Microsoft FORGE Lab Identifies 140 Windows CVEs, Pushes AI-Driven Vulnerability Research to Scale
Microsoft's FORGE Lab has discovered 140 Windows CVEs and 155 reports across 23 open-source projects, highlighting the critical need to scale vulnerability validation and remediation alongside AI-driven discovery.

Microsoft Security's Frontier Offensive Research & Generative Exploitation (FORGE) Lab has announced significant findings from its AI-native vulnerability research efforts, identifying 140 Common Vulnerabilities and Exposures (CVEs) in Windows and submitting 155 validated reports across 23 open-source projects, including the Linux kernel. These results, spanning from May to September 2026, demonstrate the growing capability of AI agents to discover complex software flaws, but also underscore a critical challenge: scaling the process of validating and remediating these vulnerabilities to match the accelerated discovery rates.
The FORGE Lab's work has already led to tangible security improvements. Of the 140 Windows CVEs found, 52 were addressed in Microsoft's September 2026 security release. Beyond Windows, the lab's contributions extended to the open-source community, with one Linux kernel vulnerability report being the first to be patched through the Linux Foundation's Akrites initiative. This success highlights the potential for AI-driven research to bolster the security of widely used open-source software, but it also brings into focus the bottleneck of moving from discovery to deployed fixes.
A central theme emerging from FORGE's research is the shift from demonstrating "frontier capability"—the ability of AI to find novel and difficult bugs—to achieving "repeatable scale." The lab emphasizes that finding a vulnerability is only the first step; the real challenge lies in establishing systems that can consistently move these findings through validation, remediation, and release processes. This requires more than just better AI models; it necessitates robust infrastructure for reproducible testing, efficient deduplication, and streamlined review workflows.
To address the growing volume of AI-generated vulnerability candidates, FORGE is focusing on optimizing "reasoning economics" rather than simply minimizing "token consumption." This means prioritizing reports that provide sufficient evidence for the next stage of the security lifecycle, even if they are longer or more detailed. The lab utilizes its multi-model agentic scanning harness, MDASH, to manage this complex workflow, aiming to convert raw findings into actionable intelligence that engineers and maintainers can readily use.
Key to achieving scale is the development of project-specific automated provers, such as proof-of-vulnerability (PoV) and proof-of-concept (PoC) generators. These tools are crucial for transforming potentially valid reports into reproducible evidence by finding crashing inputs, confirming execution paths, and producing regression-ready triggers within a project's native build and test environment. This automation helps reduce the burden on human triagers, accelerates the remediation process, and makes vulnerability research more sustainable.
FORGE's research also points to the importance of "validation and remediation as a continuous learning loop." As AI systems generate more vulnerability candidates, the bottleneck shifts from discovery to accurately identifying which reports are genuine, exploitable, and security-relevant. By integrating feedback loops from validation and remediation back into the AI discovery process, organizations can refine their models and workflows, leading to more efficient and effective security outcomes.
The lab's findings suggest that the scarce resource in AI-driven security research is often not the AI model's intelligence itself, but rather the availability of working build and deployment environments, reproducible exploit triggers, or the time of skilled engineers. Addressing these constraints is paramount for organizations looking to leverage AI for proactive security and keep pace with the evolving threat landscape.
Looking ahead, the FORGE Lab plans to continue advancing the frontier of autonomous security engineering, focusing on building ecosystems and fostering understanding to enhance the security of both Microsoft products and the broader open-source software landscape. Their work serves as a critical case study for the industry on how to transition AI-driven vulnerability discovery from a promising capability to a scalable, operational reality.