Vulnerability disclosures double as AI speeds exploitation
Monthly vulnerability disclosures have doubled since the start of the year, and artificial intelligence is changing how attackers turn those bugs into working exploits, according to Google's Threat Intelligence Group (GTIG).
In a report published Wednesday, GTIG said disclosures climbed from 5,045 in January to a record 10,740 in August. Both July and August passed the 10,000 mark.
"We found that AI is measurably changing not just the pace of vulnerability discovery and exploitation, but also the types and typical risk profiles of vulnerabilities that are being discovered," the researchers said.
More exploited bugs than all of 2025
The rise is not limited to raw disclosure numbers. Between January and August, the number of distinct vulnerabilities disclosed and exploited already exceeded the totals for the whole of 2025. GTIG counted 141 exploited vulnerabilities so far this year, compared with 127 last year.
According to the report, this growth is not the result of a wave of new zero-days. Zero-days are flaws exploited before the vendor knows about them. Instead, GTIG links the increase to "the rapid, targeted weaponization of high-risk exploits in the wild." Much of that activity involves n-days, which are vulnerabilities that have already been patched and publicly disclosed.
Researchers found that attackers are getting better at using AI to analyze patches and exploit critical flaws. Kelli Vanderlee, senior analyst at GTIG, said the team expects AI-assisted vulnerability discovery and exploitation to keep growing in the short to medium term.
"It is possible that threat actors are finding it more accessible or efficient to use LLMs and AI tools to automate analysis of differences between product versions, patches, vulnerability disclosure announcements, and Proof-of-Concept (POC) code to rapidly weaponize n-days, rather than to discover new zero-days," the researchers noted.
The BeyondTrust case
Google used CVE-2026-1731, a flaw in BeyondTrust software, as an example. US federal cyber defenders highlighted the bug in February. It was discovered autonomously by Hacktron AI, a third-party research agent.
Once the flaw was public, attackers moved quickly. GTIG saw one threat cluster exploiting it within four days of disclosure. Within seven days, five more clusters had joined in, using the bug in targeted initial-access campaigns to get past enterprise perimeters.
After gaining access, the attackers escalated privileges, exfiltrated data and dropped additional payloads. These included SNOWLIGHT, SPARKRAT and cryptominers.
According to GTIG, the case shows that autonomous research agents pointed at critical attack surfaces "demonstrate a formidable capacity to uncover high-severity flaws." This is a pattern our readers may recognize from the recent incident in which DIVD was breached by an autonomous AI agent.
What counts as high-risk
GTIG said AI agents are mostly finding medium- and high-risk vulnerabilities. Vanderlee explained that a bug is classed as high-risk if exploiting it gives attackers a notable, direct impact on the security of targeted devices and networks, without major mitigating factors standing in the way.
"Reliability of exploitation is expected to be high and can typically be done on a wide scale," she said.
Many of this year's disclosures came from a small number of vendors, including router firmware maker Totolink and Oracle.
Attackers are also still focused on perimeter devices and exposed enterprise services. Of the vulnerabilities exploited between January and August, 14% affected edge and security appliances.
CISA and NIST numbers point the same way
The findings match data released last week by the Cybersecurity and Infrastructure Security Agency (CISA), the US federal agency responsible for civilian cyber defense. CISA said more than 67,000 new CVEs have been published in 2026 so far. Experts expect the total to reach 96,000 by the end of the year.
CISA also cited figures from the National Vulnerability Database (NVD), the public CVE catalog run by the National Institute of Standards and Technology (NIST). Annual CVE submissions grew by 263% between 2020 and 2025. In the first three months of 2026, submissions were one-third higher than in the same period of 2025.
Why It Matters
The key takeaway from GTIG's report is that the gap between disclosure and exploitation is shrinking. The BeyondTrust example shows attackers acting within days, and several groups were active within a week. This suggests that patch cycles measured in weeks or months carry more risk than they used to. That is especially true for internet-facing systems.
The focus on edge and security appliances is consistent with what we have reported over the past weeks. Examples include the exploited Cisco SD-WAN Manager zero-day and the mass attacks on Citrix NetScaler. If AI makes patch diffing cheaper, defenders should expect more of these devices to be targeted soon after vendors release fixes.
There is also a volume problem. With disclosures now above 10,000 a month, security teams can't treat every CVE the same way. Risk-based prioritization, guided by exploitation data and exposure, looks increasingly necessary rather than optional.
It is worth watching whether the same AI tools help defenders and vendors shorten their own response times, and whether vulnerability databases such as the NVD can handle the growing number of submissions. Another open question is whether AI-driven discovery will eventually produce more zero-days, and not only faster n-day exploitation.
