Google GTIG finds AI accelerating vulnerability discovery across enterprise and critical ...
New data from Google Threat Intelligence Group (GTIG) found that artificial intelligence is changing the pace of vulnerability discovery and exploitation, with implications for enterprise and critical infrastructure attack surfaces. Vulnerability disclosures doubled from 5,045 in January 2026 to 10,740 in August, while the average number of vulnerabilities exploited each month increased from 10.5 in 2025 to 18 between January and August 2026. GTIG said the growth in exploitation was driven primarily by rapid weaponization of high-risk, previously disclosed vulnerabilities, rather than a major increase in zero-day exploitation.
The research found that vulnerabilities affecting edge and security appliances accounted for 14% of vulnerabilities exploited from January through August 2026, while another 11% affected enterprise directory and collaboration hubs. More than 65% of exploited edge vulnerabilities met GTIG’s High or Critical threat-risk ratings, with adversaries targeting unauthenticated public management interfaces.
GTIG also said exploitation of High-Risk vulnerabilities more than doubled, from 28 in 2025 to 75 during the first eight months of 2026, highlighting the exposure of perimeter and enterprise infrastructure to faster vulnerability weaponization. The data disclosed that AI-assisted vulnerability discovery is also producing a different risk profile, with AI-discovered vulnerabilities showing a higher proportion of Medium- and High-Risk findings and vulnerabilities resulting in remote code execution.
From January through August 2026, 58% of identified AI-discovered vulnerabilities were rated Medium risk, compared with 28% among vulnerabilities not discovered by AI, while 50% of AI-discovered vulnerabilities resulted in remote code execution compared with 26% across the broader CVE ecosystem. GTIG said autonomous research agents can uncover high-severity flaws when directed at critical attack surfaces, while organizations are also facing a growing attack surface around AI systems, with 2,076 AI-related CVE disclosures tracked from January 2025 through August 2026.
During the same period, GTIG recorded 141 distinct vulnerabilities disclosed and exploited, surpassing the total number of vulnerabilities exploited for the full year of 2025 (127). In-the-wild exploitation increased from an average of 10.5 per month in 2025 to 18 per month in 2026. However, proportion of vulnerabilities exploited versus disclosed remains vanishingly small: only 0.23% of all disclosed vulnerabilities in 2026 (roughly 1 in 431) were ever observed in active exploitation, or on the order of tens versus thousands per month. This means that monthly exploitation counts can more easily be influenced by other factors such as vendor disclosure cycles and threat actor campaign spikes.
Since May 2026, a shift has emerged, with the expansion of CVE exploitation (+127% indexed growth) closely mirroring disclosure growth (+128% indexed growth), scaling in tandem with the overall vulnerability landscape rather than outpacing it.
Plotting raw monthly counts hides relative momentum because of the vast disparity between single-digit zero-day discoveries and the more than 10,000 vulnerabilities disclosed in August, for example. To enable a direct comparison of growth rates across vulnerability tiers, Figure 7 indexes four metrics to a baseline of 0 in January 2025 and provides a trendline of the three-month rolling average growth rate.
Overall CVE disclosure rose by 128%. As previously stated, raw counts of CVE disclosures doubled from January 2026 to August 2026, and the three-month rolling average growth rate suggests that disclosures have steadily accelerated in 2026. High-risk vulnerabilities disclosed rose by 241%, the steepest growth across the dataset. By August 2026, the count had climbed to almost 3.5 times its initial baseline. Excluding Linux, Oracle, and Totolink, the rate of increase was just 128% from January 2025 to August 2026.
CVE exploitation in the wild rose by 127%. From January to August 2026, exploitation increased at approximately the same rate as overall CVE disclosure, though the three-month rolling average trendline suggests that growth in exploitation did not begin to pick up until the second quarter of 2026.
Zero-days exploited rose by 59%. The count remained near baseline levels, between 8 and 12 zero-days per month, through mid-2026, but reached 22 in August. This increase is reflected in the three-month rolling average growth rate, which began to show an upward trend in the summer of 2026.
Current public data significantly undercount vulnerabilities discovered by AI because of two structural dynamics.
The first is the absence of standardized metadata. Public CVE repositories do not yet feature uniform metadata tags for AI attribution, which requires manual heuristic tracking. The second is silent first-party and cloud patching. Major cloud and SaaS providers routinely remediate AI-surfaced vulnerabilities directly in production without requesting formal CVE IDs, because CVE assignments are typically reserved for on-premises or third-party software that requires customer patching coordination. Many findings also remain embargoed for a period during established Coordinated Vulnerability Disclosure (CVD) windows.
However, vulnerabilities likely surfaced by autonomous agents can still be identified using a multi-tier verification process.
