Overview
- The findings, published at the end of September and start of October 2026, show monthly CVE disclosures roughly doubled in 2026 and the average number of distinct vulnerabilities observed exploited rose from 10.5 per month in 2025 to 18 per month in early 2026.
- Google’s Threat Intelligence Group found that vulnerabilities it labeled as likely discovered by AI were far more likely to enable remote code execution, 50% versus 26% for other findings.
- Microsoft reports that AI is compressing attack timelines so weaponization now often happens in well under 24 hours, and both companies say much of the recent rise in exploitation reflects rapid n‑day weaponization rather than a big surge in zero‑day discovery.
- Risk is concentrating on the network edge and AI infrastructure: GTIG tracked 2,076 AI‑related CVEs through August 2026 with orchestration frameworks and inference servers prominent, and edge/security appliances accounted for 14% of exploited bugs with over 65% of those rated high or critical.
- Both reports urge defenders to move from blanket patching to intelligence‑driven triage, to inventory AI orchestration and inference components, to harden exposed edge management interfaces, and to tighten identity controls such as phishing‑resistant multi‑factor authentication because unpatched, known flaws are likely to accumulate and be weaponized quickly.