Vulnerability Disclosure Reaches Critical Levels

Monthly CVE disclosures have doubled in 2026, rising from 5,045 in January to 10,740 in August, according to the Google Threat Intelligence Group (GTIG). Yet despite this explosive growth, only 0.23% of vulnerabilities disclosed in 2026—approximately 1 in 431—were observed exploited in the wild.

GTIG recorded 141 distinct exploited vulnerabilities between January and August 2026, already exceeding the 127 exploited across all of 2025. Zero-day exploitation has also accelerated, growing from an average of 8 per month in 2025 to 11 per month in 2026. Exploitation of GTIG-rated High Risk vulnerabilities surged from 28 in 2025 to 75 in the first eight months of 2026.

AI-Discovered Vulnerabilities Show Higher Severity

Vulnerabilities identified as likely discovered by AI present a markedly different risk profile. Half of AI-discovered vulnerabilities lead to remote code execution, compared to 26% for vulnerabilities found by non-AI means.

Risk ratings also diverge sharply. Of AI-discovered vulnerabilities, 39% were rated Low Risk and 58% Medium Risk by GTIG. In contrast, 69% of non-AI-discovered vulnerabilities were rated Low Risk and 28% Medium Risk. This suggests AI discovery tools are identifying more severe flaws that traditional methods may miss.

CVE records currently have no standard tag for AI attribution, causing public data to undercount AI-discovered vulnerabilities.

BeyondTrust Flaw Shows Rapid Exploitation Timeline

CVE-2026-1731, an unauthenticated OS command injection vulnerability in BeyondTrust Privileged Remote Access and Remote Support discovered by the Hacktron AI research agent, demonstrates how quickly critical flaws are weaponised. One threat cluster exploited the vulnerability within four days of public disclosure, with five additional threat clusters exploiting it within seven days.

Attackers exploiting CVE-2026-1731 escalated privileges, exfiltrated data, and dropped payloads including SNOWLIGHT, SPARKRAT, and cryptominers.

AI Software Vulnerability Ecosystem Under Pressure

GTIG tracked 2,076 vulnerabilities in AI-related software between January 2025 and August 2026, with over 1,500 disclosed in 2026 alone. Half of 2026’s AI-software vulnerability disclosures affect agent orchestration frameworks, specifically Flowise and Langflow.

Inference and serving software including vLLM, Ollama, and LiteLLM had 212 vulnerabilities disclosed in 2026. CVE-2026-42271, a command injection flaw in LiteLLM that leads to host takeover and API credential theft, has been confirmed exploited in the wild by CISA. Langflow has been affected by multiple critical flaws confirmed exploited in the wild: CVE-2026-5027, which allows file writes to the host, and CVE-2025-3248, which permits remote code execution.

GitLab Patches AI Gateway Flaw

GitLab patched a critical severity 9.9-rated flaw in its AI Gateway that could allow a logged-in user with Duo Agent Platform access to run commands on the gateway.

Outlook

GTIG expects vulnerability discovery and exploitation to keep rising in the short to medium term.


Source: Help Net Security