritization of vulnerabilities does the opposite. It creates a shared language between SecOps, IT, and leadership. It turns an overwhelming backlog into an actionable queue. It makes security decisions defensible not just to auditors, but to the organization itself.

Agentic AI for Vulnerability Management: How SmartEx² Enterprise Speaks to Your Tools

🔭 What This Means in Practice

The launch of Claude Code Security is a milestone, not an endpoint. It signals that AI-powered detection is becoming commoditized. What remains scarce - and differentiating - is the ability to make sense of what AI surfaces.

For security leaders, this means:

  1. Rethink your metrics. CVE count is noise. Risk reduction velocity is signal.
  2. Demand explainability from your tools. If your prioritization engine can't tell you why a vulnerability is ranked the way it is, it's a black box you can't operationalize or defend.
  3. Build processes for scale, not volume. The teams that win won't be those who find the most vulnerabilities, but those who fix the right ones, demonstrably faster.

The AI-driven CVE tsunami isn't coming. It's already here. The organizations that navigate it successfully won't be the ones with the best scanner. They'll be the ones with the clearest answer to the question: "Of everything we know about, what do we fix next and why?"

AI is rewriting the rules of vulnerability management. Explainability in risk scoring is no longer simply a “nice to have”, and a healthy prioritization - transparent, risk-based, and actionable - is the new competitive moat for security teams.

💬 What's your take? Is the industry ready to move from detection to intelligent prioritization at scale? Drop your thoughts below.

Wilfrid BLANC
Co-Founder and Head of Product & Engineering
Wilfrid Blanc is Co-Founder and Head of Product & Engineering at Hackuity. A former Ethical Hacker at Lexsi, he brings deep expertise in offensive security and leads Hackuity’s product and engineering roadmap, helping transform how organizations manage and prioritize cyber exposure. When he's not behind his laptop, you'll find him skiing on the slopes of the 3 Vallées in winter or hiking through the mountains in summer.
Ready to see Hackuity in action?
See how Hackuity maps to your tools, teams, and remediation workflows.
Book a demo
Share this post
VR-1
Property
Model type

Post-trained cyber reasoning model

Primary specialization

Multi-domain enterprise attack-chain discovery

Starting condition

A scoped foothold and a concrete objective

Operating surfaces

Cloud, identity, runtime, code, CI/CD, SaaS, and organizational context
xxxxxx

Success signal

Execution-verified completion of the objective

Primary evaluation

IntrusionBench

Preliminary result (preview)

More than 2× black-box pass@3 over the strongest evaluated frontier baseline

Trajectory budget

Two-hour wall-clock limit per trajectory, or 250 agent turns (whichever comes first)

Most recent articals

Hackuity in the News
Article
5 minutes
Hackuity raises $19M Series B to scale the AI-powered Vulnerability Operations Center
Today we announced $19 million in new funding, bringing Hackuity's total funding to $38 million. The round was led by Forgepoint Capital International, alongside our existing investors Bright Pixel, Bpifrance and Seventure Partners.
Patrick RAGARU
Co-founder & CEO
Pierre SAMSON
Co-Founder and Chief Revenue Officer
September 15, 2026
Expert View
Article
5 minutes
All about CTEM in 5 minutes
Security teams do not suffer from a lack of vulnerability data, they suffer from too much of it. What they need is a clear way to prioritize and act on it.
Pierre SAMSON
Co-Founder and Chief Revenue Officer
September 9, 2026
Expert View
8 minutes
MTTR & MTO: The Metrics Everyone Talks About, But Almost No One Calculates Correctly
The KPI Your Clients Always Ask First: No matter the industry, no matter the maturity of the organization: when a CISO or security leader reviews their vulnerability management.
Thomas CHARARA
Product Manager
August 25, 2026

See Hackuity in action

Schedule a personalized demo to see how Hackuity maps to your environment.
Illustration of hackuity presention, Screenshot of the Hackuity Exposure Overview dashboard showing 1 critical, 474 high, and 2.6k other open findings, alongside a 12-month bar chart of findings by severity and a video call panel