Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

therecord+1siliconangletherecordThe number of software vulnerabilities disclosed each month doubled between January and August 2026, Google's Threat Intelligence Group (GTIG) said Wednesday. The group says artificial intelligence is speeding up the discovery of flaws and changing which kinds get found.therecord+1
Monthly disclosures went from 5,045 in January to more than 10,000 in July and reached a new high of 10,740 in August. "We found that AI is measurably changing not just the pace of vulnerability discovery and exploitation, but also the types and typical risk profiles of vulnerabilities that are being discovered," the researchers wrote. Google is a unit of Alphabet .siliconangle+1
GTIG said the raw totals can make the threat look bigger than it is, because open-source ecosystems assign identifiers automatically. Flaws with "Linux Kernel" in their descriptions made up about 5,000 records this year, and none of them produced a zero-day exploited in the wild. Attackers exploited 141 newly disclosed vulnerabilities from January through August, compared with 127 in all of 2025. That works out to about one exploited flaw for every 431 disclosed.siliconangle
The report said the rise in exploitation "is driven by the rapid, targeted weaponization of high-risk exploits in the wild rather than a flood of new zero-days". Zero-days averaged 11 a month this year, up from eight in 2025, and August had 22. Much of the growth came from n-days, which are flaws that are already public and usually already patched. Researchers suggested attackers may be using large language models to compare patches and product versions so they can build working exploits faster. About 14% of the flaws exploited this year were in edge and security appliances.therecord+1
GTIG said AI agents have turned up proportionally fewer low-risk flaws and more medium- and high-risk ones. Of the likely AI discoveries, 58% fell in the moderate tier of Google's risk scale, and about half allowed remote code execution. Among all other disclosures, remote code execution showed up in 26%. As an example, Google pointed to CVE-2026-1731, a flaw in BeyondTrust software found on its own by an agent from Hacktron AI. One threat cluster was exploiting it within four days of disclosure, and five more joined within a week.cloud.google+2
Flaws in AI software are also increasing. GTIG has tracked 2,076 of them since early 2025, and more than 1,500 were disclosed this year. Orchestration frameworks such as Flowise and Langflow account for about half.siliconangle
GTIG told organizations to stop patching everything without priorities and to use threat intelligence to decide what to fix first. It said software vendors should run agentic AI code review before shipping code and named Google's own CodeMender as one option. If that becomes common practice, growth in public disclosures could eventually slow, the group said. Kelli Vanderlee, a senior analyst at GTIG, said she expects AI-assisted discovery and exploitation to keep growing in the short to medium term.therecord+1