From January to August 2026, monthly vulnerability disclosures rose from 5,045 to 10,740, while the monthly average of flaws exploited increased from 10.5 in 2025 to 18. About 50% of vulnerabilities GTIG identified as likely AI discovered enabled remote code execution, compared with 26% of other vulnerabilities.
Published byEdited with GPT-6 LunaImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: How did AI affect the volume, types, risk levels, and exploitation of software vulnerabilities from January through August 2026, according t. Article summary: Google’s Threat Intelligence Group (GTIG) found that AI was accelerating vulnerability discovery and changing the mix of flaws being found, but the surge in disclosures did **not** mean a comparable share of flaws was be. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fa
Google’s Threat Intelligence Group (GTIG) found that software vulnerability disclosures more than doubled between January and August 2026, while the average number of vulnerabilities observed in exploitation rose less sharply. AI-assisted discovery was associated with a different mix of flaws, including a higher share that enabled remote code execution. The findings do not establish how much of the overall increase AI alone caused. 3
17
Monthly vulnerability disclosures increased from 5,045 in January 2026 to 10,740 in August. GTIG also counted 141 distinct vulnerabilities exploited during the first eight months of the year, compared with 127 in all of 2025. The monthly average of vulnerabilities exploited rose from 10.5 in 2025 to 18 between January and August 2026. 3
These figures describe different things: disclosure counts measure vulnerabilities made public, while exploitation counts track distinct flaws observed being used by attackers. They are not counts of attacks or victims. A rise in disclosures does not mean that attackers are exploiting a similar share of newly reported flaws. 3
The data shows that both discovery and exploitation increased, but it does not isolate AI as the cause of either trend. GTIG’s findings describe AI’s growing influence on vulnerability discovery and the risk profile of some findings—not a precise measure of how much AI contributed to the broader totals. 3
29
GTIG identified about half of the vulnerabilities it classified as likely AI-discovered as enabling remote code execution (RCE), compared with about 26% of other vulnerabilities. RCE can let an attacker run code on a vulnerable system, so this difference points to potentially serious consequences. “Likely AI-discovered” is an attribution, however; it does not mean AI independently found every flaw in that group. 17
23
The severity picture needs a second qualification. Reporting on GTIG’s analysis says 58% of the likely AI-discovered vulnerabilities were rated medium risk, compared with 28% of other disclosures; only about 4% were high risk, a share similar to the non-AI group. Separately, high-risk disclosures on GTIG’s own scale rose from 131 in January to 350 in August. That increase covers disclosures overall, not just vulnerabilities attributed to AI. 23
28
29
A zero-day is a vulnerability exploited before a fix is available. An n-day is already known publicly, often with a patch available, but may remain exploitable on systems that have not been updated.
GTIG reported that average monthly zero-day exploitation rose from about eight in 2025 to about 11 from January through August 2026. That was a more modest increase than the rise in exploitation overall, which points to the importance of flaws beyond newly exploited zero-days—including known vulnerabilities that attackers can target after disclosure. These figures don’t establish what share of n-day exploitation was enabled by AI. 3
29
GTIG also reported a criminal actor with a zero-day exploit it believed was developed with AI. The actor planned a mass-exploitation campaign, but GTIG said its proactive discovery may have prevented the planned use. This is evidence of a specific AI-related development, not proof that AI was responsible for the broader rise in exploitation. 7
The software ecosystem used to develop and deploy large language models has itself become a target for exploitation, according to GTIG. Organizations should treat AI components and services as part of their production environment’s attack surface, while assessing individual vulnerabilities based on their exposure and evidence of exploitation. 1
For defenders: Triage vulnerabilities based on whether affected systems are exposed, the potential impact, and evidence of exploitation—not disclosure volume alone. Keep an inventory of internet-facing systems and AI software, apply available fixes promptly, and prepare monitoring and mitigations for vulnerabilities that are being exploited before a patch exists. For known flaws, reduce the time between disclosure and remediation. 3
8
9
For software vendors: Use AI-assisted testing alongside human review to find and validate flaws before release. Secure AI components as production software, and provide customers with timely fixes and actionable advisories so they can assess exposure and patch. GTIG’s findings support attention to both the volume of discoveries and the potential impact of the vulnerabilities being found. 4
8
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
From January to August 2026, monthly vulnerability disclosures rose from 5,045 to 10,740, while the monthly average of flaws exploited increased from 10.5 in 2025 to 18.
From January to August 2026, monthly vulnerability disclosures rose from 5,045 to 10,740, while the monthly average of flaws exploited increased from 10.5 in 2025 to 18. About 50% of vulnerabilities GTIG identified as likely AI discovered enabled remote code execution, compared with 26% of other vulnerabilities.
Zero day exploitation rose more modestly than overall exploitation, making timely assessment and patching of already known vulnerabilities important too.