Likely AI-found flaws that enabled RCE (other CVEs: 26%): 50% (Source: Google Threat Intelligence Group, via Infosecurity Magazine (September 30, 2026))
Think of a vulnerability notice as the moment an attacker's timer starts. Every day a fix sits unapplied is a day the attacker keeps. That is our argument, not something the research measured. Google's new report does offer one case that fits it. Attacks on that flaw began within four days of disclosure.
Google Threat Intelligence Group (GTIG) published its findings on September 30. Infosecurity Magazine covered them the same day. The headline number is about severity. The finding executives can act on is about time: one case shows how fast attackers can move.
What Google found
GTIG picked out a set of flaws it judged likely to have been found with AI help. Half of them allowed remote code execution (RCE). Among other CVEs, the figure was 26%. RCE means an attacker can run their own commands on a system from a distance.
Volume rose as well. Monthly disclosures stood at 5,045 in January and 10,477 in July. August came in at 10,740. Exploited flaws averaged 18 a month so far in 2026, against 10.5 a month in 2025.
Where the extra exploitation came from
Zero-days are flaws attacked before any fix exists. They rose only from eight to 11 a month. In August they reached 22.
GTIG suggests most of the growth came from n-days rather than zero-days. An n-day is a flaw that is already public, usually with a patch on offer. Attackers who move quickly can hit organisations that have not yet applied it. GTIG says AI tools that study patches and proof-of-concept code may be helping. That is a suggestion, not a measured result.
Google gives one example: CVE-2026-1731, a bug in two BeyondTrust products, Privileged Remote Access and Remote Support. It is a command injection flaw. An attacker needs no login to slip in commands that the system then runs. Hacktron AI found the flaw autonomously. One threat cluster attacked it within four days of disclosure. Five more clusters followed within seven days.
What the numbers do not say
GTIG calls confirmed exploitation of AI-found flaws an early indicator, not an established trend. The four-day case is one case. The coverage we reviewed gives no earlier disclosure-to-attack gap to compare it with.
The severity skew may also reflect human choices. Google says it likely comes largely from how researchers use autonomous agents. They tend to aim them at critical infrastructure instead of scanning broadly. Google adds that public data probably undercounts AI-found flaws. So the 50% describes disclosed flaws, not how AI behaves by nature.
GTIG used its own risk ratings, not CVSS scores. For January to August, 58% of likely AI-found flaws were medium risk, against 28% of the rest. Low risk was the reverse: 39% of the AI group and 69% of the rest.
Where exposure gathers
Attacks still clustered at the network perimeter. Edge and security devices were 14% of exploited flaws in 2026. GTIG rated more than 65% of those edge flaws high or critical.
GTIG also counted over 1,500 flaws in AI software disclosed this year. Of these, 782 were in agent orchestration frameworks, the tools that coordinate AI agents. Another 212 were in inference and serving systems, which run the models. About one in four of those 212 involved APIs with no login, or server-side request forgery. That is a trick that makes a server send requests on an attacker's behalf.
GTIG has confirmed exploitation for only a few of these AI-software flaws. It has not yet seen a zero-day attack on AI infrastructure.
A separate item in the same coverage concerns Citrix NetScaler. Citrix fixed two exploited zero-days, and GTIG and Mandiant have tracked one in active attacks. The source does not link this to AI-found flaws. It does show a different risk. Mandiant CTO Charles Carmakal wrote on LinkedIn on September 27 that customers should check for compromise before patching. His words: "Patching alone may not eradicate the threat actor from your environment."
Questions to put to your team
Treat patch speed as time given to an attacker, not only a hygiene score. Executives can ask four things.
First, how many days pass between a vendor advisory and a fix on our internet-facing appliances? Second, when a flaw is already under attack, do we check for intruders before we patch? Third, which AI agent frameworks and model-serving tools do we run, and can any of their APIs be reached without a login? Fourth, who decides to act on a vendor notice outside business hours?
The research does not show that AI has broken defence. It shows more exploitation, a higher share of severe flaws among likely AI finds, and one case of a fast attack. A rehearsed, shorter response is the sensible answer. A bigger pile of alerts is not.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Infosecurity Magazine.





