← Back to news
SecurityWeek30 Sept 2026 · 2 min read

Google Report Says AI Is Reshaping Vulnerability Discovery and Exploitation

Google Threat Intelligence Group (GTIG) says artificial intelligence is affecting both the volume of reported software flaws and the characteristics of vulnerabilities being found.In a review of vulne...

Google Threat Intelligence Group (GTIG) says artificial intelligence is affecting both the volume of reported software flaws and the characteristics of vulnerabilities being found.

In a review of vulnerability disclosures from January 2025 through August 2026, GTIG reported that monthly CVE disclosures increased from 5,045 in January 2026 to 10,477 in July, before reaching 10,740 in August. The group cautioned that disclosure totals alone do not necessarily indicate a corresponding increase in meaningful security risk, since automated CVE assignment, particularly in open-source projects, can inflate the figures.

For example, disclosures mentioning the Linux kernel accounted for about 5,000 CVEs during the first eight months of 2026, GTIG said, without observed zero-day exploitation of those issues in the wild.

GTIG identified 141 distinct vulnerabilities exploited in attacks during the first eight months of 2026, exceeding the 127 recorded across all of 2025. The monthly average rose to approximately 18 exploited vulnerabilities, compared with 10.5 last year. Even so, the group said only about 0.23% of vulnerabilities disclosed in 2026 had confirmed in-the-wild exploitation.

Zero-day activity increased more modestly, from an average of eight cases per month in 2025 to 11 per month in 2026. GTIG assessed that the broader increase in exploitation was driven largely by known, previously disclosed vulnerabilities, sometimes called n-days.

The report suggested that attackers may be using large language models and related tools to speed analysis of patches, version differences, advisories and proof-of-concept exploit code, allowing them to weaponize public flaws more quickly.

AI-found flaws show different risk profile

Vulnerabilities GTIG classified as likely AI-discovered were more frequently assessed as medium or high impact than conventional findings. Half of those AI-discovered flaws could lead to remote code execution, compared with 26% of non-AI findings.

GTIG attributed the difference in part to AI-assisted research programs targeting sensitive privilege boundaries and critical systems. It also said AI models may help identify memory-safety and logic errors that conventional static-analysis tools can miss.

  • GTIG confirmed exploitation of some AI-discovered vulnerabilities.
  • One cited example was CVE-2026-1731, a command-injection issue in BeyondTrust products reportedly found by an autonomous research agent.
  • More than 1,500 AI-related CVEs were recorded in 2026 through August, many involving AI orchestration frameworks.

GTIG expects vulnerability discovery and exploitation rates to continue rising in the near term, while noting that exploitation of AI infrastructure itself remains limited and that it has not observed zero-day attacks targeting such infrastructure.

Share this article:TwitterLinkedIn