Chronicle/Attacks & incidents

Google's threat intelligence group reports CVE disclosures doubled in 2026 and profiles likely AI-discovered vulnerabilities

AttackMisuse reportSignificance assistant-drafted

Google Threat Intelligence Group (GTIG) reports that monthly CVE disclosures rose from 5,045 in January 2026 to 10,477 in July and 10,740 in August, and that exploited vulnerabilities averaged 18 per month from January to August 2026 against 10.5 per month in 2025. GTIG says zero-day exploitation rose only marginally and suggests rapid weaponization of n-days drove most of the growth, and that vulnerabilities it identified as likely AI-discovered skew toward Medium risk ratings and remote code execution. It also counts 2,076 cumulative AI-related CVEs (January 2025 to August 2026) and reports in-the-wild exploitation of a handful, including a flaw in LiteLLM's MCP server preview endpoints.

Why it matters

It supplies aggregate disclosure and exploitation counts and a risk-profile comparison for likely AI-discovered flaws, while GTIG itself says its attribution to AI is inferred and that public data undercount AI discovery.

Key facts

As stated in the sources, with where to find them.

  • Disclosures per month: 5,045 in January 2026, 10,477 in July, 10,740 in August 2026. GTIG cautions that raw volume can mislead: vulnerabilities whose description contains "Linux Kernel" generated about 5,000 CVEs from January to August 2026, with no exploited zero-days observed.Key findings; CVE Disclosure Doubled in 2026
  • GTIG recorded 141 distinct vulnerabilities disclosed and exploited from January to August 2026, against 127 for all of 2025; the monthly average rose from 10.5 in 2025 to 18 in 2026. Only 0.23% of vulnerabilities disclosed in 2026 (roughly 1 in 431) were observed exploited.In-the-Wild Exploitation
  • Zero-day exploitation averaged 8 per month in 2025 and 11 per month from January to August 2026 (8 to 12 per month through mid-2026, 22 in August); zero-days were 62% of exploited vulnerabilities in that period. GTIG suggests the main source of exploitation growth was rapid weaponization of n-days and says it is possible attackers use AI tools to diff patches and PoC code; GTIG offers no measurement of this.Zero-Day Exploitation Remains Stable; Are Threat Actors Finding More Success with Exploiting N-Days?
  • Using GTIG's own risk ratings (not CVSS), High-Risk disclosures rose from 131 in January 2026 to 350 in August 2026 (+167%), still 3% of August disclosures. GTIG attributes this to more affected vendors and concentrated disclosure cycles (TOTOLINK router firmware, 75 High-Risk flaws in April and May; Oracle and Linux kernel, 128 in August). Exploited High-Risk vulnerabilities rose from 28 in 2025 to 75 from January to August 2026.Distinguishing Threat Risk from CVE Inflation; CVE Exploitation Trends Toward Higher Risk Vulnerabilities
  • For vulnerabilities GTIG identified as likely AI-discovered versus not, January to August 2026: Low 39% vs 69%, Medium 58% vs 28%, High 4% vs 3% (Table 1). Remote code execution 50% vs 26%; information disclosure 8% vs 18%; data manipulation 5% vs 9%. The post gives no count of AI-discovered vulnerabilities and says public data undercount them; GTIG says the skew likely reflects how researchers scope and task AI agents.AI as the Hunter: Risk Profile Divergence; Table 1; Figure 7
  • CVE-2026-1731 (BeyondTrust Privileged Remote Access and Remote Support, unauthenticated OS command injection) was discovered autonomously by a third-party research agent (Hacktron AI). GTIG observed one threat cluster exploiting it within four days of public disclosure and five more within seven days, with post-exploitation including data exfiltration.AI as the Hunter: Risk Profile Divergence
  • GTIG tracked 2,076 cumulative AI-related CVE disclosures from January 2025 to August 2026, over 1,500 of them from January to August 2026 across eight layers. Agent orchestration and framework flaws numbered 782 (50% of AI-related flaws, +347% in 2026); inference and serving infrastructure 212, of which 24% stemmed from unauthenticated API endpoints or SSRF.AI as the Hunted; Table 2; Emerging Battlegrounds
  • GTIG says zero-day exploitation of AI infrastructure had not been observed and only a handful of the 2,076 AI-related CVEs were confirmed exploited in the wild, listing CVE-2026-42271 (LiteLLM MCP server preview endpoint command injection), CVE-2026-5027 and CVE-2025-3248 (Langflow).Active In-the-Wild Exploitation of AI Middleware
  • GTIG expects vulnerability discovery and exploitation to keep growing in the short to medium term, calls the public data early, and recommends threat-intelligence-driven triage with automated, agentic remediation instead of unprioritized mass patching.Introduction; Outlook

Findings that cite this record

Key questions this bears on

Sources

Related records