Disclosure Doubled and Exploitation Followed: What GTIG's AI-Era Data Actually Shows
Google Threat Intelligence Group's first full dataset on vulnerabilities in the AI era reports monthly disclosures more than doubling — from 5,045 in January 2026 to 10,740 in August — while
TL;DR
- Google Threat Intelligence Group published its first full dataset on how AI is changing the vulnerability landscape, and the headline number is a doubling: 5,045 vulnerabilities disclosed in January 2026 became 10,740 in August.
- The exploited share stayed vanishingly small — 0.23% of disclosed vulnerabilities, roughly 1 in 431 — and GTIG is explicit that raw disclosure volume is inflated by automated CNA assignment, with about 5,000 "Linux Kernel"-described CVEs carrying zero observed exploited zero-days.
- The risk concentrates in the exploited slice: 62% of exploited vulnerabilities are zero-days, and High-Risk exploitation more than doubled from 28 in 2025 to 75 in January–August 2026.
- AI-assisted discovery finds different flaws, and the exploit market follows: 50% of AI-discovered vulnerabilities lead to remote code execution, versus 26% across the wider ecosystem, and AI findings skew away from low-risk noise.
- The practical takeaway for any team: mass-patching every disclosure is no longer a strategy — triage against threat intelligence is the only control point that scales.
The number to argue with: 1 in 431
The dataset's most important sentence is not the doubling headline; it is the denominator. GTIG recorded 141 distinct vulnerabilities disclosed and exploited in January–August 2026 — a record that already surpassed the full-year 2025 total of 127 — yet that remains 0.23% of all disclosures, "roughly 1 in 431." Every week brings thousands of new CVEs; attackers actually touch tens.

That gap is the whole case for intelligence-driven triage, and GTIG makes the inflation explicit so nobody misreads the raw curve. "However, raw disclosure volume throughout 2026 can be misleading without threat intelligence context. Automated CNA Numbering Authority (CNA) assignment policies across open-source ecosystems can inflate baseline figures" — the example is stark: vulnerabilities with a description containing "Linux Kernel" alone generated approximately 5,000 CVEs between January and August 2026 with zero observed exploited in-the-wild zero-days. If you patch by volume, you are working off a curve that the vendors' own numbering process inflates.
The risk-rating view sharpens the same point. High-Risk disclosures surged from 131 in January 2026 to 350 in August — a 167% growth — yet they remain 3% of all disclosures. Two dynamics drove that peak: TOTOLINK mass research disclosures on consumer router firmware (75 High-Risk flaws in April–May, driving the Command Execution spike) and Oracle's quarterly CPU plus Linux kernel network driver advisories (128 High-Risk in August alone, nearly 37% of the month's High-Risk total). The disclosed universe is big and mostly noise; the High-Risk slice is small and actionable.
The exploited slice concentrates upward
Exploitation grew an average of 10.5 per month in 2025 to 18 per month in January–August 2026, and GTIG's composition analysis says where the growth really lives: "the primary source of growth in vulnerability exploitation from January 2026 to August 2026 has been concentrated in the rapid weaponization of n-days." Zero-day exploitation rose only marginally — 8 per month to 11, with a spike to 22 in August — while High-Risk exploitation more than doubled from 28 in 2025 to 75 from January to August 2026.

The zero-day share still dominates the exploited slice at 62%, which on its face is counterintuitive: n-day exploitation grew faster, but zero-days remain the majority of what is actually seen in the wild. And since May 2026 the two curves have moved together — exploitation growth (+127% indexed) mirrors disclosure growth (+128% indexed) — "scaling in tandem with the overall vulnerability landscape rather than outpacing it."
That ratio flips the usual threat-model instinct. The growth comes from the rapid weaponization of already-disclosed flaws, which GTIG hypothesizes is becoming cheaper precisely because of AI: "threat actors are finding it more accessible or efficient to use LLMs and AI tools to automate analysis of differences between product versions, patches, vulnerability disclosure announcements, and Proof-of-Concept (POC) code to rapidly weaponize n-days, rather than to discover new zero-days." N-day exploitation is a diffing-and-packaging problem now, and that is a labor category AI compresses hard.
AI finds different flaws, and the market follows
The dataset's third finding is the one most directly about the future of the field: AI-assisted discovery finds more vulnerabilities, and a different profile of them. Across the vulnerabilities GTIG could identify as likely AI-discovered, Low-Risk findings drop to 39% versus 69% for conventional discovery, Medium rises to 58% versus 28%, and — the striking number — exactly 50% of AI-discovered vulnerabilities result in remote code execution, compared to 26% across the broader ecosystem.

