Skip to content

Executive Summary

Vulnerabilities found via AI are disproportionately likely to enable remote code execution (RCE), with 50% of AI-discovered vulnerabilities resulting in RCE, compared to 26% of other CVEs. Vulnerability disclosures doubled between January 2026 and July 2026, reaching 10,477 disclosures in July and 10,740 in August. Exploited vulnerabilities rose from an average of 10.5 per month in 2025 to 18 per month in 2026. The growth in exploitation was largely attributed to the rapid weaponization of n-days, potentially aided by AI tools analyzing patches and proof-of-concept code. Medium-risk flaws accounted for 58% of likely AI-discovered vulnerabilities between January and August 2026. This distribution is suggested to reflect how researchers deploy autonomous agents targeting critical infrastructure rather than broad scans. A specific example cited is CVE-2026-1731, an unauthenticated command injection flaw found autonomously by Hacktron AI, which was exploited within four days of disclosure and led to five further exploits within seven days. Risk concentration in exploitation occurred at the perimeter, where edge and security appliances accounted for 14% of exploited vulnerabilities in 2026, with over 65% of those edge flaws being rated high or critical risk.

Facts Only

* 50% of vulnerabilities likely discovered by AI resulted in Remote Code Execution (RCE), compared to 26% of other CVEs.
* Vulnerability disclosures doubled from 5,045 in January 2026 to 10,477 in July and 10,740 in August 2026.
* Exploited vulnerabilities rose from an average of 10.5 per month in 2025 to 18 per month so far in 2026.
* Zero-day exploitation increased from eight to 11 per month, jumping to 22 in August.
* Most growth in exploitation is suggested to come from the rapid weaponization of n-days via AI tools analyzing patches and proof-of-concept code.
* Medium-risk flaws accounted for 58% of likely AI-discovered vulnerabilities between January and August 2026, compared to 28% of non-AI attributed CVEs.
* Confirmed exploitation occurred for CVE-2026-1731, an unauthenticated command injection flaw in BeyondTrust Privileged Remote Access and Remote Support, within four days of disclosure.
* Agent orchestration frameworks accounted for 782 AI-related vulnerabilities disclosed in 2026.
* Edge and security appliances made up 14% of exploited vulnerabilities in 2026.

Full Take

The narrative reveals a critical shift where the capacity for automated discovery is directly translating into higher-impact exploitation, specifically concerning remote code execution. The disproportionate success rate suggests that the velocity introduced by AI in the vulnerability lifecycle—from discovery to weaponization—outpaces traditional defensive and patching cycles. The focus on autonomous agents targeting infrastructure implies that risk concentration is not random but strategically focused, as evidenced by the concentration of exploited flaws at perimeter edge devices. This structure moves the threat landscape away from broad scanning and toward specific, high-value targets managed via orchestration frameworks. The implication for agency is that the speed advantage gained through AI creation must be countered by commensurate increases in defensive automation; if agents can weaponize n-days rapidly, traditional reactive patching will become obsolete before mitigation can be applied. The question is whether defensive postures designed for human-paced discovery are sufficient to manage machine-paced exploitation. What systems of accountability must evolve when the mechanism of risk generation becomes increasingly opaque and autonomous?

From the original · InfoSecurity Magazine

Vulnerabilities found with the help of AI are disproportionately likely to enable remote code execution (RCE), as disclosures and exploitation both accelerated in 2026. In research published September 30, Google Threat Intelligence Group (GTIG) found that 50% of vulnerabilities it identified as likely AI-discovered resulted in RCE, against 26% of other CVEs.
Read the full story at infosecurity-magazine.com

Sentinel — Human

Confidence

The text reads like a compilation of specific technical research findings, structured around statistics and case examples, suggesting it is either based directly on primary source reporting or expertly synthesized from such sources.

Signals Detected
low severity: Sentence length variance is moderate; prose flows logically but exhibits technical density.
low severity: The text maintains a consistent, analytical tone focused on data presentation rather than emotional appeal. The claims flow logically from statistics to implications.
low severity: The structure is highly dense with cited figures and specific examples (CVEs, dates), suggesting adherence to a structured research summary rather than general narrative.
low severity: Specific citation of the GTIG findings, CVE numbers, and specific dates suggests grounding in a real data set, though this requires external verification against the cited source.
Human Indicators
The inclusion of a direct, attributable quote from an industry expert (Charles Carmakal) on LinkedIn adds a layer of potential human sourcing beyond pure statistical regurgitation.
AI-Found Vulnerabilities More Likely to Enable RCE, Google Says | Huntaegis