AI just changed the vulnerability clock.
Palo Alto Networks CEO Nikesh Arora told the All-In podcast that AI found vulnerabilities in six weeks that would normally have taken five to seven years to find. The management lesson is not just that AI helps security teams. It is that the discovery timeline for old code, exposed systems, and weak patch operations may have compressed from years to weeks.
Executive Summary
- AI is turning vulnerability discovery into a speed problem. Boards should assume attackers will eventually get similar scanning leverage.
- Legacy code is a balance-sheet risk when a model can surface years of buried flaws in weeks.
- The hard part is not only finding bugs. It is triage, ownership, patch delivery, exposure reduction, and proof that customer-facing risk went down.
- Security teams will be augmented, but the bottleneck moves to engineering capacity, decision rights, and operational discipline.
Arora's point is bigger than Palo Alto Networks.
The All-In source frames Palo Alto Networks as a major cybersecurity winner and uses Arora's comments to show what frontier models can already do against software security backlogs.
Arora's quoted claim is blunt: in six weeks, AI found vulnerabilities that would normally have taken five to seven years to find. Palo Alto Networks' own May 2026 update gives the broader company context. The company said it had tested frontier models including Anthropic's Mythos, Claude Opus 4.7, and OpenAI's GPT-5.5-Cyber. It also said the majority of findings in its May Patch Wednesday advisory came from frontier AI model scanning.
"In 6 weeks we found vulnerabilities which would have normally taken us 5 to 7 years to find."
Nikesh Arora, quoted by CEOInterviews.AI from the June 2026 All-In appearanceAI compresses security review
Manual review, penetration testing, and code audit cycles do not disappear, but AI can scan broader surfaces faster and produce a larger first-pass vulnerability backlog.
Leadership impact: more findings, faster.Old flaws become visible
The strategic risk is the accumulated software base. Years of human-written code may contain issues that become discoverable once model-driven scanning improves.
Leadership impact: legacy risk repricing.Cybersecurity demand rises
The source positions Palo Alto Networks as a likely beneficiary because AI increases both offensive pressure and defensive urgency.
Leadership impact: security becomes more strategic.Humans are not removed
Security teams still need to validate, prioritize, patch, and monitor. AI changes throughput and scale, not accountability.
Leadership impact: augment the team.The vulnerability clock has moved.
When discovery speed changes, the entire risk model changes: backlog size, exploit timing, patch capacity, and customer assurance all need new assumptions.
Vulnerability discovery was constrained by human review capacity, specialist availability, and periodic testing cycles.
Quarterly remediation, sampled testing, and risk acceptance often felt adequate.
AI can scan larger codebases faster and surface more possible defects, especially when given the right context and harnesses.
Engineering, product, legal, customer success, and security need a shared remediation lane.
Palo Alto Networks estimated a narrow three-to-five-month window for organizations to outpace adversaries before AI-driven exploits become a new norm.
Exposure reduction and virtual patching become board-level operational topics, not just security tooling choices.
The finding is not "AI found bugs." The finding is "AI may erase the time advantage that organizations assumed they had."
The risk moves from unknown defects to unowned remediation.
Once AI finds a large backlog, the enterprise failure mode becomes slow ownership and unclear tradeoffs.
Turn AI scanning into a remediation system.
The companies that benefit most will not be the ones that run the newest model once. They will be the ones that build a repeatable find, triage, patch, verify, and report loop.
Scan the real estate
Include production code, customer-facing applications, open-source dependencies, SaaS configurations, cloud exposure, and AI infrastructure.
Triage by reachability
Prioritize exploitable paths, internet exposure, customer impact, privilege boundaries, and compensating controls.
Patch with owners
Assign product, engineering, DevOps, legal, comms, and customer success owners for each class of remediation.
Verify continuously
Rescan after patches, test for regression, and track whether fixes actually reduce reachable risk.
Protect during the gap
Use segmentation, WAF rules, endpoint controls, virtual patching, monitoring, and response automation while fixes ship.
Report in business language
Show the board the vulnerable surface, the risk trend, time-to-fix, residual exposure, and investment constraints.
What leaders should ask this quarter.
The right questions are operational, not theoretical.
Questions that expose risk
- What percentage of our customer-facing code has been scanned with AI-assisted vulnerability discovery?
- Which findings are externally reachable or chained into critical exploit paths?
- What is our current median time from finding to validated fix?
- Where do we lack ownership because the bug crosses product, platform, or supplier boundaries?
Questions that create discipline
- What evidence can we show auditors, insurers, regulators, and enterprise customers?
- Which compensating controls protect customers before code fixes ship?
- What is the monthly executive cadence for AI-assisted scanning, patch progress, and residual exposure?
- How are we building secure-by-design practices into the development lifecycle?
Source notes.
The source video is the driver. Palo Alto Networks' May 2026 blog provides the supporting operational detail behind the same moment.
Palo Alto Networks CEO: "AI Found 5 Years of Bugs in 6 Weeks". Episode notes highlight Claude Mythos finding years of vulnerabilities in Palo Alto's code in weeks.
Verified quote page for Nikesh Arora's "six weeks" and "five to seven years" statement.
Defender's Guide to the Frontier AI Impact on Cybersecurity: May 2026 Update. Reports the initial scan of more than 130 products, 26 CVEs representing 75 issues, and immediate recommendations.
Palo Alto Networks says Mythos, GPT-5.5 found bugs in weeks. Independent business press coverage of the disclosure.