The Google Threat Intelligence Group (GTIG) has unveiled a report indicating a significant rise in the number of vulnerabilities disclosed monthly, doubling in 2026 compared to previous years. The analysis, covering data from January 2025 to August 2026, shows a surge in both the discovery and exploitation of these vulnerabilities, driven by advances in artificial intelligence (AI).
The Impact of AI on Vulnerability Discovery
According to GTIG, AI has reshaped not only the speed at which vulnerabilities are identified but also the nature and risk profile of these discoveries. Between January and August 2026, the number of monthly disclosures increased from 5,045 in January to an impressive 10,740 by August. This surge is attributed to AI’s role in automating and expediting the identification process.
The report warns that the sheer volume of these disclosures can be deceptive, as automated CVE assignments, particularly in open source ecosystems, may inflate the figures. For instance, vulnerabilities related to the Linux kernel alone accounted for approximately 5,000 CVEs during this period without any observed zero-day exploits.
High-Risk Vulnerabilities on the Rise
High-risk vulnerability disclosures have seen a dramatic increase, with GTIG’s assessments showing a 167% rise from 131 in January to 350 by August. Additionally, GTIG recorded 141 distinct exploited vulnerabilities in the first eight months of 2026, surpassing the total from 2025. While the exploitation rate is still low at 0.23%, the trend is noticeable.
Zero-day exploits, however, showed a minor increase, averaging 11 per month in 2026, up from eight in 2025, with a peak of 22 in August. A significant portion of the exploitation growth stems from n-days rather than new zero-days, suggesting that threat actors may prefer using AI tools for analyzing and weaponizing existing vulnerabilities.
AI’s Role in Shaping Risk Profiles
The vulnerabilities identified by AI from January to August 2026 displayed different risk characteristics, with 39% labeled as low-risk and 58% as medium-risk, compared to traditional methods. This reflects AI’s deployment in auditing critical infrastructure and privilege boundaries, focusing on higher-impact findings.
Remarkably, half of the AI-discovered vulnerabilities led to remote code execution, a stark contrast to the 26% for non-AI findings. This outcome is likely due to AI models’ proficiency in detecting memory corruption and logic flaws, often overlooked by traditional static analysis tools.
Future Outlook on AI and Cybersecurity
While GTIG confirms in-the-wild exploitation of AI-discovered vulnerabilities, such as CVE-2026-1731, it remains an emerging trend rather than an established norm. The report also notes a rise in AI system-related vulnerabilities, with 2,076 AI-related CVEs recorded in the examined period. Despite this, only a few have been exploited in the wild.
Looking ahead, GTIG anticipates that the pace of vulnerability discovery and exploitation will continue to escalate, highlighting the need for robust security measures and ongoing vigilance in the face of evolving AI technologies.
