Breaking
SecurityDeveloping Story

Mythos May Ease 2027 Patching Load

Gartner's Craig Lawson suggests AI bug-hunting could cut vulnerability severity next year as technical debt gets paid down.

··3 hours ago·5 min read
a close up of a computer with green lights
Photo by Tyler on Unsplash

Security teams staring down a record flood of patches might be looking at the worst of it right now. Gartner research vice president Craig Lawson argued this week that the surge in vulnerability discoveries driven by Anthropic's Mythos and similar bug-hunting AI models could be nearing its peak — and that the payoff may arrive as soon as next year.

Lawson spoke at Gartner's IT Symposium in Australia, where he outlined a scenario in which AI-assisted code auditing has already retired enormous amounts of technical debt and could soon make software safer and patching lighter.

Record patch volume, different read

The backdrop is a patching workload that has felt less like a schedule and more like a deluge. Microsoft delivered over 970 patches last week, a volume that many in the industry read as a nightmare for already stretched security staff.

Lawson's take flips that reading. He sees the high number of CVEs reported in 2026 as a positive signal rather than a warning sign, because it reflects how much previously hidden weakness is being surfaced and fixed.

The core of his argument is that automated bug-hunters are now auditing codebases at a scale and depth that human review never reached. That means flaws that might have sat dormant for years — available to attackers as zero-days — are being found and reported in a concentrated burst.

OpenBSD as the evidence

To make the case that AI bug-hunting is cleaning up hardened software, Lawson pointed to a recent series of CVEs found in OpenBSD, an operating system that has historically been considered unusually secure and stable.

The thinking is straightforward: if AI-assisted tools are turning up bugs in a project with OpenBSD's reputation, they are likely finding problems in less carefully maintained code too. Each fix closes a door that attackers might otherwise have walked through.

Lawson also noted that security vendors — the companies that in theory know best what it takes to build secure products — are themselves using AI to hunt flaws in their own wares. Those discoveries, he suggested, further indicate AI is removing potential avenues for zero-day attacks.

“We've never had a situation where massive codebases have been audited to that level before,” he told The Register.

— Craig Lawson, research vice president at Gartner

Why 2027 could look different

Lawson suspects 2027 might bring a change in the numbers, as vendors finish cleaning up older code and start using AI more thoroughly to test their new releases before shipping them.

He framed it not as a guarantee that aggregate vulnerability counts will fall, but as a likely drop in severity. In his view, the pile of findings in 2026 reflects a one-time clearing of accumulated debt, and the pipeline of future releases should be cleaner because it is being checked harder.

“2027 could be the first year we see a net drop, maybe not in aggregate vulnerabilities, but definitely in severity of flaws,” he told The Register.

— Craig Lawson, research vice president at Gartner

That distinction matters for defenders. A world with the same number of CVEs but fewer serious ones still means less emergency work, fewer rushed weekend upgrades, and fewer critical systems left exposed while a fix is tested and deployed.

Red teaming moves in-house

Beyond the discovery side, Lawson argued AI will hand defenders better tools. Today, he said, a red-teaming exercise is an infrequent and costly event that usually involves hiring an external provider.

With AI bug-hunters, he suggested organizations could effectively run a red team every day — continuously probing their own systems rather than waiting for a periodic engagement.

That shift changes the economics of offensive-style testing. Exercises that once required budget approvals and outside consultants become something an internal team can repeat often enough to catch issues before they become incidents.

From findings to fixes

The harder part of security work is not finding a problem but resolving it. Lawson argued AI can shorten that path too, helping analysts identify and implement fixes more quickly once a ticket is opened.

“What if I could spend three minutes going to Gemini and saying ‘Write syntax for an F5 IRule’ that becomes a virtual patch? Everyone can do threat intelligence, enrichment, some of those harder tasks.”

— Craig Lawson, research vice president at Gartner

The example points at a practical bottleneck: translating a discovered flaw into a working mitigation, especially for teams without deep specialization in every product they run. If AI can draft that syntax, the gap between disclosure and defense narrows.

Celebrating the work that matters

Lawson also wants organizations to change how they measure security operations centers. Today, he said, SOCs measure staff by the number of tickets they process and close — a metric that rewards volume rather than outcome.

He thinks a better approach is to celebrate the fact that cyber-defenders kept a hospital open or stopped a ransomware raid. That reframing puts the emphasis on harm prevented rather than queues cleared.

The metric shift is not cosmetic. Ticket-count incentives can push analysts toward closing items quickly rather than solving the underlying problem, while outcome-based recognition aligns the team with the mission the business actually cares about.

What the numbers show

  • Microsoft delivered over 970 patches last week.
  • Lawson expects a possible net drop in flaw severity in 2027.
  • He cited a recent series of CVEs in OpenBSD as evidence AI bug-hunters are finding flaws in hardened code.
  • He described a hypothetical three-minute AI-assisted workflow to produce syntax for an F5 IRule as a virtual patch.

What it could mean for defenders

The practical upshot for security leaders is that the current patching crunch may be a peak rather than a plateau. If Lawson's scenario holds, the same AI that is generating the flood of findings today could be the thing that thins out the most dangerous ones tomorrow.

That is an inference about direction, not a promise. The source material offers no guarantee that attackers will not find ways to use AI that offset defensive gains, and Lawson's remarks do not include an investment recommendation or a prediction that overall CVE counts will fall.

What the source does support is a narrower, more testable set of expectations: more thorough auditing of existing code, more frequent internal red teaming, faster drafting of mitigations, and a possible drop in the severity of flaws reaching defenders in 2027.

For businesses, the takeaway is to watch severity trends rather than raw CVE totals when judging whether their patching burden is actually easing, and to consider how their own teams measure success. For consumers, the hope is quieter — that the software they rely on gets audited more thoroughly than it ever was before, and that the worst flaws are caught earlier.

#mythos#patching#gartner#vulnerability management#ai security

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories