AI-Driven Vulnerability Discovery Accelerates at Alarming Rate
A new report from Google's Threat Intelligence Group (GTIG) reveals that AI is significantly changing the pace and profile of vulnerability discovery. The number of vulnerabilities disclosed each month doubled in 2026, with a monthly average of exploited vulnerabilities nearly doubling as well.
Between January 2025 and August 2026, GTIG analyzed disclosures and found that monthly disclosures rose from 5,045 in January 2026 to 10,740 in August. The researchers also discovered that high-risk disclosures grew by 167%, from 131 in January to 350 in August.
GTIG suggests that the growth in exploitation came primarily from n-days, with exploitation of high-risk vulnerabilities more than doubling, from 28 in 2025 to 75 in the first eight months of 2026. The report also found that AI-discovered vulnerabilities had a different risk profile, with 39% being rated low-risk and 58% medium-risk.
The researchers caution that raw volume can be misleading, as automated CVE assignment in open source ecosystems can inflate the numbers. GTIG has confirmed in-the-wild exploitation of AI-discovered vulnerabilities, though it describes this as an early indicator rather than an established trend.