Threat actors are rapidly exploiting vulnerabilities discovered by artificial intelligence research agents, often within days of public disclosure, according to new research from Google Threat Intelligence Group (GTIG). The group's analysis, covering January 2025 to August 2026, indicates a significant increase in overall vulnerability exploitation, particularly for "n-day" flaws.
Monthly CVE disclosures more than doubled in 2026, from 5,045 in January to 10,740 in August. While only a small fraction of these are observed exploited in the wild (0.23% or about one in 431), the total number of exploited vulnerabilities rose from 127 in all of 2025 to 141 in the first eight months of 2026. Zero-day exploitation also increased, from an average of 8 per month in 2025 to 11 per month in 2026. GTIG suggests that the majority of this growth in exploitation stems from n-day vulnerabilities, possibly due to threat actors leveraging large language models and AI tools to quickly analyze patches, disclosure announcements, and proof-of-concept code for weaponization.
Vulnerabilities identified as likely discovered by AI agents are often more severe. Half of these AI-found flaws lead to remote code execution, compared to 26% of vulnerabilities discovered through other means. AI-discovered vulnerabilities are also less frequently rated as low risk, with 39% being low risk and 58% medium risk, whereas vulnerabilities found by other methods were 69% low risk and 28% medium risk. This trend likely reflects how research programs scope and deploy AI systems, often tasking them with auditing critical infrastructure and sensitive privilege boundaries.
GTIG noted that public data likely undercounts AI-discovered vulnerabilities because CVE records lack a standard tag for AI attribution, and cloud and SaaS providers often fix AI-found flaws in production without requesting CVE IDs.
A notable example of rapid exploitation involved CVE-2026-1731, an unauthenticated OS command injection vulnerability in BeyondTrust Privileged Remote Access and Remote Support. This flaw, discovered by the Hacktron AI research agent, was exploited by one threat cluster within four days of its public disclosure, and by five additional clusters within seven days. Attackers used it in targeted initial-access campaigns to escalate privileges, exfiltrate data, and deploy payloads such as SNOWLIGHT, SPARKRAT, and cryptominers.
The research also highlighted a growing number of vulnerabilities in AI-related software itself. Between January 2025 and August 2026, GTIG tracked 2,076 such vulnerabilities, with over 1,500 disclosed in 2026 alone. Half of this year's disclosures affect AI agent orchestration frameworks like Flowise and Langflow, where attackers exploit code execution nodes via prompt injection or crafted workflow JSONs.
Inference and serving software, including vLLM, Ollama, and LiteLLM, saw 212 vulnerabilities disclosed in 2026. Nearly a quarter of these vulnerabilities originate from unauthenticated API endpoints or server-side request forgery, which can enable attackers to bypass perimeter firewalls, consume GPU resources, or extract model checkpoints. Compromised enterprise AI gateways risk exposing third-party API keys and private prompt streams containing personally identifiable information or proprietary source code.
While only a handful of AI-related vulnerabilities have been confirmed as exploited in the wild, these include a command injection flaw in LiteLLM (CVE-2026-42271) leading to host takeover and API credential theft, and two Langflow flaws (CVE-2026-5027 and CVE-2025-3248) that permit file writing to the host or remote code execution.
GTIG anticipates that both vulnerability discovery and exploitation will continue to rise in the short to medium term. To mitigate this increased risk, organizations are advised to shift from unprioritized mass-patching to threat-intelligence-driven triage, combining targeted edge defense with automated, agentic remediation.






