Particle.news

AI-Driven Vulnerability Discovery Doubles Reports and Raises RCE Risk

Google's threat team says the shift in what AI finds signals faster weaponization of known flaws that will raise short-term risk.

Overview

  • GTIG's September 30, 2026 report found monthly vulnerability disclosures doubled in 2026, climbing from about 5,045 in January to a peak of 10,740 in August, and that the monthly average of vulnerabilities exploited in the wild rose from about 10.5 in 2025 to roughly 18 in the first eight months of 2026.
  • Half of vulnerabilities GTIG judged likely found with AI resulted in remote code execution, compared with 26% for non-AI discoveries, and AI-linked flaws skewed toward GTIG's medium-risk rating rather than low risk.
  • GTIG says much of the rise in exploitation stems from rapid weaponization of n-day flaws, and it warns threat actors may be using LLMs and other AI tools to speed analysis of patches, diffs, and proof‑of‑concept code.
  • The report highlights fast real-world follow-up on AI-found bugs, noting that Hacktron AI autonomously found CVE-2026-1731 in BeyondTrust and that one threat cluster exploited it within four days and several more followed within a week.
  • AI orchestration frameworks and edge devices concentrate the risk: GTIG tracked 2,076 AI-related CVEs since January 2025, with roughly half affecting orchestration tools, and it urges organizations to use threat-intelligence triage and check for compromises rather than rely only on patching.