- Google Threat Intelligence Group says vulnerability disclosures rose from 5,045 in January to 10,740 in August. In 8 months, the total number of disclosed and exploited vulnerabilities already exceeds all of 2025
- 141 exploited vulnerabilities have been recorded in the first 8 months of 2026, higher than 2025’s full-year total of 127. The growth mainly stems from attackers speeding up weaponization of already-patched n-day vulnerabilities
- BeyondTrust’s CVE-2026-1731 was automatically discovered by the AI research agent Hacktron AI. Within 4 days of public disclosure, a threat group had already begun attacking, with 5 more groups following within 7 days
On this page
Vulnerability Disclosures Double Within Half a Year
In a report published on Sep 30, Google Threat Intelligence Group (GTIG) said vulnerability disclosures surged from 5,045 in January to over 10,000 in both July and August, hitting a new high of 10,740 in August, according to a report by The Record.
Researchers said AI is ‘measurably changing’ the speed at which vulnerabilities are discovered and exploited, as well as the types and risk profiles of the vulnerabilities themselves. The total number of vulnerabilities disclosed and exploited in the first 8 months of 2026 already exceeds the full-year level of 2025. Among them, 141 vulnerabilities have been confirmed as exploited, higher than last year’s full-year total of 127.
Attackers Use AI to Speed Up Weaponization of Patched Flaws
GTIG said the growth in exploitation activity in 2026 mainly stems from attackers conducting ‘fast, targeted weaponization’ of high-risk vulnerabilities, rather than a surge in new zero-day vulnerabilities (zero-day). Instead, attackers are increasingly skilled at using AI to analyze patch diffs, vulnerability disclosure advisories, and proof-of-concept (PoC) code, allowing them to quickly turn disclosed n-day vulnerabilities into usable weapons.
Kelli Vanderlee, senior analyst at GTIG, said the trend of AI-assisted vulnerability discovery and exploitation is expected to keep growing in the short to medium term. She said AI agents are mainly used to find medium- to high-risk vulnerabilities. If attackers can directly affect the security of target devices and networks without needing to overcome major mitigations, the vulnerability is classified as high-risk, with exploitation expected to be highly reliable and scalable.
BeyondTrust Case Reveals AI Agents’ Ability to Find High-Risk Flaws
GTIG cited CVE-2026-1731 as an example of this trend. According to a CISA advisory, the agency added this OS command injection vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) to its Known Exploited Vulnerabilities (KEV) catalog on Feb 13, 2026, after finding evidence of active exploitation.
GTIG said the vulnerability was automatically discovered by the third-party research agent Hacktron AI. Within just 4 days of public disclosure, GTIG had already observed one threat group beginning to exploit the vulnerability. Within the following 7 days, 5 additional threat groups followed, conducting follow-on activity including privilege escalation, data exfiltration, and deployment of SNOWLIGHT, SPARKRAT, and cryptocurrency mining software. GTIG said this case shows that autonomous research agents, when directed at critical attack surfaces, have a ‘strong ability to discover high-severity vulnerabilities’.
Edge Devices Remain a Key Target as Overall Vulnerability Numbers Keep Climbing
The report said many vulnerability disclosures this year have concentrated among a small number of vendors, including router firmware company Totolink and Oracle. Among vulnerabilities exploited between January and August, 14% involved edge and security devices.
The report echoes data released by CISA last week, which said over 67,000 new CVE identifiers have been issued in 2026 so far, with experts forecasting a full-year total of 96,000. The National Vulnerability Database (NVD) project at the US National Institute of Standards and Technology (NIST) also shows that annual CVE submissions grew 263% between 2020 and 2025, with first-quarter submissions in 2026 up by a third compared with the same period last year.
What to do now
- Confirm that all BeyondTrust Remote Support and Privileged Remote Access systems have the patch for CVE-2026-1731 applied
- Prioritize patching vulnerabilities listed in CISA’s KEV catalog, especially on edge and security devices
- Shorten patch cycles, assuming threat groups may attack within days of public disclosure
- Monitor networks for signs of backdoor tools like SNOWLIGHT and SPARKRAT, and unusual cryptocurrency mining activity
- Assess whether to use AI tools to speed up internal patch verification and diff analysis, to keep pace with attackers’ weaponization speed
FAQ
What is an n-day vulnerability, and how does it differ from a zero-day vulnerability?
An n-day vulnerability is one that already has a patch available and has been publicly disclosed, while a zero-day vulnerability is one exploited before the vendor knows about it and releases a patch. GTIG says the growth in attacks in 2026 mainly comes from attackers speeding up exploitation of n-day vulnerabilities, rather than a surge of new zero-day vulnerabilities.
What is CVE-2026-1731, and is a patch available?
CVE-2026-1731 is an OS command injection vulnerability in BeyondTrust Remote Support and Privileged Remote Access software. The vendor has released a patch, and CISA has added it to its KEV catalog, requiring federal agencies to remediate within a set deadline.
Have these vulnerabilities already been used in attacks?
Yes. GTIG says CVE-2026-1731 was exploited by a threat group within 4 days of public disclosure, with 5 more groups following within 7 days, conducting privilege escalation, data exfiltration, and malware deployment. 141 vulnerabilities have been confirmed as exploited in the first 8 months of 2026.
What role does AI play in this rise in vulnerabilities?
According to GTIG, attackers are using AI and large language models to analyze patch diffs, disclosure advisories, and proof-of-concept code, speeding up the conversion of disclosed vulnerabilities into usable attack tools. At the same time, AI research agents such as Hacktron AI are being used to automatically discover vulnerabilities, including CVE-2026-1731.
Which systems are most commonly targeted?
GTIG’s report says that among vulnerabilities exploited between January and August 2026, 14% involved edge devices and enterprise security appliances, with Totolink and Oracle among the vendors with more disclosed vulnerabilities.



