Recent findings from VulnCheck, a leading research entity specializing in cybersecurity, reveal that software vulnerabilities identified by artificial intelligence (AI) tools are being exploited at a rate comparable to those vulnerabilities uncovered through traditional methods. Patrick Garrity, a vulnerability researcher at VulnCheck, detailed these insights in the latest State of Exploitation H1 2026 Report.
The report highlights that among the 1,061 vulnerabilities attributed to AI-assisted discovery, 14 have been confirmed as actively exploited in real-world scenarios. This statistic translates to an exploitation rate of 1.3% for AI-discovered vulnerabilities, a figure that closely aligns with the overall exploitation rate across all vulnerabilities for the period under review.
These findings may serve to temper concerns voiced by various experts regarding the burgeoning abilities of AI tools, such as Anthropic’s advanced models, which some have ominously warned could lead to a “vulnpocalypse.” This term refers to a potential onslaught of vulnerabilities flooding the security landscape, posing significant risks to software integrity. However, Garrity’s analysis indicates that, so far, the use of frontier AI models appears to favor defenders over attackers. In his assessment, these models may enhance the capabilities of cybersecurity teams in bolstering software defenses rather than empowering hackers to uncover and exploit vulnerabilities ahead of developers.
Adding another layer to the analysis, the report also draws attention to the findings of Anthropic’s Project Glasswing. Although the project has reported over 23,000 vulnerability findings, only 126 of these have resulted in published Common Vulnerabilities and Exposures (CVEs), and a mere single vulnerability has been confirmed as exploited in the wild. These statistics suggest that while AI is a powerful tool for identifying vulnerabilities, the actual risk posed remains contained.
The report sheds light on the broader trends in vulnerability exploitation. For the first half of 2026, VulnCheck identified nearly 500 known exploited vulnerabilities (KEVs), indicating a worrying trend, with exploitation occurring faster than in previous years. The median time between the publication of a CVE and its exploitation has significantly decreased from 120 days in 2025 to just 80 days in the first half of 2026. Despite this acceleration, the report notes a slight decline in the percentage of KEVs that were exploited on or before the release of the CVE itself. In the current report, 23.43% of KEVs were exploited the same day they were published, dipping from 28.93% in 2025.
Moreover, early exploitation activity appears to have stabilized, as approximately 200 CVEs were identified as being exploited within the first 31 days of their publication during this period. Garrity explained that this early exploitation behavior has not increased in proportion to the number of new CVEs entering the landscape, a trend that merits further examination.
The data also points towards content management systems (CMS) as the most targeted technology category, accounting for a substantial portion of the KEVs—163 in total, which constitutes about one-third of all recorded KEVs. Following CMS, the vulnerabilities affecting network edge devices, operating systems, and server software were also highlighted, with respective counts of 68, 44, and 40.
Additionally, a noteworthy trend is the emergence of AI products as a new attack surface. Vulnerabilities affecting various aspects of AI technology, including model-building tools and workload-scaling platforms, have begun to be exploited. This development underscores the evolving nature of cybersecurity threats as AI technologies become increasingly integrated into diverse sectors.
The VulnCheck report encapsulates the complete catalog of KEVs added to its database during the first half of 2026, collecting data based on the publication date of CVEs and the earliest instances of their exploitation. Vulnerabilities discovered through AI methods are documented not only through Garrity’s analysis but also through the telemetry provided by initiatives such as the Berkeley Vulnerability Research Initiative.
In summary, while AI’s role in identifying vulnerabilities is significant, the threat landscape necessitates ongoing vigilance. Both cybersecurity professionals and developers are urged to stay informed and adequately respond to the challenges posed by these evolving technologies.

