According to one cybersecurity research group, autonomous discovery has been exposing higher-risk flaws across security appliances and AI frameworks.
According to Google’s Threat Intelligence Group (GTIG) analyses, monthly software vulnerability disclosures had more than doubled from 5,045 in January 2026 to 10,477 in July, and a record 10,740 in August.
The group has said AI is accelerating vulnerability discovery and changing the types and risk profiles of flaws being identified. However, the increase in disclosures does not represent an equivalent surge in attacks. GTIG said open-source projects automatically assign vulnerability identifiers, inflating the raw totals. Linux kernel flaws accounted for about 5,000 records this year, but none had resulted in a zero-day exploited in the wild.
The data shows that, between January and August 2026, attackers had exploited 141 newly disclosed vulnerabilities, compared with 127 during all of 2025. That equates to roughly one exploited vulnerability for every 431 disclosures. GTIG said the increase is being driven by the rapid, targeted weaponization of high-risk vulnerabilities — particularly flaws that have already been publicly disclosed and patched — rather than by a flood of new zero-days.
- AI-assisted discovery appears to be shifting the risk profile of vulnerabilities. Among flaws GTIG identified as likely discovered by AI, 58% were rated moderate under Google’s risk scale, while half enabled remote code execution.
- By comparison, remote code execution affected 26% of other disclosed vulnerabilities. GTIG cited CVE-2026-1731, an unauthenticated operating-system command-injection flaw in BeyondTrust’s Privileged Remote Access and Remote Support products. A research agent from Hacktron AI discovered the vulnerability autonomously. One threat cluster exploited it within four days of public disclosure, followed by five more within seven days.
- Vulnerabilities affecting AI software are also increasing, according to the data. GTIG has tracked 2,076 AI-related vulnerabilities since the beginning of 2025, including more than 1,500 disclosed in 2026. About half affect AI orchestration frameworks such as Flowise and Langflow.
GTIG has advised organizations to prioritize patching using threat intelligence instead of attempting to fix every vulnerability indiscriminately. It also recommends that software vendors conduct agentic AI code reviews before releasing software. Wider adoption of such regimes could eventually slow the growth in public disclosures, although Kelli Vanderlee, a senior GTIG analyst, expects AI-assisted discovery and exploitation to continue expanding in the short to medium term.
