Google: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation
Vulnerability disclosures continue to skyrocket, doubling over the course of the year to more than 10,000 each month, Google researchers warned.
Google's Threat Intelligence Group (GTIG) has found that monthly software vulnerability disclosures more than doubled between January and August, rising from 5,045 to 10,740. This surge in disclosures coincides with the increasing role artificial intelligence (AI) plays in identifying and exploiting vulnerabilities. Half of the vulnerabilities discovered by AI agents allow for remote code execution.
GTIG warns that raw totals may overstate the threat, as automated identifier assignment in open-source ecosystems inflates the numbers. Flaws related to the Linux Kernel accounted for about 5,000 records, but no zero-days were exploited in the wild. High-risk disclosures rose 167% to 350 in August, with 128 of those stemming from Oracle Corp.'s quarterly patch releases and Linux kernel network driver advisories.
Despite the increase in disclosed vulnerabilities, attackers have only exploited 141 in the wild, a rate of about one in 431. Zero-day exploitation averaged 11 per month, with August seeing 22. Most of the growth in exploited flaws comes from n-days, where flaws are targeted once they are public and often already patched. AI's discovery of vulnerabilities is growing, with 58% of the AI-discovered flaws falling in the moderate risk tier.
Researchers tend to focus on critical infrastructure and sensitive privilege boundaries, explaining the gap in AI-discovered vulnerabilities compared to human-discovered ones. A notable example of an AI-discovered flaw exploited in the wild is CVE-2026-1731, which allows an unauthenticated attacker to inject operating system commands into BeyondTrust Corp.'s Privileged Remote Access and Remote Support products.
The report suggests that organizations should prioritize threat intelligence in deciding which vulnerabilities to address first and recommends running agentic AI code reviews before deployment.
Written by urgent.news from SiliconANGLE's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.