A recent report from VulnCheck reveals that only 1.3% of software vulnerabilities identified through AI have been exploited in real-world scenarios, which matches the overall exploitation rate of vulnerabilities. Notably, the report highlighted that despite AI tools discovering a high volume of vulnerabilities, many remain unutilized by attackers. For instance, while Anthropic's Project Glasswing found over 23,000 vulnerabilities, only 126 received published CVEs, with just one confirmed as exploited.
Additionally, nearly 500 known exploited vulnerabilities (KEVs) were identified within the first half of 2026, showing an increased pace of exploitation compared to previous years. Content Management Systems (CMS) are the most targeted, accounting for one-third of KEVs.