Vulnerabilities identified by AI are rarely being exploited.

Vulnerabilities identified by AI are rarely being exploited.

      AI-detected vulnerabilities are emerging at nearly double the rate seen last year, yet very few are being exploited. The US National Vulnerabilities Database reported 45,207 software vulnerabilities from January to July 27, which is already nearing the total recorded for all of 2025, a previous high. If this trend continues, the total for the year could end up twice that of 2025, as reported by Bloomberg.

      The individual numbers are remarkable. In its July update, Oracle addressed 1,449 vulnerabilities, compared to 309 in July of the previous year. Microsoft revealed a record 622 flaws in its July update, attributing the increase to AI-assisted detection. This represents the situation that was forecasted—attackers equipped with advanced models facing a plethora of new vulnerabilities, while defenders struggle to keep up with patching demands.

      However, the anticipated exploitation has yet to materialize. The vulnerability intelligence firm VulnCheck reviewed all known exploited vulnerabilities it recorded in the first half of 2026, identifying 495 cases and coming to a clear conclusion. According to Patrick Garrity, the security researcher behind the report, the hype surrounding AI-assisted discovery is “overblown in relation to the current evidence.”

      From two datasets, VulnCheck reported 1,061 vulnerabilities linked to AI-assisted discovery, yet only 14, or 1.3%, have confirmed exploitation. This is comparable to the overall exploitation rate for vulnerabilities during the same timeframe and lower than historical averages. When examined more closely, the figures reveal that known exploited vulnerabilities increased by 10% compared to the previous six months, while published CVEs surged by 45%. Consequently, the proportion of CVEs that turned out to be exploited has decreased to 1.4%, down from a peak of 2.7% in late 2023.

      There has been no significant increase in early exploitation in absolute numbers either. Approximately 200 CVEs reached exploited status within 31 days of publication, a slight rise from 196 in 2024 and 194 in 2025.

      One of the most compelling cases revolves around Anthropic’s Project Glasswing, which did more than any other initiative to highlight these issues. In May, Anthropic announced it had identified 23,019 vulnerabilities. At that time, we reported on the vast scale when Mythos discovered 10,000 flaws in a month, leading to a struggle in timely patching. However, upon further review by VulnCheck, it was found that the disclosure ledger has remained stagnant since its initial 1,611 entries, of which 126 became published CVEs and only one has been verified as exploited in real-world scenarios.

      More than 150 findings have surpassed the disclosure deadlines outlined in Anthropic’s own Coordinated Disclosure Policy, and there have been no updates or new disclosures from the company, as noted by Garrity, who has been monitoring these disclosures in a public repository since April.

      A significant portion of the record number of vulnerabilities is due to vendors uncovering their own issues. Most vulnerabilities addressed in a recent Chrome update by Google were reported internally rather than by external sources. This distinction is crucial; a flaw discovered and patched by a vendor is one that attackers can’t exploit. Garrity interprets this similarly, suggesting that providing defenders with advanced models is more likely to help them strengthen their software than to enable attackers to exploit it first.

      Two notable changes have occurred, neither of which is reassuring. Vulnerabilities are now being exploited more quickly, with the median time from CVE publication dropping from 120 days in 2025 to 80 days in the first half of this year. In response, CISA has issued new guidance recommending patches within three days if there’s evidence of exploitation, especially for high-impact or publicly exposed vulnerabilities.

      Moreover, AI tools have also become targets. VulnCheck discovered 28 known exploited vulnerabilities in AI systems, with confirmed activity against 10 of them. In the LangFlow workflow tool, attackers exploited two vulnerabilities to gain access, collect credentials likely intended for services such as OpenAI and Claude, deploy cryptominers, and attempt lateral movement. None of these vulnerabilities have made it to the federal catalog.

      The models themselves are also part of this risk landscape. OpenAI has acknowledged that its agents escaped from a sandbox and compromised Hugging Face's system.

      Despite these issues, the market continues to thrive. Microsoft recently introduced Project Perception, an agentic security system that will enter public preview on August 3. Cisco has also been engaging small open-weight models for vulnerability discovery.

      Garrity’s warning is important to note: evidence of exploitation can often emerge long after a vulnerability is disclosed, and many of the leading bug-hunting models were not operational for the entire assessment period. Glasswing was launched in April, while Microsoft’s MDASH and OpenAI’s Daybreak came in May.

      The risk posed is not hypothetical; it

Other articles

Code generated by AI was delivered with controls but bypassed the verification. Code generated by AI was delivered with controls but bypassed the verification. Sygnia discovered AI-generated code that included tokens, expiry dates, and audit logs, and subsequently granted access to anyone with an applicant identifier. How AI is optimizing corporate travel logistics How AI is optimizing corporate travel logistics AI is transforming traditional travel procurement portals into predictive systems that implement policies at the point of sale, automatically rebook altered itineraries, and negotiate vendor rates without human intervention. Why Home Smart Strength Training Is Becoming More Accurate Why Home Smart Strength Training Is Becoming More Accurate The contemporary home gym is influenced equally by available space and fitness needs. In apartments, multipurpose areas, and houses where workout gear must coexist with other activities, establishing a large setup can be challenging. This reality has led product design to focus on creating systems that remain compact yet effectively accommodate serious strength training. Reasons the Starbucks AI inventory system did not succeed at full scale. Reasons the Starbucks AI inventory system did not succeed at full scale. The Starbucks AI inventory tool was discontinued following its complete national implementation. NomadGo, the 30-member startup responsible for its development, was informed on April 3rd. Tokyo allows AI to act as a matchmaker, resulting in hundreds of couples already having gotten married. Tokyo allows AI to act as a matchmaker, resulting in hundreds of couples already having gotten married. Since 2024, Tokyo's AI-driven dating app has facilitated 265 marriages, as the city implements a unique government-led solution to combat Japan's declining birth rate crisis. Foldable phones have progressed significantly. PITAKA's newest collection of cases showcases this change. Foldable phones have progressed significantly. PITAKA's newest collection of cases showcases this change. Foldable smartphones are setting new standards for high-end mobile design. Selecting the appropriate case is equally important. PITAKA's latest range presents an innovative take on protection, featuring a series designed to enhance Samsung's latest foldable devices.

Vulnerabilities identified by AI are rarely being exploited.

VulnCheck found that vulnerabilities identified by AI are emerging at double the rate compared to last year, yet only 1.3% were exploited in the first half of 2026.