I am not sure it is what is happening here, but a problem I have seen with internal QA and Security-focused teams is that they are incentivized to file bugs. The number of bugs filed if their monthly/quarterly achievement, it has nothing to do with the quality of those bugs or how they improve the quality of security. Just "hey I found these 10 bugs that I labeled XXX severity".
I just imagine somewhere there are people updating their CV or something else with "filed XX CVE's" like it is some kind of accomplishment for them.