The first tier involves verified lab and vendor ledgers, which means directly ingesting confirmed disclosures from frontier AI research programs. The second tier involves advisory and release parsing, which means programmatically monitoring Cybersecurity and Infrastructure Security Agency (CISA) advisories, MITRE records, and vendor security bulletins for explicit acknowledgments that attribute root-cause discovery or proof-of-concept synthesis to autonomous AI agents, such as Hacktron AI and AISLE.
AI-discovered vulnerabilities differ sharply from other vulnerabilities in their exploitation consequences. Exactly 50% of AI-discovered flaws result in Remote Code Execution (RCE), compared with 26% across the broader CVE ecosystem, while AI agents surface Information Disclosure (8% vs. 18%) and Data Manipulation (5% vs. 9%) at less than half the rate of vulnerabilities not discovered by AI.
This concentration on code execution likely stems from how frontier agents operate. They navigate complex, multi-step code paths across core C/C++ libraries, runtimes, and hypervisors, and by synthesizing fuzzing harnesses, modeling memory states, and chaining edge-case logic, they excel at finding memory corruption and logic bypasses that traditional static analyzers consistently miss.
Although still an early indicator rather than an established trend, confirmed exploitation shows the risk from AI-discovered flaws is not purely theoretical. A notable case is CVE-2026-1731, an unauthenticated OS command injection flaw in BeyondTrust Privileged Remote Access and Remote Support, discovered autonomously by a third-party research agent, Hacktron AI.
Within four days of public disclosure, GTIG observed a threat cluster exploiting it, followed by five more clusters within seven days. These actors conducted post-exploitation activity, including privilege escalation, data exfiltration, and the dropping of secondary payloads such as SNOWLIGHT, SPARKRAT, and cryptominers, showing that the high-impact vulnerabilities defensive AI agents uncover are ones threat actors actively seek to exploit.
From January 2026 through August 2026, disclosures of AI application vulnerabilities were heavily concentrated in three core areas, including agent orchestration frameworks, backend serving infrastructure, and enterprise AI gateways.
Agent orchestration is the primary chokepoint. Orchestration middleware accounts for 50% of all AI-related flaws and saw a 347% surge in disclosures in 2026. Visual workflow builders, such as Flowise and Langflow, and autonomous frameworks often deploy dynamic code execution nodes to facilitate environment interaction. Attackers exploit these nodes via prompt injection or crafted workflow JSONs to hijack execution loops, turning natural language prompts into unauthenticated Remote Code Execution.
Centralized AI gateways create a catastrophic dual-threat vector and enable lateral movement through cloud environments. At the application layer, compromised gateways expose third-party application programming interface (API) keys and private prompt streams containing personally identifiable information (PII) or proprietary source code. At the infrastructure layer, they act as initial footholds for adversaries to harvest database credentials and pivot laterally into internal cloud environments.
Inference gateways are the new perimeter. Disclosures across backend serving infrastructure, such as vLLM, Triton, LiteLLM, and Ollama, reached 212 vulnerabilities in 2026. Nearly a quarter (24%) of these flaws stem directly from unauthenticated API endpoints or Server-Side Request Forgery (SSRF), which gives remote adversaries direct entry points to bypass perimeter firewalls, exhaust expensive GPU compute resources, or extract proprietary model checkpoints.
GTIG expects rates of vulnerability discovery and exploitation to keep increasing in the short to medium term. Its May AI Threat Tracker reported the first known case of a threat actor holding a zero-day exploit script developed with generative AI, which was intercepted during operational planning before in-the-wild execution but bore high-confidence LLM generation markers. Its September tracker noted threat actors sharing resources and prototyping agentic vulnerability discovery tooling.
Although public data on AI-augmented vulnerability discovery and on vulnerabilities targeting AI infrastructure is still in its early days, emerging signals show that autonomous research agents can uncover high-severity flaws when directed at critical attack surfaces. By reasoning through complex semantic code paths and synthesizing dynamic proof harnesses, they excel at finding memory corruption and logic bypasses in core libraries and runtimes, the very flaws sophisticated adversaries seek to exploit.
As threat actors begin exploiting vulnerabilities in AI systems in the wild, organizations cannot treat AI security as an afterthought. They need immediate containment strategies, sandboxing of autonomous agentic workloads, and risk-based vulnerability management. The cybersecurity community has a window of opportunity to strengthen defenses on two fronts before threat actors scale up zero-day and n-day exploitation.
First, organizations must modernize how they triage and remediate disclosed vulnerabilities, following the blueprint for AI-Assisted Vulnerability Management that Mandiant published. Second, organizations that provide software or services to others should proactively run AI-enhanced code review internally, using agentic defensive tools such as CodeMender, integrated into Google AI Threat Defense, to continuously audit and patch code across developer workflows. If pre-release AI code review becomes standard practice, the growth in public vulnerability disclosures could eventually slow.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
