www.securityweek.com 30 Sept 2026, 14:05 UTC

Google Finds AI Discovered Flaws Are More Likely to Enable RCE

Google Finds AI Discovered Flaws Are More Likely to Enable RCE
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor

GOOGLE Threat Intelligence Group (GTIG) has analysed vulnerability disclosures from January 2025 to August 2026 and found that AI-enabled discovery is accelerating both the pace and the focus of security flaws. Monthly disclosures more than double from 5,045 in January 2026 to 10,477 in July, with a peak of 10,740 in August. GTIG cautions that raw volume can be misleading because automated CVE assignment in open-source ecosystems inflates numbers.

Notably, high-risk disclosures rose by 167%—from 131 in January to 350 in August—and the first eight months of 2026 saw 141 distinct exploited vulnerabilities, more than the 127 seen in all of 2025. Despite this, exploitation remains a minority, with only about 0.23% of disclosed vulnerabilities observed being exploited in the period.

A striking finding is the risk profile and exploitation pattern of AI-discovered vulnerabilities. Among AI-identified flaws from January to August, 39% were rated low-risk and 58% medium-risk, versus 69% low and 28% medium for non-AI vulnerabilities, suggesting AI-driven programmes may be auditing critical infrastructure with a focus on higher-impact findings.

Half of AI-discovered vulnerabilities resulted in remote code execution, compared with 26% for non-AI flaws, a difference GTIG attributes to AI’s ability to uncover memory corruption and logic flaws that static analysers miss. zero-days in 2026 averaged 11 per month (up from eight in 2025), with 62% of exploited vulnerabilities being zero-days, while AI-driven exploitation

appears to hinge on n-days rather than new zero-days; for example CVE-2026-1731, an unauthenticated OS command injection in BeyondTrust Privileged Remote Access, was autonomously discovered and rapidly weaponised in active campaigns. GTIG also notes rising disclosures of AI-system vulnerabilities, though only a few have been observed exploited in the wild.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline