Google: AI Is Rewriting Bug Economics
GTIG data shows vulnerability disclosures doubled in 2026 while exploitation shifted toward n-days, with AI-discovered flaws carrying a riskier profile.
A typical month in 2026 now produces roughly twice as many vulnerability disclosures as it did a year earlier, and the average number of flaws being exploited in the wild has nearly doubled alongside them. That is the central finding of a new analysis from Google Threat Intelligence Group (GTIG), which examined disclosure data from January 2025 through August 2026 and concluded that AI is reshaping both how fast bugs surface and what kind of bugs they are.
The shift is not just about volume. GTIG reports that the characteristics of the flaws themselves are changing, with AI-associated discoveries skewing toward higher-impact categories and away from the low-risk backlog that has historically dominated disclosure counts.
Disclosure Volume Doubled in 2026
GTIG's numbers show monthly vulnerability disclosures climbing from 5,045 in January 2026 to 10,477 in July, before peaking at 10,740 in August. That is roughly a doubling over the course of the year, and it forms the backdrop for everything else in the report.
The researchers are careful to note that raw counts can mislead. Automated CVE assignment in open source ecosystems inflates totals, and GTIG flags one specific example: vulnerabilities whose description mentions the Linux kernel alone generated roughly 5,000 CVEs between January and August, with no in-the-wild zero-day exploitation observed for that group.
To work around that noise, GTIG leaned on its own risk ratings rather than CVSS scores. By that measure, high-risk disclosures grew 167%, from 131 in January to 350 in August — a steeper curve than the headline volume figure suggests, because it strips out the automated churn.
Exploitation Is Outpacing 2025 Already
On the exploitation side, GTIG recorded 141 distinct exploited vulnerabilities in the first eight months of 2026, already more than the 127 seen across all of 2025. That works out to an average of 18 per month, up from 10.5 last year.
The share of disclosed bugs that actually get exploited remains small. Only 0.23% of this year's disclosed vulnerabilities — roughly one in 431 — were observed being exploited.
Zero-day activity rose more modestly, from an average of eight per month in 2025 to 11 per month in 2026, though the count jumped to 22 in August. Zero-days accounted for 62% of the vulnerabilities exploited between January and August.
Exploitation of high-risk vulnerabilities more than doubled, from 28 in 2025 to 75 in the first eight months of 2026.
The Pull of n-Days Over Zero-Days
The most consequential shift GTIG identifies is where the growth is coming from. It attributes the rise in exploitation primarily to n-days — flaws that are already known or patched — rather than to newly discovered zero-days.
The report offers a mechanism for that preference, suggesting that large language models and AI tooling may be lowering the cost of turning a known flaw into a working exploit.
“It is possible that threat actors are finding it more accessible or efficient to use LLMs and AI tools to automate analysis of differences between product versions, patches, vulnerability disclosure announcements, and Proof-of-Concept (POC) code to rapidly weaponize n-days, rather than to discover new zero-days,” the report reads.
The underlying finding that AI is changing the pace and profile of vulnerability discovery comes from GTIG's own analysis.
“We found that AI is measurably changing not just the pace of vulnerability discovery and exploitation, but also the types and typical risk profiles of vulnerabilities that are being discovered,” GTIG says.
A Riskier Profile for AI-Found Bugs
Vulnerabilities that GTIG identified as likely discovered by AI between January and August carry a different risk profile from the rest of the pool. Among AI-discovered flaws, 39% were rated low-risk and 58% medium-risk. For non-AI vulnerabilities, those figures were 69% and 28%, respectively.
The severity distribution is more striking still. Half of the AI-discovered vulnerabilities result in remote code execution, compared to 26% of non-AI vulnerabilities. GTIG attributes that gap to AI models' apparent ability to find memory corruption and logic flaws that traditional static analyzers tend to miss.
The organization also suggests the pattern reflects how research programs actually deploy AI agents — tasking them with auditing critical infrastructure and sensitive privilege boundaries, with a focus on higher-impact findings. In other words, the population of AI-discovered bugs may look riskier partly because of where humans point the tools.
An Early Signal, Not a Trend Yet
GTIG says it has confirmed in-the-wild exploitation of AI-discovered vulnerabilities, but describes this as an early indicator rather than an established trend. The report does not claim that AI-discovered flaws are routinely being weaponized at scale.
