The number of vulnerabilities disclosed each month doubled in 2026, and the monthly average of vulnerabilities exploited in the wild nearly doubled, according to a new report from Google Threat Intelligence Group (GTIG).
Analyzing disclosures from January 2025 through August 2026, GTIG found that monthly disclosures rose from 5,045 in January 2026 to 10,477 in July, peaking at 10,740 in August.
“We found that AI is measurably changing not just the pace of vulnerability discovery and exploitation, but also the types and typical risk profiles of vulnerabilities that are being discovered,” GTIG says.
The researchers caution that raw volume can be misleading, as automated CVE assignment in open source ecosystems can inflate the numbers. Vulnerabilities whose description mentions the Linux kernel alone generated roughly 5,000 CVEs between January and August, with no in-the-wild zero-day exploitation observed.
High-risk disclosures, based on GTIG’s own ratings rather than CVSS, grew 167%, from 131 in January to 350 in August. In addition, GTIG recorded 141 distinct exploited vulnerabilities in the first eight months of 2026, more than the 127 seen in all of 2025. That’s an average of 18 per month, up from 10.5 last year.
Still, only 0.23% of this year’s disclosed vulnerabilities, roughly one in 431, were observed being exploited.
Zero-day exploitation increased only marginally, from an average of eight per month in 2025 to 11 per month in 2026, although the count jumped to 22 in August. Zero-days made up 62% of the vulnerabilities exploited between January and August.
GTIG suggests that the growth in exploitation came primarily from n-days. Exploitation of high-risk vulnerabilities also more than doubled, from 28 in 2025 to 75 in the first eight months of 2026.
“It is possible that threat actors are finding it more accessible or efficient to use LLMs and AI tools to automate analysis of differences between product versions, patches, vulnerability disclosure announcements, and Proof-of-Concept (POC) code to rapidly weaponize n-days, rather than to discover new zero-days,” the report reads.
Vulnerabilities that GTIG identified as likely discovered by AI between January and August show a different risk profile. Of these, 39% were rated low-risk and 58% medium-risk, compared to 69% and 28%, respectively, for non-AI vulnerabilities.
GTIG says this likely reflects how research programs deploy AI agents, tasking them with auditing critical infrastructure and sensitive privilege boundaries with a focus on higher-impact findings.
Half of the AI-discovered vulnerabilities result in remote code execution, compared to 26% of non-AI vulnerabilities. According to GTIG, this likely stems from AI models’ ability to find memory corruption and logic flaws that traditional static analyzers miss.

GTIG has also confirmed in-the-wild exploitation of AI-discovered vulnerabilities, though it describes this as an early indicator rather than an established trend.
One example is CVE-2026-1731, an unauthenticated OS command injection flaw in BeyondTrust Privileged Remote Access and Remote Support, discovered autonomously by the Hacktron AI research agent. One threat cluster exploited it within four days of public disclosure, and five more followed within seven days.
Disclosures of vulnerabilities in AI systems themselves are also rising. GTIG tracked 2,076 AI-related CVEs between January 2025 and August 2026, including more than 1,500 this year, roughly half of which affect AI orchestration frameworks.
Only a handful of the 2,076 have been confirmed as exploited in the wild, including flaws in LiteLLM and Langflow. GTIG has not yet observed zero-day exploitation of AI infrastructure.
“GTIG expects that rates of vulnerability discovery and exploitation are likely to continue to increase in the short to medium term,” the report reads.
Related: High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL
Related: WatchGuard Patches Critical Fireware OS Code Injection Vulnerability
Related: Chrome, Firefox Updates Patch Over 100 Vulnerabilities

