Skip to content
AI Agents Find RCE Vulnerabilities at Double the Traditional Rate

AI Agents Find RCE Vulnerabilities at Double the Traditional Rate

Forkast.News • October 1, 2026

Autonomous research agents are now identifying vulnerabilities that lead to remote code execution (RCE) at a rate of 50%, nearly double the 26% observed across the broader CVE ecosystem . This finding, detailed in the GTIG report published September 30, 2026, highlights a shift in how software flaws are surfaced and subsequently weaponized.

The mechanics of this risk are visible in the case of CVE-2026-1731, a CVSS 9.9 pre-auth RCE in BeyondTrust remote support software. Hacktron AI identified the vulnerability on January 31, 2026, through AI-enabled variant analysis. According to the company, their autonomous scans are designed to discover vulnerability classes and variants across enterprise software at scale. Within four days of disclosure, threat actors began exploiting the flaw. By the seventh day, five distinct threat clusters were active, utilizing the vulnerability to deploy SparkRAT, VShell backdoors, and conduct data exfiltration via DNS tunneling. Telemetry from Cortex Xpanse indicated over 16,400 exposed instances at the time, affecting sectors including financial services, healthcare, and government across multiple continents.

The broader data suggests that the velocity of vulnerability management is failing to keep pace with automated discovery. Monthly vulnerability disclosures doubled from 5,045 in January 2026 to 10,740 in August 2026. High-risk vulnerabilities saw a 167% surge, rising from 131 to 350 in the same period. The GTIG report identifies the primary growth driver as the rapid weaponization of n-days, rather than a surge in zero-day exploits, which remained relatively stable at an average of 11 per month in 2026.

AI-discovered vulnerabilities are also inverting traditional risk distributions. While conventional discovery methods yield 69% low-risk findings, AI agents shift the focus, with 58% of their discoveries categorized as medium threat risk and 4% as high, compared to 3% for conventional methods. The GTIG report notes that autonomous research agents excel at reasoning through complex semantic code paths and synthesizing dynamic proof harnesses, surfacing memory corruption and logic bypasses in core libraries and runtimes. Conversely, these agents currently under-index in lower-impact categories like information disclosure and data manipulation.

The AI infrastructure itself has become a primary attack surface. Between January 2025 and August 2026, 2,076 cumulative CVEs were tracked within the AI/LLM stack, with over 1,500 occurring in the first eight months of 2026. Agent orchestration frameworks accounted for 782 of these, representing 50% of all AI-related flaws and a 347% surge. Specific vulnerabilities, such as CVE-2026-42271 in LiteLLM and CVE-2026-5027 and CVE-2025-3248 in Langflow, demonstrate active exploitation within this stack.

These developments align with incidents tracked by Forkast. The DIVD Zammad breach , the use of an AI agent as C2 in the CARBONATO Docker botnet , the DNS sandbox escape at OpenAI’s Misalignment Portal, and the $387.5 million Bitget theft via a security appliance zero-day all underscore the increasing integration of AI in both offensive and defensive operations.

Grunewald, Mazumdar, and Vanderlee state that industry data on AI-augmented discovery is currently incomplete. The baseline is still under construction. However, existing metrics confirm that the interval between automated discovery and automated exploitation has compressed to days. For enterprise security teams, this velocity gap represents the primary structural challenge.