AI-FOUND vulnerabilities are disproportionately linked to remote code execution (RCE), according to Google Threat Intelligence Group (GTIG) analysis published on 30 September 2026. The researchers compared AI-discovered vulnerabilities with other CVEs and found that 50% of AI-identified vulnerabilities are likely to yield RCE, versus 26% for non-AI-discovered flaws.
GTIG notes this may reflect how autonomous agents are directed at critical infrastructure and that public data undercounts AI-discovered vulnerabilities. A key finding is that exploitation signals are an early indicator rather than a settled trend, with one AI-identified flaw, CVE-2026-1731, an unauthenticated command injection in BeyondTrust Privileged Remote Access and Remote Support, being exploited within four days of disclosure and five more within seven days.
The study highlights risk concentration around orchestration tools and edge devices. GTIG tracked more than 1,500 AI-related vulnerabilities disclosed in 2026, with 782 in agent orchestration frameworks and 212 in inference/serving infrastructure—nearly a quarter of which involved unauthenticated APIs or server-side request forgery. Exploitation remains perimeter-focused: edge and security appliances accounted for 14% of exploited vulnerabilities in 2026, and over 65% of edge flaws were rated high or critical risk.
The context includes Citrix NetScaler zero-days previously exploited, reinforcing guidance that customers should prioritise compromise assessment before patching, as patching alone may not remove active threats. The report presents a cautious view, with exploitation of AI-discovered flaws still not established as a broad trend but showing notable early activity and high-impact potential.