AI-Driven Surge in Vulnerability Disclosures and Exploitation in 2026, Google Report Finds
A new report from Google’s Threat Intelligence Group (GTIG) reveals a sharp rise in cybersecurity vulnerabilities and their exploitation in 2026, driven in part by the growing role of AI. Analyzing data from January 2025 to August 2026, GTIG found that monthly vulnerability disclosures nearly doubled from 5,045 in January 2026 to a peak of 10,740 in August while the average number of exploited vulnerabilities per month rose from 10.5 in 2025 to 18 in 2026.
Despite the surge in disclosures, only 0.23% of vulnerabilities were exploited in the wild, with zero-days accounting for 62% of those attacks. However, exploitation of n-days known vulnerabilities with available patches drove much of the increase, more than doubling from 28 in 2025 to 75 in the first eight months of 2026. GTIG suggests that threat actors may be leveraging AI tools to automate the weaponization of n-days by analyzing patches, disclosures, and proof-of-concept code, rather than investing in zero-day discovery.
AI is also reshaping the types of vulnerabilities being uncovered. Of the flaws likely discovered by AI, 39% were rated low-risk and 58% medium-risk, compared to 69% low-risk and 28% medium-risk for non-AI vulnerabilities. Notably, half of AI-discovered vulnerabilities enable remote code execution (RCE), compared to 26% of non-AI flaws, likely due to AI’s ability to detect memory corruption and logic flaws missed by traditional tools.
One example is CVE-2026-1731, an unauthenticated OS command injection flaw in BeyondTrust’s Privileged Remote Access, autonomously discovered by the Hacktron AI research agent. The vulnerability was exploited within four days of disclosure, with six threat clusters targeting it within a week.
The report also highlights a rise in vulnerabilities within AI systems themselves, with 2,076 AI-related CVEs logged between January 2025 and August 2026 over 1,500 of them in 2026 alone. While most affect AI orchestration frameworks, only a few, including flaws in LiteLLM and Langflow, have been confirmed as exploited.
GTIG warns that the trend of increasing vulnerability discovery and exploitation is likely to continue in the near term, with AI playing a growing role in both offensive and defensive cybersecurity efforts.
Source: https://www.securityweek.com/google-ai-is-changing-the-pace-and-profile-of-vulnerability-discovery/
BeyondTrust cybersecurity rating report: https://www.rankiteo.com/company/beyondtrust
"id": "BEY1790785539",
"linkid": "beyondtrust",
"type": "Vulnerability",
"date": "1/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Cybersecurity',
'name': 'BeyondTrust',
'type': 'Company'},
{'industry': 'Technology',
'name': 'LiteLLM',
'type': 'AI Framework'},
{'industry': 'Technology',
'name': 'Langflow',
'type': 'AI Framework'}],
'attack_vector': ['Remote Code Execution (RCE)',
'OS Command Injection',
'Memory Corruption',
'Logic Flaws'],
'date_detected': '2026-08-01',
'date_publicly_disclosed': '2026-08-01',
'description': 'A new report from Google’s Threat Intelligence Group (GTIG) '
'reveals a sharp rise in cybersecurity vulnerabilities and '
'their exploitation in 2026, driven by the growing role of AI. '
'Monthly vulnerability disclosures nearly doubled from 5,045 '
'in January 2026 to 10,740 in August, while exploited '
'vulnerabilities per month rose from 10.5 in 2025 to 18 in '
'2026. Threat actors leveraged AI to automate the '
'weaponization of n-days vulnerabilities, with exploitation of '
'known vulnerabilities more than doubling. AI also reshaped '
'the types of vulnerabilities discovered, with 39% rated '
'low-risk and 58% medium-risk, and half enabling remote code '
'execution (RCE).',
'impact': {'operational_impact': 'Increased exploitation of known '
'vulnerabilities',
'systems_affected': ['Privileged Remote Access (BeyondTrust)',
'AI Orchestration Frameworks']},
'investigation_status': 'Ongoing',
'lessons_learned': 'AI is increasingly used to automate vulnerability '
'discovery and exploitation, particularly for n-days '
'vulnerabilities. Organizations must prioritize patch '
'management and enhance defensive AI capabilities to '
'counter automated threats.',
'motivation': ['Automated Exploitation via AI',
'Financial Gain',
'Data Exfiltration'],
'post_incident_analysis': {'corrective_actions': ['Accelerate patch '
'deployment for critical '
'vulnerabilities',
'Deploy AI-based defensive '
'tools to counter automated '
'threats',
'Enhance monitoring of AI '
'orchestration frameworks'],
'root_causes': ['AI-driven automation of '
'vulnerability discovery and '
'exploitation',
'Delayed patching of known '
'vulnerabilities (n-days)',
'Increased focus on memory '
'corruption and logic flaws by AI '
'tools']},
'recommendations': ['Prioritize patch management for known vulnerabilities',
'Enhance AI-driven defensive tools to detect and mitigate '
'automated exploitation',
'Monitor AI-related vulnerabilities in orchestration '
'frameworks',
'Improve threat intelligence sharing on AI-discovered '
'vulnerabilities'],
'references': [{'date_accessed': '2026-08-01',
'source': 'Google’s Threat Intelligence Group (GTIG) Report'}],
'threat_actor': ['Multiple Threat Clusters'],
'title': 'AI-Driven Surge in Vulnerability Disclosures and Exploitation in '
'2026',
'type': ['Vulnerability Disclosure', 'Exploitation'],
'vulnerability_exploited': ['CVE-2026-1731',
'LiteLLM Flaws',
'Langflow Flaws']}