Skip to content
AI Agents Accelerate Discovery of RCE Vulnerabilities

AI Agents Accelerate Discovery of RCE Vulnerabilities

First seen 1 Oct 2026, 17:04 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 17:05 UTC
  • •AI agents are discovering RCE vulnerabilities at a rate of 50%, nearly double traditional methods.
  • •CVE-2026-1731, a critical RCE vulnerability, was exploited within days of its disclosure.
  • •The AI/LLM stack has over 2,000 tracked CVEs, highlighting a growing attack surface.

AI research agents have identified remote code execution (RCE) vulnerabilities at a rate of 50%, nearly double the traditional rate of 26%. The GTIG report, published on September 30, 2026, highlights the case of CVE-2026-1731, a RCE vulnerability in BeyondTrust software, discovered on February 6, 2026. Within days of its disclosure, threat actors exploited this flaw, deploying malware like SparkRAT and VShell backdoors, affecting over 16,400 instances across sectors including finance, healthcare, and government. The report indicates a significant increase in monthly vulnerability disclosures, which doubled from January to August 2026. AI agents are also shifting the risk profile, with a higher percentage of medium and high-risk findings compared to traditional methods. The AI infrastructure itself has become a target, with over 2,000 CVEs tracked in the AI/LLM stack, including CVE-2026-42271 and CVE-2026-5027, which are. The report emphasizes the urgent need for improved vulnerability management to keep pace with automated discovery.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-04-07
CVE-2025-3248 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-02-06
CVE-2026-1731 published
A critical RCE vulnerability in BeyondTrust software was disclosed, with a CVSS score of 9.9.
Tech.Yahoo
2026-02-11
First public PoC for CVE-2026-1731
Proof-of-concept code for the critical RCE vulnerability was made publicly available.
Tech.Yahoo
2026-02-13
CVE-2026-1731 added to CISA KEV
CISA listed CVE-2026-1731 as actively exploited, confirming the threat's severity.
Tech.Yahoo
2026-03-27
CVE-2026-5027 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-08
CVE-2026-42271 published
A high-risk vulnerability in the AI/LLM stack was disclosed, with a CVSS score of 8.7.
Tech.Yahoo
2026-06-08
CVE-2026-42271 added to CISA KEV
CISA confirmed that CVE-2026-42271 is actively exploited in the wild.
Tech.Yahoo

More articles in this cluster (2)

Following this threat?

Track Carbonato, Bitget and CVE-2025-3248 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What is CVE-2026-1731?
CVE-2026-1731 is a critical remote code execution vulnerability in BeyondTrust software, published on February 6, 2026.
How quickly was CVE-2026-1731 exploited?
Threat actors began exploiting CVE-2026-1731 within four days of its disclosure.
What sectors are affected by these vulnerabilities?
The vulnerabilities impact various sectors, including financial services, healthcare, and government.