Google Threat Intelligence Group (GTIG) has published one of the first data-driven attempts to measure what artificial intelligence is doing to the vulnerability landscape. The report, "Vulnerability Discovery and Exploitation Trends in the AI Era," was released on 1 October 2026 and written by Robin Grunewald, Supriya Mazumdar and Kelli Vanderlee. It finds that AI is changing both the pace of discovery and exploitation and the kind of bugs being found. Monthly CVE disclosures doubled in 2026. In-the-wild exploitation through August already exceeds all of 2025. Vulnerabilities that GTIG could attribute to AI-assisted discovery lead to remote code execution at almost twice the rate of everything else. GTIG's conclusion for defenders is blunt: stop mass-patching by volume and triage by threat intelligence.
Key findings
GTIG's dataset covers vulnerabilities disclosed from 1 January 2025 to 31 August 2026. Risk tiers in the report use GTIG's own vulnerability risk ratings, not CVSS severity.
- Disclosures doubled. Monthly disclosures rose from 5,045 in January 2026 to 10,477 in July and peaked at 10,740 in August.
- Exploitation nearly doubled. Exploited vulnerabilities averaged 10.5 per month in 2025 and 18 per month from January to August 2026. GTIG recorded 141 distinct exploited vulnerabilities in that period, against 127 for the whole of 2025.
- Zero-days rose only slightly. The average went from 8 to 11 per month, holding between 8 and 12 through mid-2026 before jumping to 22 in August. Zero-days still made up 62% of all exploited vulnerabilities from January to August 2026.
- AI finds more consequential bugs. Likely AI-discovered vulnerabilities include proportionally fewer Low-Risk and more Medium-Risk issues, and far more that lead to RCE.
What changed in 2026
Volume is not the same as risk
GTIG warns that raw disclosure counts can mislead. Automated CNA assignment policies in open-source ecosystems inflate the numbers: CVEs with "Linux Kernel" in the description alone generated about 5,000 CVEs between January and August 2026, with zero exploited zero-days observed. The more meaningful rise was in High-Risk vulnerabilities, which grew from 131 in January 2026 to 350 in August — a 167% increase — though they were still only 3% of August's disclosures.
Some of that High-Risk rise was concentrated in a few vendors. Mass research disclosures against TOTOLINK router firmware added 75 High-Risk flaws in April and May. Oracle's quarterly Critical Patch Update, combined with Linux kernel network driver advisories, contributed 128 High-Risk vulnerabilities in August alone, nearly 37% of that month's total. Outside these spikes, GTIG says baseline High-Risk disclosures still more than doubled, from about 65 per month in mid-2025 to about 135 per month in mid-2026.
Exploitation is growing in step with disclosure
Only 0.23% of all vulnerabilities disclosed in 2026, roughly 1 in 431, were observed being exploited. Because the exploited count is small, GTIG notes it can easily be moved by vendor disclosure cycles and campaign spikes. Since May 2026, growth in exploitation (+127% indexed) has closely tracked growth in disclosure (+128%) rather than outpacing it. Exploitation of High-Risk vulnerabilities more than doubled, from 28 in 2025 to 75 from January to August 2026.
GTIG's reading is that the growth comes mainly from "rapid weaponization of n-days," not new zero-days. It suggests attackers may find it easier to use LLMs to analyse patch diffs, version differences, disclosure announcements and proof-of-concept code than to find fresh zero-days.
Where attackers are aiming
Edge and security appliances accounted for 14% of vulnerabilities exploited in January–August 2026. Enterprise directory and collaboration hubs accounted for 11%. More than 65% of exploited edge flaws met GTIG's High/Critical threat risk ratings, with adversaries "aggressively targeting unauthenticated public management interfaces" to take advantage of EDR blind spots on those devices.
AI as the hunter
GTIG says public data significantly undercounts AI-discovered vulnerabilities. CVE records have no standard tag for AI attribution, cloud and SaaS providers often fix AI-surfaced bugs in production without requesting CVEs, and many findings are still under coordinated-disclosure embargo. GTIG instead identifies likely AI-discovered bugs from confirmed disclosures by frontier AI research programmes and from advisories that explicitly credit autonomous agents (it names Hacktron AI and AISLE as examples).
Among those bugs, the risk profile is different. AI-discovered vulnerabilities were 39% Low, 58% Medium and 4% High risk, against 69%, 28% and 3% for everything else. Exactly half of them lead to RCE, compared with 26% across the ecosystem. They also show up at less than half the rate in Information Disclosure (8% vs 18%) and Data Manipulation (5% vs 9%). GTIG attributes this mostly to how programmes point agents at critical code and privilege boundaries, where they excel at memory corruption and logic bypasses that static analysers miss.
The report's main real-world example is CVE-2026-1731, an unauthenticated OS command injection in BeyondTrust Privileged Remote Access and Remote Support that Hacktron AI found autonomously. Within four days of disclosure GTIG saw one threat cluster exploiting it, and five more within seven days. Post-exploitation activity included privilege escalation, data exfiltration, and deployment of SNOWLIGHT, SPARKRAT and cryptominers. CISA added CVE-2026-1731 to its KEV catalog on 13 February 2026. GTIG calls exploitation of AI-discovered flaws "an early indicator rather than an established trend."
