Back to News
RSS feedcloud.google.com

Google Finds AI Is Accelerating Vulnerability Discovery and Exploitation

Summary

Google Threat Intelligence Group analyzed vulnerability disclosures and exploitation from January 2025 through August 2026 to assess how AI is changing the threat landscape. Monthly disclosures rose from 5,045 in January 2026 to 10,740 in August, while vulnerabilities exploited in the wild averaged 18 per month in 2026, up from 10.5 in 2025. Zero-day exploitation increased only modestly, from eight to 11 per month on average, suggesting that the larger change is the faster weaponization of n-day vulnerabilities. GTIG recorded 141 vulnerabilities exploited between January and August 2026, but only 0.23% of all disclosed vulnerabilities were observed in active exploitation. High-risk exploited vulnerabilities rose from 28 in 2025 to 75 in the 2026 period, with edge appliances and exposed enterprise services remaining important targets. GTIG says AI-assisted discovery appears to find fewer low-risk flaws and more medium- and high-risk vulnerabilities: 58% of identified AI-discovered flaws were medium risk, compared with 28% among other findings, and 50% led to remote code execution versus 26% across the broader CVE ecosystem. The group cautions that public data undercounts AI discovery because CVE repositories lack standardized attribution and cloud providers may patch findings without assigning CVEs. It also tracked 2,076 AI-related CVE disclosures during the full monitoring window, including vulnerabilities in orchestration frameworks, AI web applications, inference infrastructure, model security components, and machine-learning frameworks. Orchestration frameworks accounted for 782 disclosures, while inference and serving infrastructure accounted for 212. GTIG reported no observed zero-day exploitation of AI infrastructure, but cited in-the-wild exploitation of several newly disclosed middleware flaws involving command injection, path traversal, and unauthenticated code execution. It recommends threat-intelligence-driven triage, targeted edge defenses, sandboxing for autonomous workloads, and automated or agentic remediation.