3 min read

AI finds more vulnerabilities, but attackers exploit few

AI helped uncover 1,061 vulnerabilities, but only 14 were exploited. VulnCheck says the window to patch is shrinking from 120 to 80 days.

Image: ITzine

AI-assisted security tools are finding vulnerabilities at a much faster rate, but attackers have captured only a small fraction of those discoveries. According to VulnCheck, just 14 of 1,061 vulnerabilities found with AI assistance were confirmed to have been exploited—a rate of 1.3%.

That result contrasts with the rapid growth in vulnerability disclosures. The US National Vulnerability Database recorded 45,207 entries between January 1 and July 27, 2026, nearly matching the previous year’s record. If the current pace continues, 2026 could finish with roughly twice the 2025 result.

AI-assisted vulnerability discovery accelerates

Software vendors are contributing to the surge. Oracle’s July update fixed 1,449 vulnerabilities, compared with 309 in the same update a year earlier. Microsoft reported 622 fixes and separately acknowledged that AI tools helped discover some of them.

Recommended reading

Okta to acquire Permiso for nearly $200 million

The pattern points to a shift in how vulnerabilities reach the public. Companies are increasingly identifying weaknesses internally and patching them before they are disclosed, rather than waiting for an outside researcher—or an attacker—to find them first.

Yet the rise in published vulnerabilities has not produced a proportional increase in attacks. VulnCheck recorded 495 known exploitation cases during the first half of 2026. Over the same period, the number of published CVEs rose by 45%, while the number of vulnerabilities actually used in attacks increased by only 10%.

The share of published vulnerabilities that ultimately reach active exploitation fell to 1.4%, down from a peak of 2.7% at the end of 2023.

Why more findings have not led to more attacks

VulnCheck’s explanation is that AI currently benefits defenders more than attackers. Many newly discovered flaws are found inside companies, where teams can develop and deploy a patch before the vulnerability becomes public. That does not eliminate the risk, but it narrows the window in which criminals can exploit an unpatched system.

Chrome provides one example. Some of Google’s recent fixes were based on internal checks rather than external vulnerability reports. Those routine, internally driven patches are less likely to be followed by reports of widespread attacks because the underlying weakness may be addressed before attackers can act on public information.

The time available to respond is shrinking, however. The median interval between a vulnerability’s publication and its first confirmed exploitation fell from 120 days in 2025 to 80 days in the first half of 2026.

Against that backdrop, CISA recommends fixing critical vulnerabilities with confirmed exploitation within three days. For IT teams, that leaves little room for slow triage, unclear ownership, or delayed deployment.

Glasswing shows the gap between findings and attacks

VulnCheck also examined Glasswing, one of the most prominent AI vulnerability-discovery projects from Anthropic. In May, Anthropic said the Claude-powered system had identified 23,019 potential problems. However, the project’s public log contained only 1,611 entries, and just 126 reached CVE status.

Only one vulnerability from that set was confirmed to have been exploited in real-world attacks. The figures illustrate the gap between a large pool of potentially interesting findings and the much smaller number that become actionable security problems for attackers.

AI systems themselves are also becoming targets. VulnCheck counted 28 known exploited vulnerabilities in AI systems, including 10 that had already been used by attackers.

One example is LangFlow. By chaining multiple flaws, attackers gained access to data that included service credentials for platforms such as OpenAI and Claude. They then deployed cryptocurrency miners and attempted to maintain a foothold inside the affected infrastructure.

The central security metric in 2026 is therefore not simply how many vulnerabilities AI can find. As discovery accelerates and the median time from publication to exploitation falls to 80 days, the advantage will go to organizations that can patch first—not to those that merely publish the most CVEs.

Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via ITzine

/ Keep reading