← Back to feed
AI SecurityEmerging1 sourceJul 26, 2026 · 11:47via Checkmarx

Zombie CVEs: Put to Rest by Humans, Dug Back Up by AI Agents

Brief

New research: 65–75% of frontier AI agents’ working patches resurrect vulnerabilities that were already found, fixed, and buried.

In 2023, a path traversal vulnerability in Starlette, one of Python’s most popular web frameworks – was found, disclosed as CVE-2023-29159, and fixed. Case closed. The bug was dead and buried, like hundreds of thousands of CVEs before it: discovered by researchers, patched by maintainers, laid to rest by the security community’s accumulated, painstaking work.

In 2026, a frontier AI coding agent rebuilt that same feature. The vulnerability walked right back out of the ground. And it wasn’t a one-off.

That is the one of the central findings of new independent research Checkmarx commissioned from Ilya Kabanov , CEO of The Weather Report — the first study to measure, generation over generation, whether AI code is getting safer as it gets better .

Read more on Checkmarx