AI as the hunted: the AI/LLM stack
GTIG tracked 2,076 AI-related CVEs from January 2025 to August 2026, more than 1,500 of them in 2026. Its 2026 breakdown by layer:
| AI stack layer | Example technologies (per GTIG) | 2026 CVEs |
|---|---|---|
| AI orchestration & agent frameworks | Flowise, Langflow, LangChain, Dify, LlamaIndex, AutoGen, CrewAI, MCP | 782 |
| AI web apps & portals | Open-WebUI, AnythingLLM, LibreChat, RAGFlow, Gradio | 230 |
| Inference & serving infrastructure | vLLM, Ollama, LiteLLM, llama.cpp, Triton, Ray | 212 |
| Model security advisories | Weights, system prompts, guardrails, evaluators | 106 |
| ML frameworks & hubs | PyTorch, Hugging Face, Transformers, ONNX Runtime | 99 |
| Frontier models | Anthropic, Gemini, OpenAI | 97 |
| MLOps & experiment tracking | MLflow, ClearML, W&B, Kubeflow, Langfuse | 39 |
| Vector databases & search | Milvus, Qdrant, ChromaDB, Weaviate | 19 |
GTIG says orchestration middleware accounts for 50% of AI-related flaws and saw a 347% surge in disclosures in 2026. Visual workflow builders and autonomous frameworks expose dynamic code-execution nodes, which attackers reach through prompt injection or crafted workflow JSON. In serving infrastructure, nearly a quarter (24%) of the 212 flaws stem directly from unauthenticated API endpoints or SSRF. GTIG describes enterprise AI gateways as a "dual-threat vector": they expose third-party API keys and sensitive prompt streams, and they also give attackers a foothold for harvesting database credentials and moving laterally into cloud environments.
GTIG has not yet observed zero-day exploitation of AI infrastructure, and only a handful of the 2,076 CVEs are confirmed exploited. It names three it rates High threat risk: CVE-2026-42271 in LiteLLM (command injection in the MCP test endpoint POST /mcp-rest/test/connection), CVE-2026-5027 in Langflow (path traversal file write via POST /api/v2/files) and CVE-2025-3248 in Langflow (unauthenticated code injection via exec() in /api/v1/validate/code). We previously covered the LiteLLM exploitation and the Langflow campaigns.
Findings at a glance
| Metric | 2025 | Jan–Aug 2026 |
|---|---|---|
| Exploited vulnerabilities (distinct) | 127 (full year) | 141 |
| Average exploited per month | 10.5 | 18 |
| Average zero-days exploited per month | 8 | 11 (22 in August) |
| Exploited High-Risk vulnerabilities | 28 | 75 |
| Monthly CVE disclosures | — | 5,045 (Jan) → 10,740 (Aug) |
| High-Risk disclosures per month | ~65 (mid-2025) | 131 (Jan) → 350 (Aug) |
| Share of 2026 disclosures exploited | — | 0.23% (~1 in 431) |
| AI-discovered bugs leading to RCE | 50% vs 26% ecosystem-wide (Jan–Aug 2026) | |
| AI-stack CVEs tracked | 2,076 cumulative (Jan 2025–Aug 2026); over 1,500 in 2026 | |
What it means for defenders
Three practical conclusions follow from GTIG's data. First, the CVE count is now too large to patch by volume. With more than 10,000 disclosures a month and only about 1 in 431 exploited, ranking by exploitation evidence and exposure matters more than ranking by count. Second, the time between disclosure and exploitation is the real battleground. GTIG's BeyondTrust example went from disclosure to six exploiting clusters within a week, and it attributes the 2026 growth mainly to n-days, so patch speed on internet-facing systems matters more than zero-day hunting. Third, AI infrastructure is now part of the perimeter. Orchestration frameworks and gateways such as Langflow and LiteLLM are already being exploited, and they hold keys to everything else.
GTIG also points to its own earlier tracking. Its May AI Threat Tracker reported the first known case of a threat actor holding a zero-day exploit script developed with generative AI, intercepted before use. Its September tracker described actors prototyping agentic vulnerability-discovery tooling. GTIG expects discovery and exploitation rates to keep rising in the short to medium term.
Defender checklist
- Move to threat-intelligence-driven triage. Rank remediation by in-the-wild exploitation (KEV and vendor intelligence), internet exposure and GTIG-style risk, not by CVSS or raw count.
- Shorten n-day windows on the edge. Treat edge and security appliances and directory/collaboration hubs, which together account for a quarter of 2026 exploitation, as days-not-weeks patch targets. Remove public exposure of management interfaces.
- Inventory your AI stack. Find every orchestration framework, inference server, AI gateway and MLOps tool, including shadow deployments. Patch them with the same urgency as edge devices.
- Sandbox agentic workloads. GTIG calls for containment and sandboxing of autonomous agents. Isolate code-execution nodes, restrict egress and keep provider keys out of agent-reachable environments.
- Use AI on the defensive side. GTIG and Mandiant recommend AI-assisted vulnerability management to keep up with compressed timelines. Software vendors should run AI-enhanced code review before release.
- Watch AI-credited advisories closely. Given the 50% RCE rate, advisories crediting autonomous research agents deserve faster review.



