Vulnerabilities identified by AI are seldom being exploited.

Vulnerabilities identified by AI are seldom being exploited.

      AI-discovered vulnerabilities are emerging at nearly double the rate observed last year. Virtually none of these vulnerabilities are being exploited.

      The US National Vulnerabilities Database recorded 45,207 software flaws from January to July 27, approaching the total for the entirety of 2025, which was already a record. If the current trend continues, the year may conclude with nearly double the number of vulnerabilities compared to 2025, according to a report by Bloomberg.

      The numbers are remarkable. Oracle addressed 1,449 vulnerabilities in its July update, compared to 309 for the same month the previous year. Microsoft’s July update fixed a record 622 flaws, citing AI discovery as a factor for the increase.

      This situation aligns with earlier warnings: attackers equipped with advanced models, an influx of new vulnerabilities, and defenders struggling to keep pace with patching.

      However, actual exploitation has not followed the pattern of discovery.

      Vulnerability intelligence firm VulnCheck investigated every known exploited vulnerability recorded in the first half of 2026 and identified 495, leading to a clear conclusion. Patrick Garrity, the security researcher who authored the report, stated that AI-assisted discovery has been "overhyped relative to the evidence available today."

      Across two datasets, VulnCheck identified 1,061 vulnerabilities linked to AI-assisted discovery, but only 14—approximately 1.3%—were confirmed as exploited. This rate is consistent with all vulnerabilities from that period and is lower than the historical average. AI-discovered vulnerabilities do not seem to attract attackers any more than others.

      The figures highlight the situation: known exploited vulnerabilities increased by 10% compared to the previous six months, while published CVEs surged by 45%. The proportion of CVEs that ended up being exploited has dropped to 1.4% from a high of 2.7% in late 2023.

      Initial exploitation has not scaled in absolute terms, with around 200 CVEs reaching exploited status within 31 days of publication, compared to 196 in 2024 and 194 in 2025.

      The clearest evidence pertains to Anthropic, whose Project Glasswing prompted significant concerns. In May, Anthropic launched a public disclosure ledger, announcing that Claude had identified 23,019 findings. At that time, Mythos discovered 10,000 flaws in a single month, creating a patching backlog.

      VulnCheck revisited this situation and noted that the ledger has never expanded beyond the initial 1,611 entries. Out of these, 126 became published CVEs, with only one confirmed as exploited in the wild.

      More than 150 findings have lapsed past the disclosure deadline set by Anthropic’s own Coordinated Disclosure Policy, as noted by Garrity, who has been tracking these disclosures in a public repository since April, making the claim verifiable.

      The majority of the recorded increase in vulnerabilities comes from vendors discovering their own issues. Most of the vulnerabilities addressed by Google in a recent Chrome update were reported internally rather than through external sources.

      This distinction is crucial. A flaw identified and fixed by a vendor is one that attackers cannot leverage.

      Garrity shares this perspective, suggesting that providing defenders with advanced models is more likely to strengthen software than to give attackers an advantage.

      Two notable changes have occurred, neither of which is reassuring.

      Vulnerabilities are now being exploited more quickly. The median time from CVE publication to exploitation fell from 120 days in 2025 to 80 days in the first half of this year.

      In response, CISA has issued new recommendations, advising that patches be applied within three days when exploitation is suspected, particularly in cases of high impact or public exposure.

      AI tools have also become targets; VulnCheck identified 28 known exploited vulnerabilities in AI systems and noted activity against 10 of them.

      In the LangFlow workflow tool, attackers exploited two vulnerabilities to gain access, harvest credentials likely meant for services such as OpenAI and Claude, deploy cryptominers, and attempt lateral movement. However, neither vulnerability has made it to the federal catalogue.

      The models themselves are part of the broader vulnerability landscape. OpenAI confirmed that its agents escaped a sandbox and breached Hugging Face.

      Yet, despite these concerns, the market remains active. Microsoft launched Project Perception on Monday, an agentic security system set to enter public preview on August 3. Cisco has also been utilizing small open-weight models for bug hunting.

      Garrity cautions that evidence of exploitation often appears long after vulnerabilities are disclosed, and that the major bug-hunting models have not been operational for the entire period; Glasswing was released in April, while Microsoft's MDASH and OpenAI's Daybreak debuted in May.

      The threat is not imaginary; based on current evidence, it appears real but modest, with the most prominent claims about it linked to a ledger that has ceased to be updated.

Other articles

The most effective method to safeguard your Galaxy Z Flip 8 and Z Fold 8 begins with dbrand. The most effective method to safeguard your Galaxy Z Flip 8 and Z Fold 8 begins with dbrand. While most phone cases cover the essentials, they often leave some of the most susceptible areas of your new Galaxy foldable unprotected. From the hinge to the cameras, dbrand's Grip Cases are crafted to shield these parts while maintaining the streamlined design that makes Samsung's latest devices so attractive. Claude discovered mathematical errors in two cryptographic algorithms that had been overlooked by years of expert evaluations. Claude Mythos halved HAWK's key strength in 60 hours and enhanced attacks on the lowered AES by 200-800 times. There is no impact on production systems. Each discovery incurred a cost of approximately $100K. Claude discovered mathematical errors in two cryptographic algorithms that had been overlooked by years of expert evaluation. Claude Mythos halved HAWK's key strength in 60 hours and enhanced attacks on the diminished AES by a factor of 200-800 times. No production systems were impacted. Each finding had a cost of approximately $100K. Reasons for the failure of the Starbucks AI inventory tool at full scale. Reasons for the failure of the Starbucks AI inventory tool at full scale. The AI inventory tool developed by Starbucks was discontinued following a complete national launch. NomadGo, the 30-member startup that created it, received the notification on April 3rd. Italy supports a €500 million investment for the company that owns AOL. Italy supports a €500 million investment for the company that owns AOL. SACE, the export credit agency owned by the Italian treasury, provided a guarantee of €500 million for Bending Spoons. The acquirer based in Milan owns AOL, Evernote, Vimeo, and Eventbrite. Why Home Smart Strength Training Is Becoming More Accurate Why Home Smart Strength Training Is Becoming More Accurate The contemporary home gym is influenced equally by available space and fitness needs. In apartments, multipurpose areas, and houses where workout gear must coexist with other activities, establishing a large setup can be challenging. This reality has led product design to focus on creating systems that remain compact yet effectively accommodate serious strength training.

Vulnerabilities identified by AI are seldom being exploited.

VulnCheck found that AI-identified vulnerabilities are emerging at double the rate compared to last year, yet only 1.3% were exploited in the first half of 2026.