Desk live·
ForensicPost
Cloud/Vulnerabilities/File 26-0410

Only 97 of 1,596 Vulnerabilities Disclosed to Open-Source Maintainers Were Patched

Of roughly 1,596 vulnerabilities disclosed to open-source maintainers, about 97 had been patched by May 2026. Finding a defect and fixing it turn out to be very differently resourced activities.

Constructed geometry · not a chart of case data
TargetOpen-source maintainers
ActorResearch consortium
D. Kennedy13 min readConfidence: high3 sources reviewed

Approximately 1,596 vulnerabilities had been disclosed to open-source maintainers as of May 2026 under the programme filed at 26-0404. Around 97 had been patched, with 65 published security advisories. That is a remediation rate of roughly six per cent.

The finding that matters here is not about any project’s diligence. It is that discovery scaled and remediation did not, and the two are performed by entirely different parties.

The Asymmetry Is Structural

Discovery is now a capital expenditure. An organisation with compute and a model can generate findings continuously, and the cost per finding falls as the process improves.

Remediation is a human activity performed largely by volunteers. Someone must read the report, reproduce it, understand the surrounding code, design a fix that does not break dependents, test it, release it, and handle the fallout. None of that scales with compute.

The Recipients Did Not Agree To This Workload

A maintainer of a widely used library is frequently one person doing unpaid work in their own time. A report arriving from a well-resourced coalition is not a collaboration between equals; it is an obligation transferred from an organisation with a security budget to an individual without one.

The libraries named in this programme — FFmpeg, the Linux kernel — sit under almost everything, which is precisely why they were chosen and precisely why their maintainers are already the most heavily loaded people in the ecosystem.

What A Six Per Cent Rate Means For Defenders

Practically: roughly fifteen hundred known, disclosed, unfixed vulnerabilities in software that is deployed nearly everywhere, with no patch to apply.

For an organisation, that is not a patching problem. It is the argument this desk made at 26-0506 arriving from a different direction — the controls that matter are the ones that work while the defect is still present, because for most of these there will be no fix in any useful timeframe.

How we reported this

Compiled from published coalition material and independent analysis, listed below. Figures are as reported by the disclosing organisation, which has a commercial interest in the discovery capability; the patching figures are correspondingly the more conservative of the two claims it makes. Corrections: corrections@forensicpost.com.

Sources
  1. Project Glasswing and the AI vulnerability disclosure velocity crisisCloud Security Alliance
  2. Project Glasswing proved AI can find the bugs. Who’s going to fix them?The Hacker News
  3. Project Glasswing: an initial updateAnthropic
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary