- Google Threat Intelligence Group (GTIG) reported that monthly vulnerability disclosures rose from 5,045 in January 2026 to 10,477 in July, then climbed further to a peak of 10,740 in August
- Among AI-discovered vulnerabilities, 50% can lead to remote code execution, far above the 26% rate for non-AI finds, reflecting AI’s skill at spotting memory corruption and logic flaws that traditional static analysis tools miss
- GTIG recorded 141 vulnerabilities exploited in the wild in the first eight months of 2026, already surpassing the 127 recorded for all of 2025. Zero-day flaws accounted for 62% of these, showing attackers are weaponising disclosed (n-day) vulnerabilities faster
On this page
Monthly disclosures nearly double
According to a report published by Google Threat Intelligence Group (GTIG) on Sep 30, analysis of disclosure data from January 2025 to August 2026 found that monthly vulnerability disclosures jumped from 5,045 in January 2026 to 10,477 in July, then rose further to a peak of 10,740 in August.
GTIG cautioned that raw disclosure numbers alone can be misleading, since automated CVE Numbering Authority (CNA) assignment policies in open-source ecosystems can inflate the base figures. For example, vulnerabilities merely referencing ‘Linux Kernel’ in their descriptions generated roughly 5,000 CVE entries between January and August 2026 alone, yet none of these was observed being exploited as a zero-day in the wild.
The report also found that disclosures of GTIG’s own ‘High Risk’ rating (distinct from CVSS scores) grew the most, rising from 131 in January to 350 in August, an increase of 167%. This growth in high-risk disclosures was driven largely by TOTOLINK router firmware research disclosures and vendor disclosure cycles such as Oracle’s quarterly Critical Patch Update (CPU).
In-the-wild exploitation nearly doubles too
The report showed that GTIG recorded 141 distinct vulnerabilities exploited in the wild between January and August 2026, already exceeding the 127 recorded for all of 2025. The average number of vulnerabilities exploited in the wild per month rose from 10.5 in 2025 to 18 in 2026.
However, GTIG stressed that the proportion of disclosed vulnerabilities that end up being exploited remains extremely low. In 2026, only 0.23% of disclosed vulnerabilities (about 1 in 431) were observed being actively exploited. Zero-day exploitation rose only modestly, from an average of 8 per month in 2025 to 11 per month in 2026, though it spiked to 22 in August alone. Zero-days accounted for 62% of all exploited vulnerabilities in the first eight months of this year.
GTIG said exploitation of high-risk vulnerabilities rose from 28 in 2025 to 75 in the first eight months of 2026, more than doubling. The group suggested threat actors may increasingly be using large language models to automatically analyse version differences, patches and proof-of-concept code, speeding up the weaponisation of disclosed (n-day) vulnerabilities rather than investing resources in discovering entirely new zero-days.
AI-discovered vulnerabilities show a distinct risk profile
Citing the GTIG report, SecurityWeek noted that among AI-discovered vulnerabilities, only 39% were rated low risk and 58% medium risk, compared with 69% and 28% respectively for non-AI finds. GTIG said this may reflect a tendency for research programmes deploying AI agents to audit critical infrastructure and sensitive privilege boundaries, focusing on higher-impact findings.
The report also found that 50% of AI-discovered vulnerabilities can lead to remote code execution, far above the 26% rate for non-AI finds. GTIG attributed this to AI models’ ability to identify memory corruption and logic flaws that traditional static analysis tools miss.
The report cited a real-world example: CVE-2026-1731, an unauthenticated OS command injection vulnerability in BeyondTrust Privileged Remote Access and Remote Support, was discovered automatically by the Hacktron AI research agent. According to SecurityWeek, one threat group exploited the flaw within four days of public disclosure, with five more groups following suit within the next seven days.
Vulnerabilities in AI infrastructure itself also rising
The report found that GTIG tracked 2,076 AI-related CVE entries between January 2025 and August 2026, with more than 1,500 of these appearing in 2026 alone. About half affected AI orchestration frameworks. Of these 2,076 vulnerabilities, only a small number have been confirmed as exploited in the wild, including flaws in LiteLLM and Langflow. GTIG said it has not yet observed zero-day exploitation of AI infrastructure.
GTIG expects the pace of vulnerability discovery and exploitation to keep rising in the short to medium term. It recommends enterprises shift from unprioritised mass patching to threat-intelligence-led triage, combined with targeted edge defences and automated agentic remediation.
What to do now
- Establish a threat-intelligence-led vulnerability triage process, prioritising GTIG’s high-risk-rated and confirmed-exploited vulnerabilities over blanket mass patching
- Strengthen monitoring of edge devices and security appliances (such as VPNs and firewall management interfaces), which the report says accounted for 14% of exploited vulnerabilities this year
- Review whether AI orchestration frameworks in use (such as LiteLLM and Langflow) have known vulnerabilities that need patching
- Stay highly alert to disclosed (n-day) vulnerabilities, as the report shows threat actors are weaponising n-days faster rather than focusing solely on new zero-days
- Assess high-risk vulnerabilities found by internal AI agent auditing tools, prioritising flaws that can lead to remote code execution
FAQ
What is the ‘High Risk’ vulnerability rating mentioned in the GTIG report?
GTIG uses its own custom vulnerability risk rating, separate from the CVSS scoring system, to assess the real-world threat level of a flaw. The report shows disclosures of High Risk vulnerabilities rose from 131 in January to 350 in August, an increase of 167%.
Are AI-discovered vulnerabilities really more dangerous?
According to the GTIG report, 50% of AI-discovered vulnerabilities can lead to remote code execution, far above the 26% rate for non-AI finds. AI-discovered vulnerabilities also have a lower share rated low risk (39% versus 69%). GTIG attributes this to AI agents being used to audit critical systems.
Does the rise in disclosures mean attack risk has risen just as much?
Not entirely. GTIG notes that in 2026, only 0.23% of disclosed vulnerabilities (about 1 in 431) were observed being exploited in the wild. Part of the growth in disclosure numbers stems from automated CVE assignment in open-source ecosystems, which inflates the base figures.
What is remote code execution (RCE)?
Remote code execution refers to an attacker’s ability to run arbitrary code on a target system over a network, without physical access or local privileges. It is one of the most severe outcomes of a vulnerability exploit. See [remote code execution](/glossary#remote-code-execution) for details.
What is CVE-2026-1731?
CVE-2026-1731 is an unauthenticated OS command injection vulnerability in BeyondTrust Privileged Remote Access and Remote Support. It was discovered automatically by the Hacktron AI research agent and was exploited by a threat group within four days of public disclosure.