GTIG's explanation is structural: AI agents are engineered to navigate complex multi-step semantic code paths in core C/C++ libraries, runtimes and hypervisors, taking aim at memory corruption and logic flaws. In GTIG's own framing, "AI models excel at identifying memory corruption (buffer overflows, use-after-free) and logic bypasses that consistently elude traditional static analyzers." In other words, the automation is being aimed at the flaw classes that actually lead to RCE, which is where the money is. The warning embedded in the finding is CVE-2026-1731, an unauthenticated OS command injection in BeyondTrust Privileged Remote Access discovered autonomously by a third-party research agent: within four days of disclosure a threat cluster was exploiting it, and seven days in, five additional clusters were running post-exploitation that included privilege escalation, data exfiltration, and secondary payloads like SNOWLIGHT, SPARKRAT and cryptominers.
The uncomfortable loop is closed when you add GTIG's numbers on vulnerabilities targeting the AI stack: 2,076 cumulative AI-related CVE disclosures across the January 2025–August 2026 window, over 1,500 of them in 2026 alone, concentrated in orchestration frameworks (782, half of all AI-related flaws, a +347% surge) and inference/serving infrastructure (212). The same technology driving faster, higher-severity discovery is itself the fastest-growing attack surface — a two-front exposure that GTIG explicitly warns maps to "the exact types of flaws that sophisticated adversaries actively seek to exploit."

Where triage has to live now
The defensive prescription writes itself out of the dataset: triage by exploitation risk, ahead of patch volume. With 10,740 disclosures in a single month and an exploited share of 0.23%, no team can patch by volume; the control point is triage against threat intelligence, combined with targeted edge defense and automated remediation where the data says the risk concentrates. GTIG's own recommendation is to move "from unprioritized mass-patching to threat-intelligence-driven triage, combining targeted edge-defense with automated, agentic remediation," and to run pre-release AI code review internally so flaws are fixed before they enter the disclosed universe at all.
The edge-appliance numbers give the triage a concrete starting point. Vulnerabilities in Edge and Security Appliances were 14% of what was exploited, and over 65% of exploited edge flaws met High/Critical threat-risk ratings, with adversaries "aggressively targeting unauthenticated public management interfaces." If you are choosing where to spend the next hour, that is the slice: the perimeter appliances that combine high severity with unauthenticated reachability — the same management-plane lesson this blog drew from the NVIDIA Infrastructure Controller disclosure, now backed by aggregate data instead of a single advisory.

The dataset's honest limits matter as much as its findings, and GTIG states them: public CVE repositories still lack uniform AI-attribution metadata, so the AI-discovery figures are partial, and "confirmed exploitation of AI-discovered vulnerabilities demonstrates that increased risk from AI-discovered flaws is not purely theoretical" as an early indicator, not an established trend. Treat the 50% RCE figure as a directional signal. The direction, though, is consistent across every table in the post: volumes inflate, the exploited slice concentrates upward, and the flaw classes AI finds are the ones attackers already hunt. That is the triage map for the next year.
Sources
Source: Vulnerability Discovery and Exploitation Trends in the AI Era — Google Threat Intelligence Group, Google Cloud Blog (cloud.google.com/blog/topics/threat-intelligence), 2026-09-30 (all disclosure, exploitation, zero-day, risk-rating, AI-discovery and AI-stack statistics quoted verbatim; official GTIG figures downloaded and verified). Internal linkage: NVIDIA Infrastructure Controller hard-coded credentials. More security engineering analysis on neticslabs.com.
Source: Google Threat Intelligence Group via Google Cloud Blog, 2026-09-30. Figures: official GTIG figures (Google Cloud Blog), downloaded 2026-10-02.