Google's Threat Intelligence Group (GTIG) has reported a significant surge in vulnerability disclosures, with monthly totals more than doubling from January to August of this year. The number of disclosures climbed from 5,045 in January to over 10,000 in both July and August, peaking at 10,740 last month. This increase is attributed by GTIG researchers to the growing influence of artificial intelligence in both vulnerability discovery and exploitation.
Beyond the sheer volume of disclosures, GTIG noted that the number of distinct vulnerabilities exploited in the first eight months of 2026 has already surpassed the total for all of 2025. There have been 141 exploited vulnerabilities this year, compared to 127 last year. The group emphasized that this rise in exploitation is primarily driven by the rapid, targeted weaponization of known, high-risk vulnerabilities (n-days) rather than a proliferation of zero-day exploits.
Researchers suggest that threat actors are leveraging large language models (LLMs) and other AI tools to automate the analysis of differences between product versions, patches, public vulnerability disclosures, and proof-of-concept (POC) code. This allows them to quickly weaponize n-days, making it a more accessible and efficient approach than discovering new zero-days.
As an illustration, Google highlighted CVE-2026-1731, a vulnerability in BeyondTrust software that federal cyber defenders flagged in February. This flaw was autonomously discovered by a third-party research agent named Hacktron AI. Following its public disclosure, GTIG observed multiple threat clusters exploiting this vulnerability in targeted initial-access campaigns to bypass enterprise perimeters. Within four days of disclosure, one threat cluster was observed exploiting it, followed by five more within seven days. These actors engaged in post-exploitation activities such as privilege escalation, data exfiltration, and deploying secondary payloads like SNOWLIGHT, SPARKRAT, and cryptominers. This case demonstrates the formidable capacity of autonomous research agents to uncover high-severity flaws when directed at critical attack surfaces.
AI agents are predominantly being used to find medium and high-risk vulnerabilities. GTIG classifies a bug as high-risk if its exploitation would have a notable, direct impact on the security of targeted devices and networks without requiring significant mitigating factors, and if exploitation is expected to be highly reliable and scalable.
Many of the disclosures this year have originated from a limited number of vendors, including router firmware company Totolink and Oracle. Threat actors continue to concentrate their exploitation efforts on perimeter appliances and exposed enterprise services; 14% of vulnerabilities exploited between January and August affected edge and security appliances.
These findings align with recent reports from the Cybersecurity and Infrastructure Security Agency (CISA), which indicated that over 67,000 new CVEs have been published in 2026, with projections for a total of 96,000 by year-end. The National Institute of Standards and Technology’s National Vulnerability Database program also reported a 263% increase in annual CVE submissions between 2020 and 2025, with submissions in the first three months of 2026 being one-third higher than the same period in 2025. GTIG anticipates that AI-assisted vulnerability discovery and exploitation will continue to grow in the short to medium term.






