Venturebeat AI-Driven Vulnerability Ranking Raises Concerns Over Accuracy
Article Content
- •Microsoft's Patch Tuesday on September 8 included a record 1,169 CVEs reported by Senserva.
- •Ivanti's AI system has been found to fabricate details in security guidance, raising trust issues.
- •Two zero-day vulnerabilities were reported in the latest patches, emphasizing the urgency of accurate risk assessment.
On September 8, 2026, Microsoft released its largest Patch Tuesday update, with discrepancies in CVE counts reported by various trackers. Ivanti's VP Chris Goettl revealed that their AI system, trained on patch data, occasionally fabricates details, leading to uncertainty in the security guidance provided to enterprise customers. The discrepancies in CVE counts reached up to 205, with Tenable reporting 964 CVEs and Senserva reporting 1,169 for the same patches. This situation highlights a broader issue where AI tools used by security vendors may produce unverified data. The AI system is designed to prioritize risks based on vendor advisories and does not access customer data. However, the reliance on AI for security guidance raises questions about the integrity of the information being disseminated. The impact of these vulnerabilities is significant, particularly as two of the reported CVEs were zero-days exploited before the patches were released. The current status indicates a need for human oversight in AI-generated security assessments.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…