Executive Summary
Facts Only
* 50% of vulnerabilities likely discovered by AI resulted in Remote Code Execution (RCE), compared to 26% of other CVEs.
* Vulnerability disclosures doubled from 5,045 in January 2026 to 10,477 in July and 10,740 in August 2026.
* Exploited vulnerabilities rose from an average of 10.5 per month in 2025 to 18 per month so far in 2026.
* Zero-day exploitation increased from eight to 11 per month, jumping to 22 in August.
* Most growth in exploitation is suggested to come from the rapid weaponization of n-days via AI tools analyzing patches and proof-of-concept code.
* Medium-risk flaws accounted for 58% of likely AI-discovered vulnerabilities between January and August 2026, compared to 28% of non-AI attributed CVEs.
* Confirmed exploitation occurred for CVE-2026-1731, an unauthenticated command injection flaw in BeyondTrust Privileged Remote Access and Remote Support, within four days of disclosure.
* Agent orchestration frameworks accounted for 782 AI-related vulnerabilities disclosed in 2026.
* Edge and security appliances made up 14% of exploited vulnerabilities in 2026.
Full Take
From the original · InfoSecurity Magazine
Vulnerabilities found with the help of AI are disproportionately likely to enable remote code execution (RCE), as disclosures and exploitation both accelerated in 2026. In research published September 30, Google Threat Intelligence Group (GTIG) found that 50% of vulnerabilities it identified as likely AI-discovered resulted in RCE, against 26% of other CVEs.Read the full story at infosecurity-magazine.com
Sentinel — Human
The text reads like a compilation of specific technical research findings, structured around statistics and case examples, suggesting it is either based directly on primary source reporting or expertly synthesized from such sources.
