Google Threat Intelligence Group (GTIG) published research on September 30, 2026 finding that the number of vulnerabilities disclosed per month doubled during 2026 and that in-the-wild exploitation nearly doubled, changes it attributes in part to artificial intelligence. The analysis covers vulnerabilities disclosed between January 1, 2025 and August 31, 2026.
What the data shows
GTIG said monthly disclosures rose from 5,045 in January 2026 to 10,477 in July and peaked at 10,740 in August 2026. Exploitation climbed from an average of 10.5 vulnerabilities per month in 2025 to 18 per month between January and August 2026, while zero-day exploitation rose more modestly, from an average of 8 per month to 11.
The company cautioned that raw counts can mislead. It said automated CVE Numbering Authority assignment policies can inflate figures, noting that descriptions containing "Linux Kernel" alone generated roughly 5,000 CVEs between January and August 2026 with no observed in-the-wild zero-days. GTIG also said only 0.23% of vulnerabilities disclosed in 2026, roughly 1 in 431, were ever seen being actively exploited.
High-Risk disclosures, measured on GTIG's own risk ratings rather than CVSS, surged from 131 in January 2026 to 350 in August 2026, a 167% increase, though they remained 3% of all disclosures in August. GTIG attributed spikes to mass research disclosures against TOTOLINK consumer router firmware and to Oracle's quarterly Critical Patch Update combined with Linux kernel network driver advisories.
AI as the hunter
GTIG said vulnerabilities it could identify as likely AI-discovered show a different risk profile from conventional findings: 39% were Low risk versus 69% for non-AI discoveries, and 58% were Medium versus 28%. Exactly 50% of AI-discovered vulnerabilities result in remote code execution, compared with 26% across the broader CVE ecosystem, according to the report.
The group said public data significantly undercounts AI-found bugs because CVE repositories lack standardized AI attribution metadata and because cloud and SaaS providers often patch silently without requesting CVE IDs.
As an example of real-world impact, GTIG cited CVE-2026-1731, an unauthenticated OS command injection flaw in BeyondTrust Privileged Remote Access and Remote Support that it said was discovered autonomously by third-party research agent Hacktron AI. Within four days of public disclosure GTIG observed one threat cluster exploiting it, followed by five more within seven days, with post-exploitation activity including privilege escalation, data exfiltration and payloads such as SNOWLIGHT, SPARKRAT and cryptominers.
AI as the hunted
GTIG said it tracked 2,076 cumulative AI-related CVE disclosures across the 20-month window, with more than 1,500 identified between January and August 2026 across eight architectural layers. Orchestration middleware accounted for 50% of all AI-related flaws and saw a 347% surge in disclosures in 2026, the report said.
Backend serving infrastructure such as vLLM, Triton, LiteLLM and Ollama reached 212 disclosures in 2026, with nearly a quarter stemming from unauthenticated API endpoints or server-side request forgery. GTIG said it has not yet observed zero-day exploitation of AI infrastructure, but listed confirmed in-the-wild exploitation of CVE-2026-42271 in BerriAI LiteLLM and CVE-2026-5027 and CVE-2025-3248 in Langflow.
Exploitation overall stayed concentrated at the perimeter: edge and security appliances made up 14% of vulnerabilities exploited in 2026 and enterprise directory and collaboration hubs 11%, with over 65% of exploited edge flaws rated High or Critical.
Outlook
GTIG expects discovery and exploitation rates to keep rising in the short to medium term. It argued the growth in exploitation is driven mainly by rapid weaponization of n-days rather than a flood of new zero-days, possibly because threat actors use LLMs to analyze patches and proof-of-concept code.
What to do
- Move away from unprioritized mass-patching toward threat-intelligence-driven triage, combining targeted edge defense with automated, agentic remediation, GTIG says.
- Treat internet-facing edge gateways and unauthenticated public management interfaces as priority defense targets, since GTIG says adversaries concentrate exploitation there.
- Contain and sandbox autonomous agentic workloads and apply risk-based vulnerability management to AI infrastructure, according to GTIG.
- Run AI-enhanced code review internally before shipping software, which GTIG says could eventually slow growth in public vulnerability disclosures.
- Review the AI middleware flaws GTIG lists as exploited in the wild: CVE-2026-42271 in BerriAI LiteLLM, and CVE-2026-5027 and CVE-2025-3248 in Langflow.
Key facts and where they come from
- Monthly vulnerability disclosures doubled during 2026, peaking at 10,740 in August.
the number of vulnerabilities disclosed per month doubled, rising from 5,045 in January 2026 to 10,477 in July and continuing to climb to 10,740 in August 2026
- In-the-wild exploitation rose from 10.5 to 18 vulnerabilities per month.
the number of vulnerabilities exploited increased from an average of 10.5 per month in 2025 to an average of 18 per month from January 2026 to August 2026
- Zero-day exploitation increased only marginally.
zero-day vulnerability exploitation grew from an average of 8 per month in 2025 to an average of 11 per month from January 2026 to August 2026
- Half of AI-discovered vulnerabilities lead to remote code execution.
Exactly 50% of all AI-discovered vulnerabilities result in Remote Code Execution (RCE), compared to just 26% across the broader CVE ecosystem.
- Only a tiny share of disclosed vulnerabilities is ever exploited.
only 0.23% of all disclosed vulnerabilities in 2026 (roughly 1 in 431) were ever observed in active exploitation
- Six threat clusters exploited CVE-2026-1731 within a week of disclosure.
within four days of public disclosure, GTIG observed a threat cluster exploiting this vulnerability, followed by five additional threat clusters within seven days of public disclosure
- GTIG tracked 2,076 AI-related CVE disclosures over the monitoring window.
GTIG tracked 2,076 cumulative AI-related CVE disclosures
- Agent orchestration middleware dominates AI-stack vulnerability disclosures.
Orchestration middleware accounts for 50% of all AI-related flaws, experiencing a +347% surge in disclosures in 2026.
- Edge and security appliances accounted for 14% of exploited vulnerabilities in 2026.
Vulnerabilities affecting Edge and Security Appliances represented 14% of vulnerabilities exploited from January 2026 to August 2026