One documented case is CVE-2026-1731, an unauthenticated OS command injection flaw in BeyondTrust Privileged Remote Access and Remote Support. GTIG says the bug was discovered autonomously by the Hacktron AI research agent. One threat cluster exploited it within four days of public disclosure, and five more followed within seven days.
AI Systems Are Getting Patched Too
Disclosures affecting AI systems themselves are also climbing. GTIG tracked 2,076 AI-related CVEs between January 2025 and August 2026, including more than 1,500 this year. Roughly half of those affect AI orchestration frameworks.
Only a handful of the 2,076 have been confirmed as exploited in the wild, including flaws in LiteLLM and Langflow. GTIG has not yet observed zero-day exploitation of AI infrastructure.
The report's forward-looking assessment is blunt about direction, if not magnitude.
“GTIG expects that rates of vulnerability discovery and exploitation are likely to continue to increase in the short to medium term,” the report reads.
By the Numbers
- Monthly disclosures rose from 5,045 in January 2026 to 10,477 in July, peaking at 10,740 in August.
- High-risk disclosures grew 167%, from 131 in January to 350 in August.
- 141 distinct exploited vulnerabilities were recorded in the first eight months of 2026, versus 127 in all of 2025 — an average of 18 per month, up from 10.5.
- Only 0.23% of 2026's disclosed vulnerabilities, roughly one in 431, were observed being exploited.
- Zero-day exploitation averaged 11 per month in 2026, up from eight per month in 2025, and reached 22 in August.
- Zero-days made up 62% of vulnerabilities exploited between January and August.
- Exploitation of high-risk vulnerabilities rose from 28 in 2025 to 75 in the first eight months of 2026.
- 2,076 AI-related CVEs were tracked from January 2025 through August 2026, including more than 1,500 this year.
What This Means for Defenders
The practical consequence of GTIG's findings lands less on the discovery side than on the patching side. If the growth in exploitation is driven primarily by n-days, then the window that matters most for most organizations is not the gap between a bug's existence and its discovery — it is the gap between a patch shipping and that patch being applied.
The CVE-2026-1731 timeline illustrates the compression. One cluster moved within four days of public disclosure; five more followed within seven. Teams that treat patch cycles in weeks rather than days are, on that evidence, operating inside the exploitation window rather than ahead of it.
The risk profile of AI-discovered bugs also complicates triage. If half of AI-associated findings produce remote code execution, versus roughly a quarter of everything else, then a straight count of open vulnerabilities will understate the danger in a queue that is increasingly AI-sourced. Severity-weighted prioritization matters more than raw backlog size — which is roughly the argument GTIG makes by rating flaws on its own scale rather than relying on CVSS alone.
There is a countervailing note. The share of disclosed vulnerabilities that are ever exploited remains tiny — 0.23% — which means the inflation of disclosure counts does not translate one-for-one into operational risk. Bulk automated CVE issuance, like the roughly 5,000 Linux-kernel-mentioning entries with no observed zero-day exploitation, can make a vulnerability management program look worse than it is.
The most uncertain element is whether AI-assisted discovery will remain a curiosity in exploitation statistics or become a routine source of exploited bugs. GTIG itself calls the confirmed cases an early indicator, not a trend, and has not observed zero-day exploitation of AI infrastructure at all. What it does project — continued increases in both discovery and exploitation rates in the short to medium term — suggests the pressure on patch windows is unlikely to ease on its own.
Sources
- SecurityWeek Original source
- CVE-2026-1731 Also reporting
- Langflow Also reporting
Continue Reading
Cloudflare Vows Quantum-Proof TLS Shift
Cloudflare says it will issue post-quantum TLS certificates using Merkle Tree Certificates, targeting Q1 2027 after acquiring a GlobalSign root.
AI-Discovered Flaws Skew Toward RCE
Google's threat intelligence unit reports AI-found vulnerabilities are far more likely to enable remote code execution than other disclosed flaws.
Teen's Auth Flaw Opened Titan's Data Vault
A 16-year-old researcher bypassed Microsoft's Titan analytics by exploiting an unverified JWT and was paid a $5,000 bounty.