Skip to content
Google Finds Likely AI

Google Finds Likely AI

Superpowerdaily • September 30, 2026

Finding a security flaw does not mean defenders get to it first. Google Threat Intelligence Group found that half of the vulnerabilities it classified as likely AI-discovered allowed remote code execution—running code on a target system from elsewhere. Its new research also confirmed real-world exploitation of an AI-discovered BeyondTrust flaw, according to SecurityWeek’s September 30 account .

The analysis covers vulnerability disclosures from January 2025 through August 2026. For the likely AI-discovered subset identified between January and August this year, Google found a different distribution of risk: 39% were low-risk and 58% medium-risk. Among non-AI vulnerabilities, those shares were 69% and 28%. Google used its own risk ratings, rather than the standard CVSS scoring system.

Google offers two explanations for that difference, both qualified rather than proven causes. One concerns where researchers direct AI agents; the other concerns the kinds of defects those agents can detect.

Research targets: Google says programs likely steer AI agents toward critical infrastructure and sensitive boundaries between access levels, emphasizing higher-impact findings.

Detection strengths: Google suggests AI models can find memory corruption and logic flaws that traditional automated code-checking tools miss, helping explain the remote-code-execution .

The concrete exploitation example is CVE-2026-1731, a flaw in BeyondTrust Privileged Remote Access and Remote Support. Hacktron AI’s research agent discovered it autonomously . The flaw allowed operating-system command injection without authentication: an attacker could issue commands without first signing in.

One threat cluster exploited it within four days of public disclosure , and five more followed within seven days. Google treats exploitation of AI-discovered vulnerabilities as an early indicator, not an established trend. This case demonstrates a rapid handoff from discovery to abuse; it does not establish that the attackers themselves used AI.

Monthly disclosures rose from 5,045 in January 2026 to 10,740 in August. But Google cautions that automated assignment of CVEs—identifiers for disclosed vulnerabilities—in open-source software can inflate the total. Descriptions mentioning the Linux kernel alone accounted for roughly 5,000 CVEs from January through August, with no observed real-world zero-day exploitation.

The higher-risk measures also increased. Monthly disclosures rated high-risk by Google climbed 167%, from 131 in January to 350 in August. Across the first eight months of 2026, it recorded 141 distinct exploited vulnerabilities, exceeding the 127 recorded in all of 2025. Still, just 0.23% of this year’s disclosed vulnerabilities had been observed exploited.

Google suggests the growth in exploitation came primarily from n-days, or already known vulnerabilities. Zero-day exploitation rose less sharply, from a monthly average of eight in 2025 to 11 in 2026, although August reached 22. Zero-days are flaws exploited before they are known to the vendor.

Its proposed mechanism is practical: attackers may find it easier or more efficient to use language models to compare product versions and patches, inspect disclosure announcements, and analyze demonstration exploit code. That could help them turn known flaws into attacks faster than discovering new ones. Google presents this as a possible explanation, not a confirmed account of attackers’ methods.

The report also tracks flaws in AI systems themselves, distinct from flaws discovered using AI. Google counted 2,076 AI-related CVEs between January 2025 and August 2026, including more than 1,500 this year. Roughly half affected orchestration frameworks, which coordinate AI workflows. Only a handful were confirmed exploited, including flaws in LiteLLM and Langflow; Google had not observed zero-day exploitation of AI infrastructure.