Google Threat Intelligence Group (GTIG) reported that vulnerability disclosures and observed exploitation both accelerated in 2026, while vulnerabilities it classified as likely discovered with AI had a higher share of remote-code-execution flaws than other vulnerabilities. Those findings do not show that AI caused every increase—or that most disclosed flaws were being exploited. They are based on GTIG analysis summarized by SecurityWeek, not an independently reviewed GTIG report or methodology.
What GTIG reported about vulnerability disclosures
In an analysis covering January 2025 through August 2026, GTIG counted 5,045 vulnerability disclosures in January 2026 and 10,740 in August. The same report, as summarized by SecurityWeek on September 30, 2026, counted 131 high-risk disclosures in January and 350 in August—a reported increase of 167%. GTIG’s high-risk label is its own rating, not a CVSS score.
The raw totals need context. Automated CVE assignment in some open-source ecosystems can increase disclosure counts without demonstrating a matching rise in distinct, exploitable danger. SecurityWeek’s account cites roughly 5,000 Linux-kernel CVEs from January through August 2026 and says GTIG observed no in-the-wild zero-day exploitation for that set. A CVE count alone therefore cannot tell an organization how many flaws affect its systems, how severe they are in context, or whether attackers are exploiting them.
Observed exploitation rose, but most 2026 disclosures had not been seen exploited
GTIG recorded 141 distinct vulnerabilities exploited in the wild from January through August 2026, compared with 127 across all of 2025. The reported monthly averages were 18 and 10.5, respectively. At the same time, only 0.23% of vulnerabilities disclosed in 2026 had been observed exploited, according to GTIG as reported by SecurityWeek. That is a period-wide observation, not a guarantee that any particular unexploited vulnerability is safe or low risk.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute#1 Best Overall
GTIG’s account distinguishes zero-day exploitation—attacks before a vulnerability is publicly disclosed or patched—from attacks on n-day flaws, which are already known. It reported an average of eight zero-day vulnerabilities exploited per month in 2025 and 11 per month in 2026, with 22 in August. Zero-days made up 62% of vulnerabilities exploited from January through August 2026. GTIG suggested that increased n-day exploitation may account for much of the overall growth, potentially because attackers can use AI tools to analyze patches, product-version differences, disclosure notices, and proof-of-concept code. That is a proposed explanation, not proof of a causal mechanism.
What the AI-discovered vulnerability comparison does—and does not—show
GTIG compared vulnerabilities it classified as likely AI-discovered with those it did not classify that way. In the first group, 50% enabled remote code execution; in the other group, 26% did. Remote code execution can let an attacker run code on a vulnerable system, making it a consequential flaw type. The difference is a reported comparison between classified groups, however, not evidence that AI alone caused the vulnerability characteristics.
The SecurityWeek coverage also compares the groups using GTIG’s low-, medium-, and high-risk categories and observed exploitation status, but does not provide enough detail about the classification method to independently evaluate how cases were assigned. These labels should not be treated as a universal scoring system or a prediction that a particular AI-discovered flaw will be exploited.
GTIG reportedly said AI models can identify memory-corruption and logic flaws that traditional static analyzers may miss. The available account does not establish a controlled causal study of AI versus non-AI discovery, so it supports describing an observed profile difference—not claiming that AI discovery makes vulnerabilities inherently more dangerous.
Rank #3
A rapid exploitation example: CVE-2026-1731
One reported case illustrates why disclosure timing matters. CVE-2026-1731 was an unauthenticated OS command-injection vulnerability in BeyondTrust Privileged Remote Access and Remote Support, reportedly discovered autonomously by the Hacktron AI research agent. GTIG said one threat cluster exploited it within four days of public disclosure, with five more following within seven days, as summarized by SecurityWeek.
This example is evidence of rapid exploitation of a particular disclosed flaw; it does not establish that all AI-discovered vulnerabilities are exploited at the same speed. It also underscores that attackers may move quickly once a vulnerability and usable technical details become public.
Rank #4
Vulnerabilities in AI systems are a separate category
GTIG separately tracked 2,076 AI-related CVEs from January 2025 through August 2026, including more than 1,500 in 2026; roughly half affected AI orchestration frameworks, according to SecurityWeek’s account. GTIG reportedly found only a handful confirmed exploited and no observed zero-day exploitation of AI infrastructure during that period.
These are vulnerabilities in AI-related products or infrastructure. They should not be conflated with vulnerabilities discovered using AI: the first describes what software is affected, while the second describes a possible discovery method.
Best Value
What security teams should do with the findings
The practical response is to prioritize the exposure and evidence for each flaw rather than react to disclosure totals alone. Keep inventories current, identify whether affected software is actually deployed and reachable, monitor disclosures for those products, and use evidence of exploitation to inform patch urgency. A short gap between public disclosure and attacks—as reported for CVE-2026-1731—makes timely triage especially important, but does not replace an organization-specific assessment of impact and exposure.
GTIG expects vulnerability discovery and exploitation rates to keep rising in the short to medium term, as quoted by SecurityWeek. That is a forecast, not an observed result or a timetable for any particular organization.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

