Part 1 of a two-part series.
Security teams already own more scanners, exposure platforms, and dashboards than they can act on, yet the vulnerability backlog grows every week. The bottleneck has moved downstream, from finding vulnerabilities to remediating them, and AI-generated code widens that gap faster than any hiring plan can close it. On a recent Backline Unfiltered episode, Google’s Knox Anderson framed the way out: you can prioritize the pile, or you can shrink it, and shrinking it is where this series begins.
Every security leader knows the backlog is too big. The harder part is that volume was never the constraint. Remediation capacity is, and AI keeps widening the gap faster than anyone can hire or patch. (And even if you could hire, who approves that headcount?).
So the question for 2026 has changed shape. Ranking another thousand findings does little when the pile refills by morning. This piece looks at why vulnerability management no longer scales. The next one covers what to do upstream about it.
Where vulnerability management runs out of road
You bought the scanners. Then you bought the exposure platform that promised to rank what they found. And the backlog still grows anyway.
Many CISOs live that pattern every morning, opening a dashboard with thousands of “critical” findings and a number that never drops. Gartner analysts called it the dashboard of despair.
The industry keeps renaming the problem. Risk-based vulnerability management became exposure management, which nearly every vendor now positions as the better way to prioritize. Knox has watched that evolution up close, and he’s blunt about what it actually changes.
Exposure management, in his framing, is another prioritization vehicle. First the question was discovery. Then it became cloud context: is this misconfigured, is it publicly reachable. Useful questions, all of them. But they circle the same unsolved center, because someone still has to go patch the thing.
“The heart of the problem still hasn’t really been solved,” Knox said, “which is someone needs to go and patch that vuln.”
Reachability scoring and cloud context make the ranking better. They don’t shrink the work. A security team can sort ten thousand findings into a flawless priority order and still miss most SLAs, because sorting was never the same as fixing.
Which is where Knox reframes the whole exercise: “You can either prioritize the pile or have a smaller pile. And I’d love to start with the smaller pile.”
For a CISO, that reframe lands as a metric change. The board doesn’t want to hear how well you ranked this quarter’s findings. It wants to see exposure eliminated, the trend line bending down. Prioritization can’t bend that line. A smaller pile can.
And the reason the pile keeps refilling faster than anyone can empty it has a new name this year.
How AI turned code generation into backlog generation
There’s a new source feeding the pile this year, and much of it comes from people with no security training.
One of Backline’s hosts on the episode zeroed in on it: vibe coding, people shipping AI-generated code they don’t fully understand. Some are developers moving fast. Some aren’t developers at all.
Knox told a story that’s hard to shake. His aunt is a doctor, and she’s diabetic. To keep an eye on her insulin monitoring, she cloned a GitHub repo and wired it up herself. He and his brother looked it over and saw that nobody had secured it, and it was connected to her insulin pump.
A physician tied her physical safety to unvetted code, because the productivity gain was too useful to pass up. If a doctor does that, a developer under deadline certainly does.
Every one of those shortcuts becomes remediation work later. AI generates code faster, which means it generates exposure faster, unless fixing scales at the same rate. Right now, in most companies, it doesn’t.
The threat data backs this up. Knox pointed to the Verizon report, where for years stolen credentials and leaked keys drove cloud breaches. Over the past year, exposed instances with vulnerabilities rose to sit right alongside them as a leading cause.
And the attackers aren’t waiting. They use the same AI speed to find flaws and build exploits, which is why mean time to exploit keeps shrinking toward zero. Mandiant’s M-Trends research has tracked exploitation that lands before a patch even ships.
Three more analysts won’t solve that. The gap is structural now, baked into how teams build software.
The metric that matters more than your backlog size
So if the pile refills this fast, the remediation has to move upstream, The next piece in this series takes that on.
Until then, there’s a question worth putting to your own dashboards. They almost certainly count findings and rank severity. Do any of them measure exposure actually eliminated, and how fast? The shift itself, from what you found to what you closed, is what Knox’s smaller pile is built to serve. It’s also the honest way to tell your board whether the trend line is bending down or being resorted one more time.