Vulnerability disclosures doubled in 2026, with exploitation following suit, as AI is finding more impactful vulnerabilities.
This is according to Google Threat Intelligence Group’s (GTIG) newest blog discussing vulernability exploitation in the AI era.
While zero-day exploits have only increased marginally, overall vulernability exploitation nearly doubled, increasing from an average of 10.5 per month in 2025 to an average of 18 per month from January 2026 to August 2026.
GTIG researchers say that the likely source of the exploitation growth was through the weaponisation of n-day vulnerabilities, specifically geared towards those that are high-risk.
As far as attack surfaces go, edge gateways emerage as a premier initial access vector, with over 65% of these atacks meeting high or ciritical threat risk ratings. Threat actors regularly targeted unauthenticated public management interafaces to exploit EDR agent blindspots.
Meanwhile, appliances represented 14% of vulnerabiliites, while 11% were via enterprise directory and collaboration hubs.
AI-Assiseted Vulnerability Discovery
While GTIG admits that the current available data will undercount the number of vulnerbailities discovered by AI, it has been able to do so in some cases through verified lab and vendor ledgers, as well as through advisory and release analysis.
The resesarchers found that AI-discovered vulnerabilities were more likely to qualify as a higher threat risk than conventional CVE disclosures. 69% of conventional vulnerbaility disclosures were rated low risk, while 28% were rated medium. Inversely, 58% of AI-discovered vulnerabilities were rated medium, while low risk findings amounted to 39%.
These results likely reveal how AI agents are being used to find and exploit vulnerabilities – rather than being used for broad-range automated scans for flaws, AI agents are being prompted with more specific tasks to focus on high-impact vulnerabilities.
This is translating into execution: 50% of vulnerabiliites discovered by AI resulted in remote code execution, compared to the 26% average for the entire CVE ecosystem.
However, AI seems to perform works in lower-impact categories, such as information disculosure and data manipulation.
“While currently an early indicator rather than an established trend, confirmed exploitation of AI-discovered vulnerabilities demonstrates that increased risk from AI-discovered flaws is not purely theoretical,” the GTIG blog post said.





