• AI-assisted discovery appears to be shifting the risk profile of vulnerabilities. Among flaws GTIG identified as likely discovered by AI, 58% were rated moderate under Google’s risk scale, while half enabled remote code execution.
  • By comparison, remote code execution affected 26% of other disclosed vulnerabilities. GTIG cited CVE-2026-1731, an unauthenticated operating-system command-injection flaw in BeyondTrust’s Privileged Remote Access and Remote Support products. A research agent from Hacktron AI discovered the vulnerability autonomously. One threat cluster exploited it within four days of public disclosure, followed by five more within seven days.
  • Vulnerabilities affecting AI software are also increasing, according to the data. GTIG has tracked 2,076 AI-related vulnerabilities since the beginning of 2025, including more than 1,500 disclosed in 2026. About half affect AI orchestration frameworks such as Flowise and Langflow.