Bankinfosecurity Google Reports AI Identifying Medium-Risk Vulnerabilities
Article Content
- •AI tools are finding primarily medium-risk vulnerabilities, with 58% classified as such.
- •The total number of known vulnerabilities has doubled over the past 18 months, exceeding 10,000.
- •Organizations must modernize their defense strategies to address the increasing number of CVEs.
Google's analysis reveals that artificial intelligence tools are primarily discovering medium-risk vulnerabilities, with 58% of AI-identified flaws classified as medium risk and only 4% as high risk. Over the past 18 months, the number of known vulnerabilities has doubled, surpassing 10,000 in July 2026. Despite concerns of a 'vulnpocalypse,' the increase in AI-discovered vulnerabilities has not led to a significant rise in hacking incidents. Google emphasizes that organizations need to adapt their defense strategies to manage the growing number of Common Vulnerabilities and Exposures (CVEs). The research also identified 782 vulnerabilities in AI orchestration and agent frameworks, which are particularly susceptible to exploitation through prompt injection attacks. Threat actors are likely using AI to enhance their capabilities in analyzing vulnerabilities and exploiting flaws. Organizations are advised to implement efficient patch management plans and maintain a clear understanding of their assets' internet accessibility.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Anthropic in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What types of vulnerabilities are being found?
How many vulnerabilities have been disclosed recently?
What should organizations do to address these vulnerabilities?
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…