Breaking
SecurityDeveloping Story

AI-Discovered Flaws Skew Toward RCE

Google's threat intelligence unit reports AI-found vulnerabilities are far more likely to enable remote code execution than other disclosed flaws.

··2 hours ago·4 min read
turned on gray laptop computer
Photo by Luca Bravo on Unsplash

Vulnerabilities surfaced with the help of artificial intelligence are disproportionately likely to end in remote code execution, according to new research from Google's Threat Intelligence Group. The finding, published September 30, examines both how flaws are being found and how quickly they are being turned against targets, drawing on Google's own tracking of vulnerability disclosures and exploitation trends.

An RCE Skew in the Data

GTIG reported that 50% of the vulnerabilities it identified as likely AI-discovered resulted in remote code execution, compared with 26% of other CVEs. That split sits at the center of the group's research into how AI-assisted discovery differs from conventional methods.

The company also noted that public vulnerability data likely undercounts AI-discovered flaws, meaning the true share of AI-assisted discovery could be higher than what is visible in public databases.

Google described confirmed exploitation of AI-discovered vulnerabilities as an early indicator rather than an established trend. The company's researchers describe the risk ratings used in the report as GTIG's own, not standard CVSS scores, a distinction worth keeping in mind when comparing the figures with public databases.

Disclosures and Attacks Both Climb

GTIG's figures show vulnerability disclosures doubling from 5045 in January 2026 to 10,477 in July, before reaching 10,740 in August. Exploited vulnerabilities rose from an average of 10.5 a month in 2025 to 18 a month so far in 2026.

Zero-day exploitation rose only marginally, from eight to 11 a month, though it jumped to 22 in August. GTIG suggested most of the growth came from the rapid weaponization of n-days, possibly aided by AI tools that analyze patches and proof-of-concept code.

  • 50% of likely AI-discovered vulnerabilities resulted in RCE, versus 26% of other CVEs
  • Disclosures rose from 5045 in January 2026 to 10,477 in July and 10,740 in August
  • Exploited vulnerabilities climbed from 10.5 a month in 2025 to 18 a month in 2026
  • Zero-day exploitation moved from eight to 11 a month, with a jump to 22 in August
  • Edge and security appliances made up 14% of exploited vulnerabilities in 2026

Medium-Risk Findings Dominate

Medium-risk flaws accounted for 58% of likely AI-discovered vulnerabilities between January and August 2026, compared with 28% of those not attributed to AI. Low-risk flaws made up 39% and 69%, respectively.

Google said the distribution likely reflects, in large part, how researchers deploy autonomous agents, pointing them at critical infrastructure rather than running broad scans. In that reading, the shift toward medium-severity findings is a function of where the tools are aimed rather than a statement about the tools' inherent capability.

A Four-Day Exploit Window

As a concrete example, GTIG cited CVE-2026-1731, an unauthenticated command injection flaw in BeyondTrust Privileged Remote Access and Remote Support that Hacktron AI discovered autonomously. One threat cluster exploited it within four days of disclosure, and five more followed within seven days.

That compressed timeline is the pattern the researchers point to: autonomous discovery, followed by rapid operationalization by separate groups. What GTIG is describing is a change in the ratio of how quickly a published flaw becomes an exploited one.

AI Infrastructure Under Scrutiny

GTIG tracked more than 1500 AI-related vulnerabilities disclosed in 2026. Agent orchestration frameworks accounted for 782, while inference and serving infrastructure accounted for 212, nearly a quarter of which involved unauthenticated APIs or server-side request forgery.

Only a handful have been confirmed as exploited, and GTIG has yet to see zero-day exploitation of AI infrastructure. Even so, the concentration of unauthenticated interfaces in serving and orchestration layers is the kind of exposure that tends to draw attention once attackers shift focus.

Perimeter Appliances Absorb the Blows

Exploitation overall remained concentrated at the perimeter: edge and security appliances made up 14% of exploited vulnerabilities in 2026, and over 65% of those edge flaws were rated high or critical risk.

If over 65% of exploited edge vulnerabilities are high or critical, perimeter appliances warrant priority patching regardless of where the discovery came from, since the flaws that are actually being abused cluster there.

The Citrix Warning

The research follows Citrix's fixes for two exploited NetScaler zero-days, one of which GTIG and Mandiant have tracked in active attacks.

"Given the active exploitation, NetScaler customers should prioritize examining their systems for compromise before upgrading/patching," Charles Carmakal, CTO at Mandiant, wrote on LinkedIn on September 27. "Patching alone may not eradicate the threat actor from your environment."

— Charles Carmakal, CTO at Mandiant

The Citrix case illustrates that patching alone may not be enough to remove an actor already inside a network, which is why Carmakal's guidance puts compromise assessment ahead of upgrading.

What the Numbers Mean for Defenders

Taken together, the figures suggest the volume and speed of exploitation are both rising, even as the underlying flaw categories stay familiar. For defenders, the practical implication is that the window between disclosure and attack may narrow for exactly the flaws that receive less urgent attention.

As autonomous discovery tools improve, the interval between finding a flaw and seeing it abused could keep shrinking. If that holds, asset inventory, compromise assessment, and rapid triage do more of the defensive work than the patch itself.

#ai vulnerabilities#remote code execution#google threat intelligence#vulnerability disclosure#zero-day exploitation#beyondtrust

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories