# Palo Alto Networks’ NOVA AI finds 14,090 unknown vulnerabilities

2026-08-16T10:52:19+00:00 | Technology | Indian Opinion Desk

Corroboration: 1 independent outlet

Palo Alto Networks has unveiled NOVA, an autonomous AI system that discovered 14,090 previously unknown vulnerabilities across 3,915 open-source projects during a two-month test. The company reported that 99.4% of these flaws had not been publicly disclosed, and nearly 40% were rated High or Critical under the CVSS 4.0 framework. The system uses a multi-agent architecture to automate source-code analysis, vulnerability identification, proof-of-concept generation and disclosure preparation. Notably, 92% of the discoveries were logic and semantic flaws, such as access control errors and code injection, rather than traditional memory-corruption bugs, indicating AI's growing ability to handle complex security research. NOVA also uncovered 5,421 supply-chain findings, including 1,280 vulnerabilities in dependencies that created 4,141 downstream exposures. The report warns that faster AI-driven discovery may compress the time organisations have to patch flaws, while stressing that human researchers remain essential for validation and responsible disclosure.

## Coverage

- ciso.economictimes.indiatimes.com <https://ciso.economictimes.indiatimes.com/news/vulnerabilities-exploits/ais-dark-side-palo-alto-networks-nova-system-finds-thousands-of-critical-open-source-vulnerabilities/132991652>

This story was synthesised by AI from the source linked above.

Tags: AI, cybersecurity, NOVA, open-source vulnerabilities, Palo Alto Networks
Canonical: https://indianopinion.org/palo-alto-networks-nova-ai-finds-14090-unknown-vulnerabilities/
License: Summary and commentary (c) Indian Opinion, reusable with attribution. Facts belong to the linked sources.
Cite: https://indianopinion.org/palo-alto-networks-nova-ai-finds-14090-unknown-vulnerabilities/#story-in-brief

Review state: restored archive article, accurate at time of publication, not offered to search indexes.

How this brief was made: an AI model read the report linked above and wrote this summary and analysis, which were published automatically. Published briefs are sampled every hour by an automated quality check; the editor verifies its findings and approves corrections, and corrected briefs carry a dated correction line. We do no original reporting. Methodology: https://indianopinion.org/ai-use-policy/
