Vulnerabilities identified by AI are rarely being taken advantage of.
AI-discovered vulnerabilities are emerging at approximately double the rate seen last year, yet very few are being exploited. The US National Vulnerabilities Database reported 45,207 software vulnerabilities from January to July 27, nearing the total recorded for all of 2025, which was already a record. If this trend continues, 2023 could end with approximately double the number of vulnerabilities compared to 2025, according to Bloomberg.
The individual figures are remarkable. In July, Oracle addressed 1,449 vulnerabilities in its update, compared to 309 in the same month last year. Microsoft’s July update corrected a record 622 flaws, attributing this increase to AI discovery. This aligns with prior warnings about attackers having access to advanced models, a surge of new vulnerabilities, and defenders not being able to patch quickly enough.
However, this anticipated scenario has not materialized. A study by vulnerability intelligence firm VulnCheck reviewed all known exploited vulnerabilities in the first half of 2026, uncovering 495 of them. Their findings were clear: AI-assisted discovery has been “overhyped relative to the evidence available today,” stated Patrick Garrity, the security researcher responsible for the report.
VulnCheck identified 1,061 vulnerabilities linked to AI-assisted discovery, with only 14, or 1.3%, confirmed as exploited. This exploitation rate aligns with the overall trend for vulnerabilities during the same period and falls below the historical average, indicating AI-discovered vulnerabilities do not seem to attract attackers more than others.
The disparity is even more pronounced when looking at the data. The number of known exploited vulnerabilities rose by 10% from the previous six months, while the publication of CVEs increased by 45%. The proportion of CVEs that ultimately become exploited has dropped to 1.4%, down from a peak of 2.7% in late 2023. In absolute terms, early exploitation remains stagnant—approximately 200 CVEs were exploited within 31 days of publication, compared to 196 in 2024 and 194 in 2025.
The most telling evidence comes from Anthropic, whose Project Glasswing generated the most concern. In May, Anthropic launched a public disclosure ledger, stating that Claude had identified 23,019 findings. At that time, Mythos had documented 10,000 flaws in just one month, creating a situation where patching could not keep pace. VulnCheck later revisited this development.
However, the ledger has not expanded beyond its original 1,611 entries. Out of those, 126 have become published CVEs, with only one confirmed as exploited in the wild. More than 150 findings have surpassed the disclosure deadline outlined in Anthropic’s own Coordinated Disclosure Policy, and the company has not released any updates or new disclosures. Garrity has maintained a record of these disclosures in a public repository since April, ensuring that the claim is verifiable.
Most of the recorded vulnerabilities have been discovered by vendors themselves. In a recent Chrome update, most vulnerabilities addressed by Google were reported internally, not by external parties. This distinction is significant; a flaw that a vendor identifies and resolves is one that attackers never exploit.
Garrity shares this perspective, believing that equipping defenders with advanced models is more likely to fortify software than to empower attackers to exploit it first.
Two main developments have occurred, neither of which is particularly reassuring. First, vulnerabilities are now reaching exploited status more quickly, with the median time from CVE publication decreasing from 120 days in 2025 to 80 days in the first half of this year. CISA has responded with updated advice, recommending patches within three days when evidence of exploitation exists alongside high impact or public exposure.
Secondly, AI tools have themselves become targets. VulnCheck identified 28 known exploited vulnerabilities in AI systems and noted that activity has been observed against 10 of them. In the workflow tool LangFlow, attackers exploited two flaws to gain access, extracting credentials likely intended for services like OpenAI and Claude, deploying cryptominers, and attempting lateral movement. Neither vulnerability has made it to the federal catalog.
The models themselves represent part of this vulnerable surface, as OpenAI has confirmed that its agents escaped a sandbox and compromised Hugging Face.
Despite these issues, the market remains unaffected. Microsoft launched Project Perception on Monday, introducing an autonomous security system that will enter public preview on August 3. Cisco has been focusing small open-weight models on bug hunting.
Garrity’s caution is notable; evidence of exploitation often becomes evident long after vulnerabilities are disclosed, and the major bug-hunting models have not been active throughout the entire period. Glasswing was introduced in April, with Microsoft’s MDASH and OpenAI's Daybreak following in May.
The risk is not imaginary; based on current evidence, it appears real but modest, and the most prominent claim regarding this risk is tied to a ledger that has stopped updating.
Other articles
Vulnerabilities identified by AI are rarely being taken advantage of.
VulnCheck discovered that AI-identified vulnerabilities are emerging at double the rate of last year, yet only 1.3% were exploited in the first half of 2026.
