Research·EASYHUB JOURNAL
Microsoft FORGE reports 140 Windows CVEs and 155 internally validated open-source vulnerability reports from scaled AI-assisted research

What changed
Microsoft Security's FORGE Lab published scaled AI-assisted vulnerability-research results on October 7. From May through September 2026, FORGE says it helped discover Windows vulnerabilities assigned 140 CVEs, including 52 addressed in the September security release. The team also submitted 155 internally validated reports across 23 open-source projects and says 93 reports across 14 projects or project families had documented maintainer acknowledgement or acceptance at the time of writing. FORGE uses a multi-model agentic scanning harness called MDASH and argues that validation, remediation and maintainer review throughput are becoming the limiting factors. These are Microsoft-reported research figures, not a claim that every open-source report became a CVE.
- Original title
- 3 lessons from frontier AI vulnerability research
- Source
- Microsoft · www.microsoft.com
- Topic
- Research
- Source month
- 2026-10
This is a concise EasyHub summary of the linked source, not the full report or original reporting. Availability and preview conditions are described in the summary and original.
Summary page published · Editorial information