Skip to content

Executive Summary

Vulnerability disclosure and exploitation rates significantly increased between January 2025 and August 2026, driven by the impact of artificial intelligence. Vulnerability disclosures doubled, rising from 5,045 in January 2026 to a peak of 10,740 in August 2026. Exploitation also nearly doubled, increasing from an average of 10.5 vulnerabilities per month in 2025 to an average of 18 per month in 2026. While zero-day exploitation grew marginally, the focus shifted toward weaponizing known n-days, with exploitation of High-Risk vulnerabilities more than doubling. This shift suggests that AI is influencing not only the volume but also the type and risk profile of discovered vulnerabilities, prioritizing flaws leading to remote code execution.
The analysis indicates a divergence in discovery patterns, where AI-assisted discovery prioritized Medium- and High-Risk vulnerabilities, contrasting with conventional methods which focus on lower-risk findings. Furthermore, the ecosystem is seeing vulnerability activity concentrated in edge and security appliances, suggesting that perimeter systems are primary targets for initial access and exploitation. The growth trend suggests a need for organizations to move away from mass patching toward threat-intelligence-driven triage and agentic remediation to manage the accelerated risk exposure.

Facts Only

* Vulnerability disclosures doubled from 5,045 in January 2026 to 10,477 in July, peaking at 10,740 in August 2026.
* Vulnerability exploitation increased from an average of 10.5 per month in 2025 to an average of 18 per month in 2026.
* Zero-day vulnerability exploitation grew from an average of 8 per month in 2025 to an average of 11 per month in 2026.
* AI-assisted discovery found proportionally fewer Low-Risk vulnerabilities and more Moderate-Risk vulnerabilities.
* High-Risk vulnerability disclosures surged from 131 in January 2026 to 350 in August 2026, representing a 167% growth.
* Baseline High-Risk disclosures increased from approximately 65/month in mid-2025 to approximately 135/month in mid-2026 across the broader software ecosystem.
* Exploitation of all vulnerabilities in the wild reached 141 distinct instances from January 2026 to August 2026, surpassing the total exploited for the full year of 2025 (127).
* In-the-wild exploitation increased from an average of 10.5 per month in 2025 to an average of 18 per month in 2026.
* Exploitation of High-Risk vulnerabilities more than doubled from 28 in 2025 to 75 from January 2026 to August 2026.
* Vulnerabilities affecting Edge and Security Appliances represented 14% of vulnerabilities exploited from January 2026 to August 2026.
* Agentic vulnerability discovery focused on High-Risk findings, with 50% of AI-discovered vulnerabilities resulting in Remote Code Execution (RCE).
* CVE exploitation increased at approximately the same rate as overall CVE disclosure, though growth in exploitation did not begin to pick up until the second quarter of 2026.

Full Take

The observation that vulnerability activity is accelerating alongside AI-driven discovery suggests a feedback loop where autonomous agents are rapidly finding high-impact flaws and threat actors are efficiently weaponizing these findings, particularly n-days rather than discovering entirely new zero-days. The key divergence lies in the risk profile: AI appears to shift focus from low-severity compliance issues toward exploitable logic flaws and memory corruption, reflecting an engineering priority focused on core system security. The emergence of vulnerabilities targeting the AI/LLM operational stack—specifically orchestration frameworks and inference gateways—signals a new, high-value attack surface being created by enterprise adoption. The documented success in weaponizing specific flaws like CVE-2026-1731 illustrates that agentic discovery directly feeds into active threat campaigns, indicating that defensive action must target the lifecycle of automated research itself. This creates an imperative for security to shift its focus from reaction against raw disclosure volume to preemptive control over autonomous testing and remediation workflows. What assumptions about the speed of human versus machine reasoning are currently holding back our understanding of the next evolution of vulnerability risk?

From the original · Google Cloud Threat Intelligence

Google Threat Intelligence Group Google Threat Intelligence Visibility and context on the threats that matter most.
Read the full story at cloud.google.com

Sentinel — Human

Confidence

The text presents complex, evidence-based analysis rooted in specific threat intelligence metrics, suggesting it is a product of expert synthesis rather than pure generative output.

Signals Detected
low severity: Sentence length variance is moderate; vocabulary shifts between formal reporting and technical specifics.
low severity: The structure flows logically from broad statistics to specific AI-related implications, typical of expert white papers.
low severity: Heavy reliance on citing internal data points (figures and statistics) suggests a source with established reporting structures.
severity: The presentation of specific, cross-referenced statistics tied to named organizations (Google Threat Intelligence Group, Mandiant) suggests grounded, verifiable reporting.
Human Indicators
Presence of highly specific internal data references (e.g., CVE numbers, specific monthly counts across a 20-month window) indicates direct access to proprietary tracking, which is characteristic of deep industry research.
The nuanced discussion distinguishing between raw disclosure volume and exploitation trends shows a contextual understanding beyond simple data presentation.
Vulnerability Discovery and Exploitation Trends in the AI Era | Huntaegis