When the patch tsunami meets the maintenance window
Brief
In April 2026, the balance between finding software flaws and fixing them broke. Frontier AI models released by Anthropic and OpenAI can now autonomously identify exploitable vulnerabilities in production software — work that used to take experienced human researchers roughly sixty days now takes about four hours, as Melissa Hathaway documents in a recent Cyber Defense Review perspective .
According to the same paper, at least 40 of the largest software and hardware vendors already have access to these models, and Anthropic’s Mythos reportedly surfaced critical flaws in 99 percent of widely used operating systems and browsers.
Hathaway’s conclusion is blunt: four decades of “field it fast and fix it later” technical debt is now coming due, and the industry should expect a tidal wave of patches over the next twelve to twenty-four months rather than the next decade.
