Half of the vulnerabilities credited to AI discovery lead to remote code execution, against about a quarter across the wider CVE ecosystem. That is one of the sharper findings in a new study by Google Threat Intelligence Group researchers Robin Grunewald, Supriya Mazumdar and Kelli Vanderlee, which measures how AI is changing both the pace and the shape of vulnerability discovery and exploitation.
The headline numbers are stark. Monthly vulnerability disclosures doubled from 5,045 in January 2026 to 10,477 in July, and reached 10,740 in August. GTIG recorded 141 distinct vulnerabilities exploited in the wild between January and August 2026, already more than the 127 it counted for all of 2025, lifting the monthly average from 10.5 to 18.
More CVEs, but not proportionally more danger
GTIG warns that raw volume misleads. Automated numbering policies in open-source ecosystems inflate the count: vulnerabilities describing the Linux kernel alone produced about 5,000 CVEs this year with zero observed in-the-wild zero-days. Only 0.23% of vulnerabilities disclosed in 2026, roughly 1 in 431, were ever seen exploited, and since May exploitation growth (+127% indexed) has tracked disclosure growth (+128%) rather than outpacing it.
Zero-days rose only modestly, from an average of 8 a month in 2025 to 11 in 2026, although August jumped to 22. GTIG therefore suggests that most of the growth comes from rapid weaponization of n-days, bugs that are already public. It raises, without claiming proof, the possibility that attackers are using LLMs to pick apart patches, advisories and proof-of-concept code faster. Exploitation of flaws GTIG rates High-Risk (its own scale, not CVSS) more than doubled, from 28 in 2025 to 75 so far in 2026.
AI hunters go after the bugs that matter
Among disclosures GTIG could identify as likely AI-discovered, 58% were Medium-Risk and 39% Low-Risk, nearly inverting the 69% Low and 28% Medium split for everything else. GTIG attributes that largely to how research programs task their agents, pointing them at critical code and privilege boundaries rather than broad scans. It also cautions that public data undercounts AI discoveries, since CVE records carry no AI-attribution field.
The risk is not theoretical. CVE-2026-1731, a command injection flaw in BeyondTrust Privileged Remote Access and Remote Support found autonomously by Hacktron AI's research agent, was exploited by one threat cluster within four days of disclosure and by five more within seven days, with follow-on payloads including SNOWLIGHT, SPARKRAT and cryptominers. AI-driven bug hunting has turned up in our coverage before, as when an AI agent chained six bugs into a WordPress takeover.
The AI stack is now a target
GTIG tracked 2,076 AI-related CVEs since January 2025, more than 1,500 of them in 2026. Orchestration and agent frameworks such as Flowise, Langflow and LangChain account for half, with disclosures up 347% this year. No zero-day exploitation of AI infrastructure has been seen yet, but a handful of newly disclosed flaws have been exploited, and GTIG rates all three it names as High Threat Risk: CVE-2026-42271 in LiteLLM, CVE-2026-5027 in Langflow and CVE-2025-3248 in Langflow. Langflow has featured here before, when attackers hijacked exposed Langflow AI servers to mine cryptocurrency.
Triage by threat, and sandbox the agents
GTIG's advice is to stop mass-patching in disclosure order and move to threat-intelligence-driven triage, with targeted protection of edge devices, and to sandbox autonomous agent workloads. It also urges software vendors to run AI-assisted code review before release; if that becomes standard practice, GTIG argues, the growth in public disclosures could eventually slow.
The data does not show AI unleashing a flood of zero-days. It shows something more pressing: the window between a bug going public and attackers using it keeps shrinking, so the speed of triage now matters more than the volume of patching.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.