Google Finds AI Is Changing Vulnerability Discovery and Exploitation Trends

Summary
Google Threat Intelligence Group reports that vulnerability disclosures and observed exploitation rose in 2026, while AI-discovered flaws skewed toward higher-risk issues. The report also tracks vulnerabilities and exploitation affecting AI systems.
Key points
- Vulnerability disclosures rose from 5,045 in January 2026 to 10,740 in August. GTIG cautions that automated CVE assignments inflated some counts.
- GTIG observed 141 disclosed vulnerabilities exploited in the wild from January through August 2026, versus 127 during all of 2025. Exploitation remained rare relative to total disclosures.
- Zero-day exploitation averaged 11 cases per month in 2026, up from 8 in 2025; 62% of observed exploited vulnerabilities in January–August 2026 were zero-days.
- Among vulnerabilities identified as AI-discovered, 58% were rated Moderate risk and 4% High risk; 50% led to remote code execution, compared with 26% across the broader CVE ecosystem.
- GTIG tracked 2,076 AI-related CVE disclosures from January 2025 through August 2026, with 782 in AI orchestration and agent frameworks during 2026.
- GTIG observed exploitation of the AI-discovered BeyondTrust CVE-2026-1731 within four days of public disclosure, followed by five more threat clusters within seven days; activity included data exfiltration and secondary payloads.
- GTIG recommends threat-intelligence-driven vulnerability triage, targeted edge defenses, automated remediation, and security reviews of AI systems and software.
Article Details
- Publisher
- Google Threat Intelligence Group (GTIG)
- Report Period
- 2025-01-01 to 2026-08-31
- Scope
- Vulnerability disclosure, risk, and in-the-wild exploitation trends, including AI-assisted discovery and vulnerabilities affecting the AI operational stack.
- Sample Size
- Total monitored vulnerabilities not stated; GTIG tracked 2,076 AI-related CVE disclosures.
- Key Statistics
- Monthly vulnerability disclosures rose from 5,045 in January 2026 to 10,740 in August 2026.
- GTIG recorded 141 distinct vulnerabilities disclosed and exploited from January through August 2026, compared with 127 during all of 2025. It observed exploitation of 0.23% of vulnerabilities disclosed in 2026.
- High-Risk disclosures rose from 131 in January 2026 to 350 in August 2026; they represented 3% of August disclosures.
- In GTIG's identified AI-discovered subset, 50% of vulnerabilities could lead to remote code execution, compared with 26% across the broader CVE ecosystem.
- GTIG tracked 2,076 AI-related CVE disclosures from January 2025 through August 2026, including more than 1,500 from January through August 2026.
- Recommendations
- Prioritize vulnerability remediation using threat intelligence and risk-based triage rather than unprioritized mass patching.
- Apply targeted defenses to exposed edge systems.
- Use automated, agentic remediation to shorten response times.
- Contain and sandbox autonomous agentic workloads.
- Use AI-enhanced code review to identify and fix vulnerabilities before software is released.
MITRE ATT&CK
CVE
CVE-2025-3248CVE-2025-3248 (Langflow): Unauthenticated Python code injection via exec() in /api/v1/validate/code, permitting immediate RCE.CVE-2026-1731A notable case is CVE-2026-1731, an unauthenticated OS command injection flaw in BeyondTrust Privileged Remote Access (PRA) and Remote Support that was discovered autonomously by a third-party research agent (HacktronCVE-2026-42271CVE-2026-42271 (BerriAI LiteLLM): Command injection in Model Context Protocol (MCP) server preview endpoints (POST /mcp-rest/test/connection), resulting in host takeover and API credential theft.CVE-2026-5027CVE-2026-5027 (Langflow): Path traversal file write in the POST /api/v2/files upload handler, allowing remote threat actors to drop unauthorized files (e.g., cron jobs, Secure Shell (SSH) keys) onto the host.
Malware
Vendors
BerriAICVE-2026-42271 (BerriAI LiteLLM): Command injection in Model Context Protocol (MCP) server preview endpoints (POST /mcp-rest/test/connection), resulting in host takeover and API credential theft.BeyondTrustA notable case is CVE-2026-1731, an unauthenticated OS command injection flaw in BeyondTrust Privileged Remote Access (PRA) and Remote Support that was discovered autonomously by a third-party research agent (HacktronGoogleGoogle Threat Intelligence Group (GTIG) examines vulnerability disclosure and exploitation statistics to evaluate the impact of artificial intelligence (AI) on the vulnerability threat landscape.OracleOracle & Linux: In June, July, and August Oracle’s quarterly Critical Patch Update (CPU) across middleware like WebLogic and Coherence combined with Linux kernel network driver advisories to contribute 128 High-RiskTOTOLINKTOTOLINK: In April and May, mass research disclosures against consumer router firmware added 75 High-Risk flaws, driving the mid-year spike in Command Execution vulnerabilities.
Products
CoherenceJuly, and August Oracle’s quarterly Critical Patch Update (CPU) across middleware like WebLogic and Coherence combined with Linux kernel network driver advisories to contribute 128 High-Risk vulnerabilities inFlowiseFlowise, Langflow, LangChain, Dify, LlamaIndex, AutoGen, CrewAI, Semantic Kernel, Letta, MCP, Pydantic-AIGoogle AI Threat DefenseLeveraging agentic defensive capabilities, such as CodeMender, integrated into Google AI Threat Defense, to continuously audit and patch code across developer workflows will be vital.LangflowFlowise, Langflow, LangChain, Dify, LlamaIndex, AutoGen, CrewAI, Semantic Kernel, Letta, MCP, Pydantic-AILinux kernelecosystems can inflate baseline figures; for instance, vulnerabilities with a description containing “Linux Kernel” alone generated approximately 5,000 CVEs between January 2026 and August 2026 with zero observedLiteLLMvLLM, Ollama, LiteLLM, Llama.cpp, Triton (NVIDIA), Ray, TGI, SGLang, TensorRT-LLM, BentoML, LocalAIOllamavLLM, Ollama, LiteLLM, Llama.cpp, Triton (NVIDIA), Ray, TGI, SGLang, TensorRT-LLM, BentoML, LocalAIPrivileged Remote Access (PRA)A notable case is CVE-2026-1731, an unauthenticated OS command injection flaw in BeyondTrust Privileged Remote Access (PRA) and Remote Support that was discovered autonomously by a third-party research agent (HacktronRemote Supportan unauthenticated OS command injection flaw in BeyondTrust Privileged Remote Access (PRA) and Remote Support that was discovered autonomously by a third-party research agent (Hacktron AI).TritonvLLM, Ollama, LiteLLM, Llama.cpp, Triton (NVIDIA), Ray, TGI, SGLang, TensorRT-LLM, BentoML, LocalAIvLLMvLLM, Ollama, LiteLLM, Llama.cpp, Triton (NVIDIA), Ray, TGI, SGLang, TensorRT-LLM, BentoML, LocalAIWebLogic& Linux: In June, July, and August Oracle’s quarterly Critical Patch Update (CPU) across middleware like WebLogic and Coherence combined with Linux kernel network driver advisories to contribute 128 High-Risk
Tools
Agentic Vulnerability Discovery Harness (AVDH)Mandiant has described similar findings when using a specialized Agentic Vulnerability Discovery Harness (AVDH) in point-in-time assessments of client codebases.CodeMenderLeveraging agentic defensive capabilities, such as CodeMender, integrated into Google AI Threat Defense, to continuously audit and patch code across developer workflows will be vital.Hacktron AIacknowledgments attributing root-cause discovery or PoC synthesis to autonomous AI agents (e.g., Hacktron AI, AISLE).