Skip to content
AI-Driven Vulnerability Disclosures Double Amid Rising RCE Risks

AI-Driven Vulnerability Disclosures Double Amid Rising RCE Risks

First seen 30 Sep 2026, 14:29 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 30, 2026 at 17:31 UTC
  • •Vulnerability disclosures doubled from 5,045 to 10,740 between January and August 2026.
  • •50% of AI-discovered vulnerabilities enable remote code execution, compared to 26% of non-AI findings.
  • •High-risk vulnerabilities increased by 167%, with 350 reported in August 2026.

A report from Google's Threat Intelligence Group reveals that vulnerability disclosures have doubled from 5,045 in January 2026 to 10,740 in August 2026, largely influenced by AI technologies. The number of vulnerabilities exploited in the wild also increased, averaging 18 per month, compared to 10.5 in 2025. Notably, 50% of AI-discovered vulnerabilities allow for remote code execution (RCE), a significant increase compared to 26% of non-AI vulnerabilities. High-risk vulnerabilities grew by 167%, with 350 reported in August. Zero-day exploitation saw a slight rise to an average of 11 per month, with a notable spike to 22 in August. The report highlights that many vulnerabilities are inflated due to automated CVE assignments, particularly those related to the Linux kernel. GTIG suggests that attackers may be leveraging AI tools to rapidly exploit known flaws. The report emphasizes the need for organizations to adopt threat-intelligence-driven triage for effective vulnerability management.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-04-07
CVE-2025-3248 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-01-01
Monthly disclosures begin tracking
Vulnerability disclosures were recorded at 5,045 for January 2026, marking the start of significant increases.
Securityweek
2026-02-06
CVE-2026-1731 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-27
CVE-2026-5027 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-08
CVE-2026-42271 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-31
August disclosures peak
Vulnerability disclosures peaked at 10,740 in August 2026, reflecting a doubling trend.
cloud.google.com
2026-09-25
CVE-2026-65660 added to CISA KEV
CVE-2026-65660, a high-risk vulnerability, was added to the CISA Known Exploited Vulnerabilities catalog.
Infosecurity-Magazine

More articles in this cluster (7)

Following this threat?

Track Jadepuffer, Snowlight and Langflow in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed